Tag

#Microsoft 365

40 stories taggedMicrosoft 365 · page 2 of 3.

A hotel lobby Wi-Fi router mounted on a wall with digital visualization showing intercepted login credentials and passwords flowing from employee devices into a
Threat Intelligence

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details

Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

3 min read
Hotel lobby with business travelers at the front desk and in seating areas, Wi-Fi network selection screen on a laptop showing spoofed networks, fake Microsoft
Threat Intelligence

Hotel Wi-Fi hijack campaign quietly harvests Microsoft 365 logins from business travellers

A cluster with overlapping infrastructure tied to Russia-linked APT28 activity is tampering with DNS on hotel and conference Wi-Fi gateways to funnel guests into fake Microsoft login pages, ReliaQuest reports.

4 min read
Modern startup office environment with security professionals at workstations, AI model training visualizations displayed on screens, phishing email samples bei
AI Security

AegisAI Raises $36 Million to Fight AI-Generated Phishing Emails

A startup built by former Google security engineers says criminals now use artificial intelligence to craft personalised fake emails at scale. Its answer is an AI system that reads those emails back.

3 min read
An office with multiple blank computer monitors and inactive workstations, devices mid-shutdown with spinning loading indicators visible on screens, overheard f
Cloud Security

Microsoft 365 hit by outage knocking out Teams, SharePoint and Excel

Downdetector logged more than 2,400 user reports as Microsoft opened incident MO1437424 and began investigating.

3 min read
An email server room with glowing equipment showing quarantine status indicators, mailboxes shown as locked containers on digital displays, calendar and email f
Cloud Security

Microsoft Exchange Online is Wrongly Locking Away Customer Mailboxes

A memory bug from an infrastructure change has been quarantining legitimate mailboxes since Sunday, blocking email and calendar access with no full-fix timeline yet.

3 min read
Full-frame photoreal editorial image of a dimly lit European police evidence room, a plain server rack with cables unplugged and yellow evidence tags dangling f
Identity & Access

Police shut down Kratos, the phishing kit built to hijack Microsoft 365 logins

German and US investigators dismantled the kit's servers, and Indonesian police arrested its alleged creator, ending a service that helped criminals slip past two-factor login checks.

3 min read
Full-frame photoreal news-editorial image of a darkened server room with rows of rack servers, red status lights dimmed, one rack cabinet unplugged with cables
Threat Intelligence

German and US police pull the plug on Kratos, a phishing kit rented to 1,800 crooks

Investigators seized more than 200 servers and arrested the developer in Indonesia, ending a service that ran roughly 15,000 fake Microsoft login campaigns every month.

3 min read
A cybercriminal's workspace with multiple monitors displaying calendar applications and email clients, showing how calendar entries contain encoded command inst
Threat Intelligence

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries

A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

3 min read
Full-frame photoreal news-editorial image of a dimly lit office desk at night, a laptop screen glowing with a blurred calendar grid showing dates far in the fut
Threat Intelligence

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050

A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

3 min read
Full-frame photoreal shot of a laptop screen showing a generic fake browser error dialog, warm office lighting, blurred keyboard in foreground, moody editorial
Threat Intelligence

ACR Stealer Tricks Staff Into Typing the Attack Themselves

Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

4 min read
Full-frame 16:9 photoreal editorial shot of a dimly lit server room with one rack door left ajar, faint blue LED glow spilling out onto a concrete floor, cables
Threat Intelligence

A Phishing Crew Forgot to Lock Its Own Front Door

A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

3 min read
Photoreal news-editorial style, 16:9 framing
Identity & Access

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time

A hacking group is phoning employees, sending them to fake Microsoft Entra ID login pages, and quietly registering their own passkeys before anyone notices. Okta has the details.

3 min read
Full-frame photoreal editorial shot of a dimly lit open-plan office at night, a desk phone glowing under a single lamp, a laptop screen out of focus in the back
Threat Intelligence

Helix: the new extortion crew phoning staff to raid SharePoint files

Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then pulls company documents from Microsoft SharePoint.

3 min read
Full-frame photoreal editorial shot of an anonymous office desk at dusk, a laptop screen glowing with an out-of-focus generic corporate sign-in page, a single s
Identity & Access

Forg365: the new phishing kit built to hoover up Microsoft 365 logins

A fresh phishing-as-a-service operation uses AI to write the bait and a browser extension to keep the door open long after the theft.

4 min read
A close-up photoreal shot of a laptop screen showing a blurred generic corporate login form, with a faint ghostly overlay of scrambled characters resolving into
Threat Intelligence

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim

The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

3 min read
© 2026 Threat Vectr