This ‘fascinating’ Microsoft Excel security flaw teams up spreadsheets and Copilot Agent to steal data



  • Microsoft’s latest Patch Tuesday release fixes 83 flaws
  • Including an Excel bug which enables AI-driven zero-click data theft
  • Update urged to block exfiltration via Copilot assistant

The March 2026 Patch Tuesday release from Microsoft has fixed a high-severity vulnerability in Excel, which combines good old cross-site scripting (XSS) with indirect prompt injection for data exfiltration via Artificial Intelligence (AI).

Since AI gave an old vulnerability a new twist, some security researchers described it as “fascinating” – and it being a “zero-click” attack didn’t help, either.


https://cdn.mos.cms.futurecdn.net/5LbNNBpRnuwNeeTTNZLSBA-2048-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img