The problem goes deeper than your Xbox -- if you use your Passport account for other Microsoft services, the phishers could have access to a lot of sensitive information. The same e-mail has reportedly been received by other users in the U.S. and U.K.
It probably goes without saying, but if you get a similar e-mail, delete it immediately. If you accidentally use the link, change your password immediately. And don't trust random e-mails to notify you about new Xbox Live updates -- that's what we're here for, after all.
[Update: Microsoft has acknowledged the scam and reportedly taken action.]