#Microsoft 365
40 stories taggedMicrosoft 365.

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts
Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark
The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You
A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

Microsoft is moving Teams and Microsoft 365 to new web addresses, here is what your IT team needs to do
Both services are redirecting to new cloud.microsoft domains by early October. Businesses need to update firewall and network settings now, or users could lose access.

Phishing kit 'BigBear' walked past Microsoft 365 logins at 258 companies
Researchers at CloudSEK found the rented service scooped up more than 5,000 Microsoft 365 credentials and 4,148 session cookies from victims in 40 countries.

Microsoft Exchange Online buckles: email delays, sign-in errors hit tens of thousands
Microsoft says it has spotted a shared authentication fault behind a widespread Exchange Online outage causing missing emails and login failures.

NovaCookies Phishing Kit Rents Microsoft 365 Session Theft for $320 a Month
A new subscription phishing service abuses genuine Docusign emails to slip past multi-factor authentication and steal live Microsoft 365 logins.

Mirage2FA Phishing Kit Slipped Past Microsoft 365 Logins at 4,500 Firms
A rented phishing service quietly harvested Microsoft 365 credentials and two-factor codes across US and European companies for nearly two years.

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots
Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

TWINLOOT Malware Hides Inside Microsoft's Own Cloud to Steal Passwords
A newly discovered piece of malicious software uses Microsoft SharePoint, Teams, and Edge to run its operation, making it nearly invisible to the tools most companies rely on.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft has attributed the CaptiveCrunch campaign to Storm-2945, a sub-group of APT29, which has been poisoning hotel and conference Wi-Fi networks since at least May 2025 to steal corporate accounts using two newly identified malware families.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

Hidden Prompts in Word Files Can Hijack Microsoft 365 Copilot, Researcher Warns
A proof of concept shows Copilot copying attacker instructions into finished documents, then spreading them to the next draft.