#365


Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Jul 10, 2026 // 16:46

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra […]

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

Jul 9, 2026 // 17:56

A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. […]

Entra passkey enrollment vishing targets Microsoft 365 users

Jul 8, 2026 // 19:57

A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra […]

ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit

Jul 3, 2026 // 19:17

A new phishing-as-a-service (PhaaS) platform dubbed “ARToken” appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed […]

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Jul 2, 2026 // 17:17

It can start with something as mundane as dragging a link into your browser. Three seconds later, a threat actor has the tokens needed to […]

Hackers target Microsoft 365 accounts with 81 million login attempts

Jul 1, 2026 // 19:58

An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. The threat actor tried to authenticate […]

5 reasons Microsoft 365 backup isn’t enough for business data protection

Jun 18, 2026 // 19:37

Written by Andy Kerr, Senior Manager, Solutions Marketing at Acronis. Many organizations assume Microsoft 365 automatically provides built-in protection for their business data. It doesn’t, and Microsoft […]

New attack turned Microsoft 365 Copilot into 1-click data theft tool

Jun 15, 2026 // 22:57

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target’s mailbox, OneDrive, or SharePoint […]

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Jun 15, 2026 // 22:49

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot […]

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Jun 3, 2026 // 18:04

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft […]