Proofpoint linked 28 Microsoft 365 tenant intrusions to unrotated service accounts still holding default passwords.
GhostCode abuses Microsoft's device authorization flow to obtain tokens and register attacker hardware inside a victim tenant.
Firewall and proxy rules that allow the old addresses will need updating before early October.
CloudSEK says it reached the admin panel of a phishing service holding thousands of session cookies stolen from Microsoft 365…
The NovaCookies phishing service uses genuine Docusign notifications to steal Microsoft 365 sessions in real time.
A two-year phishing-as-a-service campaign bypasses 2FA across more than 4,500 Microsoft 365 domains.
IEH Corporation told the SEC that a phished employee's Microsoft 365 mailbox exposed engineering files and potentially export-controlled technical data.
A voicemail-themed AitM phishing wave is taking over Microsoft 365 accounts to harvest payroll and finance email.