Tag

#Microsoft 365

37 stories taggedMicrosoft 365 · page 3 of 3.

Identity & Access

BEC Keeps Winning Because It Looks Exactly Like Normal Work

The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

3 min read
AI Security

SearchLeak: How a microsoft.com Link Could Have Drained a Copilot Tenant

Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfil path that lived behind a trusted Microsoft URL.

2 min read
Threat Intelligence

Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive

Threat hunters say the executive's mailbox was siphoned in small batches over consumer cloud channels — a pattern consistent with state-aligned espionage rather than financially motivated crime.

3 min read
Identity & Access

A Debug Flag Shipped to Prod Turned M365 Android Apps Into a Token Buffet

Any sideloaded app on the same phone could ask for the signed-in user's Microsoft token and get it. No prompt. No password. Just IPC.

3 min read
Identity & Access

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA

The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

3 min read
Threat Intelligence

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers

Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

3 min read
Identity & Access

FBI flags Kali365, the latest phishing kit pitched at draining Microsoft 365 tenants

The bureau says the subscription-priced service abuses OAuth device-code flows to lift session tokens and walk straight past MFA.

2 min read
© 2026 Threat Vectr