Microsoft 365
18 stories on Microsoft 365, newest first, from 19 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- CSuite Phishing Campaign Hijacks Microsoft 365 Sessions and Installs Remote Access Tools
- Forgotten Service Accounts Leave Microsoft 365 Environments Exposed
- Most Organisations Are Losing Track of Who Can Access Their Microsoft 365 Data
- Forgotten Service Accounts Exploited in Microsoft 365 Password-Spraying Campaign
- Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts
- Microsoft and UK Police Take Down 'EvilTokens' AI-Powered Phishing Service
- Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours
- AI Rollouts Outpacing Basic Permission Checks, Study Finds
- Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives
- New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts
- 'NovaCookies' Phishing Kit Lets Criminals Hijack Microsoft 365 Accounts for $320 a Month
- Phishing Kit 'Mirage2FA' Bypasses Two-Factor Authentication, Hits 4,500 Companies
-
New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
Also covered by The Hacker News
- Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails
- Windows Hello for Business Flaw Lets Malware Hijack Cloud Logins
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages