A vulnerability has been discovered in excel and excel reader versions after 2000 that allows system compromise (that's pwnage 2 u) from remote. Although it is never a good idea to open office documents from an untrusted source it is now a super-not-very-good-idea(tm). Exploits are already in the wild and more can be expected while it remains unpatched, along with the PDFs you can also expect a few XLSs in your spam emails, which is nice.