#365


Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Aug 5, 2026 // 00:56

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. The platform has been active […]

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Aug 5, 2026 // 00:39

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously […]

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Aug 4, 2026 // 16:57

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously […]

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Jul 25, 2026 // 00:37

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign […]

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

Jul 22, 2026 // 09:41

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used […]

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Jul 20, 2026 // 17:38

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files […]

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17, 2026 // 11:57

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, […]

New phishing kits target Microsoft 365 accounts, evade MFA

Jul 14, 2026 // 15:56

Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). While Jalisco […]

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Jul 13, 2026 // 16:03

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, […]

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

Jul 13, 2026 // 12:54

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The […]