Advertisement
Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse
Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.
Persistent Prompt Injection Risks in Microsoft 365 Copilot for Word
Researchers demonstrate how hidden instructions in Word documents can persist through Microsoft 365 Copilot drafting, creating risks of malicious prompt propagation.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
Microsoft Fixes Exchange Online Erroneous Mailbox Quarantine Issue
Microsoft is mitigating a service disruption where Exchange Online mailboxes were incorrectly quarantined, causing delivery failures and access issues.
HollowGraph Malware Uses Microsoft Graph for Stealthy C2
HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.
Advertisement
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.
Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits
A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker's toolkit and session cookies.
Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise
Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.
Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk
A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.
ADFS Golden SAML: Recovering Signing Keys via Machine DPAPI
Learn how ADFS configuration drift allows attackers to recover active signing keys from Machine DPAPI, enabling SAML assertion forgery and MFA bypass.
ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit
ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.
Chinese APT UNC5221 Deploys New Malware for M365 Persistence
Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…
Microsoft Exchange Online Outage: North America and Germany Impacts
Microsoft Exchange Online outage disrupts mail flow in North America and Germany, causing email delays and NDR errors. Learn how to monitor service health.
Microsoft Teams and Office Web File Access Disruptions - Mitigation Guide
Microsoft is investigating a service incident impacting file access in Teams and Office for the web, causing operational delays for global enterprises.
FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts
The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.
Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow
Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.
AitM Phishing Attacks Target US Organizations with Conduct Reports
Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.
Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.
Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users
Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.