Proofpoint linked 28 Microsoft 365 tenant intrusions to unrotated service accounts still holding default passwords.
A new exploit kit chained two Chrome flaws and a Windows bug for four espionage crews.
TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
Chinese espionage group exploits Roundcube webmail vulnerabilities to target US and Canadian universities
Cybercriminals are using Microsoft's OAuth device authorization flow to steal authentication tokens through phishing campaigns that bypass traditional security tools.