Skip to main content
← All Articles

Tag

#Microsoft 365

34 articles

Advertisement

Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse
HIGH
Threat Intel

Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse

Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.

Runtime Rebel Intel
4 min read · Aug 8, 2026
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
HIGH
Threat Intel

Greatness PhaaS Adds Device Code Phishing for MFA Bypass

Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.

Runtime Rebel Intel
5 min read · Aug 4, 2026
Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word
MEDIUM
Vulnerabilities

Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word

Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.

Runtime Rebel Intel
3 min read · Jul 30, 2026
MEDIUM
Cloud Security

Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure

Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.

Runtime Rebel Intel
4 min read · Jul 24, 2026
MEDIUM
Cloud Security

Microsoft Fixes Exchange Online Erroneous Mailbox Quarantine Issue

Microsoft is mitigating a service disruption where Exchange Online mailboxes were incorrectly quarantined, causing delivery failures and access issues.

Runtime Rebel Intel
4 min read · Jul 23, 2026
HIGH
Malware

HollowGraph Malware Uses Microsoft Graph for Stealthy C2

HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.

Runtime Rebel Intel
4 min read · Jul 20, 2026

Advertisement

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HIGH
Malware

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2

HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.

Runtime Rebel Intel
5 min read · Jul 20, 2026
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
MEDIUM
Threat Intel

Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks

Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.

Runtime Rebel Intel
3 min read · Jul 13, 2026
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
HIGH
Threat Intel

Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits

A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.

Runtime Rebel Intel
4 min read · Jul 13, 2026
HIGH
Threat Intel

Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise

Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.

Runtime Rebel Intel
4 min read · Jul 9, 2026
HIGH
Identity & Access

Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk

A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.

Runtime Rebel Intel
5 min read · Jul 8, 2026
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
HIGH
Threat Intel

EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption

Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.

Runtime Rebel Intel
3 min read · Jul 8, 2026
HIGH
Identity & Access

ADFS Golden SAML: Recovering Signing Keys via Machine DPAPI

Learn how ADFS configuration drift allows attackers to recover active signing keys from Machine DPAPI, enabling SAML assertion forgery and MFA bypass.

Runtime Rebel Intel
4 min read · Jul 8, 2026
MEDIUM
Threat Intel

ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit

ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.

Runtime Rebel Intel
5 min read · Jul 3, 2026
HIGH
Threat Intel

Chinese APT UNC5221 Deploys New Malware for M365 Persistence

Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…

Runtime Rebel Intel
5 min read · Jun 5, 2026
MEDIUM
Cloud Security

Microsoft Exchange Online Outage: North America and Germany Impacts

Microsoft Exchange Online outage disrupts mail flow in North America and Germany, causing email delays and NDR errors. Learn how to monitor service health.

Runtime Rebel Intel
4 min read · Jun 2, 2026
MEDIUM
Cloud Security

Microsoft Teams and Office Web File Access Disruptions - Mitigation Guide

Microsoft is investigating a service incident impacting file access in Teams and Office for the web, causing operational delays for global enterprises.

Runtime Rebel Intel
4 min read · Jun 1, 2026
HIGH
Threat Intel

FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts

The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.

Runtime Rebel Intel
3 min read · May 25, 2026
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
HIGH
Threat Intel

EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow

The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.

Runtime Rebel Intel
4 min read · May 19, 2026
MEDIUM
Threat Intel

Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow

Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.

Runtime Rebel Intel
3 min read · May 17, 2026
HIGH
Threat Intel

BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion

Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.

Runtime Rebel Intel
6 min read · May 15, 2026
MEDIUM
Threat Intel

AitM Phishing Attacks Target US Organizations with Conduct Reports

Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.

Runtime Rebel Intel
3 min read · May 5, 2026
Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
HIGH
Identity & Access

Defeating Persistent OAuth Token Risks in Google and Microsoft Apps

Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.

Runtime Rebel Intel
4 min read · May 5, 2026
Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users
HIGH
Threat Intel

Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users

Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.

Runtime Rebel Intel
4 min read · May 5, 2026