#365


US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

Sep 30, 2026 // 13:51

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and […]

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Sep 24, 2026 // 23:39

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to […]

Secure enterprise sharing with access reviews for Microsoft 365

Sep 19, 2026 // 00:02

Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with coworkers, clients and business partners. Yet when […]

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Sep 12, 2026 // 01:37

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts […]

Microsoft 365 Attackers Use Help Desk Vishing to Steal Data for Extortion

Sep 7, 2026 // 19:02

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information […]

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Sep 7, 2026 // 18:57

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers […]

Microsoft 365 Attackers Use Help Desk Vishing to Steal Data for Extortion

Sep 7, 2026 // 18:52

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information […]

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Aug 27, 2026 // 00:41

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while […]

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Aug 25, 2026 // 14:58

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate […]

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Aug 8, 2026 // 01:07

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with […]

1 2 3 4 Next