BACK_TO_FEEDAICRIER_2
Copilot agent turns patched Excel bug into zero-click leak
OPEN_SOURCE ↗
YT · YOUTUBE// 3h agoSECURITY INCIDENT

Copilot agent turns patched Excel bug into zero-click leak

Researchers demonstrated that a previously patched XSS vulnerability in Excel can be exploited via Microsoft Copilot to silently exfiltrate data. The exploit highlights how autonomous agents can bypass traditional security to resurrect old vulnerabilities.

// ANALYSIS

Autonomous agents are creating new, unexpected attack surfaces that bypass traditional security monitoring.

  • Attackers used the Copilot agent to exploit a patched XSS bug in Excel
  • Data can be silently read and exfiltrated without user interaction
  • Highlights the risk of agents amplifying the impact of older vulnerabilities
  • Traditional security tools struggle to monitor agent-driven data access
// TAGS
microsoft-copilotagentsafety

DISCOVERED

3h ago

2026-04-24

PUBLISHED

3h ago

2026-04-24

RELEVANCE

9/ 10

AUTHOR

Better Stack