#Microsoft 365
40 stories taggedMicrosoft 365 · page 2 of 3.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Hotel Wi-Fi hijack campaign quietly harvests Microsoft 365 logins from business travellers
A cluster with overlapping infrastructure tied to Russia-linked APT28 activity is tampering with DNS on hotel and conference Wi-Fi gateways to funnel guests into fake Microsoft login pages, ReliaQuest reports.

AegisAI Raises $36 Million to Fight AI-Generated Phishing Emails
A startup built by former Google security engineers says criminals now use artificial intelligence to craft personalised fake emails at scale. Its answer is an AI system that reads those emails back.

Microsoft 365 hit by outage knocking out Teams, SharePoint and Excel
Downdetector logged more than 2,400 user reports as Microsoft opened incident MO1437424 and began investigating.

Microsoft Exchange Online is Wrongly Locking Away Customer Mailboxes
A memory bug from an infrastructure change has been quarantining legitimate mailboxes since Sunday, blocking email and calendar access with no full-fix timeline yet.

Police shut down Kratos, the phishing kit built to hijack Microsoft 365 logins
German and US investigators dismantled the kit's servers, and Indonesian police arrested its alleged creator, ending a service that helped criminals slip past two-factor login checks.

German and US police pull the plug on Kratos, a phishing kit rented to 1,800 crooks
Investigators seized more than 200 servers and arrested the developer in Indonesia, ending a service that ran roughly 15,000 fake Microsoft login campaigns every month.

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries
A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050
A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

ACR Stealer Tricks Staff Into Typing the Attack Themselves
Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft Entra ID login pages, and quietly registering their own passkeys before anyone notices. Okta has the details.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then pulls company documents from Microsoft SharePoint.

Forg365: the new phishing kit built to hoover up Microsoft 365 logins
A fresh phishing-as-a-service operation uses AI to write the bait and a browser extension to keep the door open long after the theft.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.