Tag

Microsoft 365

All articles tagged with #microsoft 365

Microsoft 365 search outage linked to deployment bug receives fix
technology6 days ago

Microsoft 365 search outage linked to deployment bug receives fix

Microsoft has confirmed a search outage affecting Microsoft 365 apps (Outlook on the web/desktop, SharePoint Online, and OneDrive) caused by a recent deployment that created resource utilization inefficiencies. A fix has been deployed to reduce pressure and restore service for affected users; Microsoft did not specify which regions were impacted. The incident adds to a history of past outages in the ecosystem.

technology20 days ago

AI-powered phishing scams: seven schemes you need to know

AI-generated phishing emails are becoming almost indistinguishable from legitimate messages, and attackers use new tricks like OAuth device code flows to bypass MFA and QR codes to hide links. The piece outlines seven current scams—Microsoft 365 login theft, support scams, fake Defender warnings, cloud/OneDrive phishing, parcel-delivery impersonations, online-banking fraud, and Postident fraud by post—and provides practical defenses: verify via official sites, enable MFA, use a password manager, avoid clicking links or scanning unknown QR codes, and resist unsolicited remote-support requests.

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins
technology23 days ago

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins

Hackers are hijacking hotel and conference Wi‑Fi gateways to redirect business travelers to fake Microsoft 365 sign‑in pages, potentially bypassing MFA via deceptive device prompts and WPAD abuse. Active since at least June, the campaign alters DNS to serve phishing domains (e.g., m365-owa.com, ms365-live.com) and can affect many industries; defenses include using a full‑tunnel VPN, a mobile hotspot, verifying login URLs, avoiding unexpected prompts, updating devices, and having IT disable WPAD where possible.

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions
technology1 month ago

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions

German and U.S. authorities dismantled Kratos, a widely used phishing kit that stole Microsoft 365 session cookies to bypass MFA, shutting down 200+ servers and affecting about 1,800 paying customers who ran some 15,000 campaigns a month. Victims number in the hundreds of thousands across 30+ countries; operators earned over €300,000 since 2024. The kit offered credential-only mode or a real-time adversary-in-the-middle reverse-proxy mode. Microsoft Threat Intelligence links it to SneakyLog; campaigns have used tax-themed W-2 emails with QR codes to lure targets. Stolen credentials can be sold or used to move laterally in Microsoft 365. Mitigations include password resets with MFA checks for credential-only hits, revoking sessions for session-stealing hits, and adopting phishing-resistant sign-ins for high-value accounts. Indicators include login-page assets barr.svg and lg.svg and endpoints like next.php or save.php. The takedown halts Kratos campaigns for now, but the kit and its customers persist elsewhere.

Phishers roll out two new kits to target Microsoft 365, sidestep MFA
technology1 month ago

Phishers roll out two new kits to target Microsoft 365, sidestep MFA

Two new phishing toolkits, Jalisco and OmegaLord, target Microsoft 365 accounts and bypass MFA: Jalisco uses OAuth device-code phishing to trick victims into authorizing attacker-controlled devices and can auto-generate fresh device codes to defeat the 15-minute window, while OmegaLord masquerades as a PDF reader to steal credentials and phone numbers to aid MFA interception. Attacks can lead to rapid data exfiltration from SharePoint and other SaaS apps, sometimes within minutes, prompting researchers to urge tighter controls: reduce Entra ID device-registration limits from 50 to 1-2, block device-code authentication via Entra Conditional Access, restrict OAuth Device Authorization grants in Okta, and audit/remove unnecessary app registrations.

Copilot's Bold Reach Fails to Pay Off as Adoption Stalls and Prices Rise
technology1 month ago

Copilot's Bold Reach Fails to Pay Off as Adoption Stalls and Prices Rise

Microsoft 365 Copilot remains a hard sell: under 4.5% of Microsoft 365 customers pay for the paid Copilot add‑on, and only about 1% are active weekly. Microsoft has raised prices for the paid tiers (up to about $30 per user per month) and expanded model options (including Claude) while keeping a free Copilot Chat tier, signaling a bundling strategy that aims to monetize AI even as adoption stays low.

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit
security1 month ago

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit

Cisco Talos flags ARToken as a new phishing-as-a-service platform allied with EvilTokens, offering a wide toolkit to steal Microsoft 365 tokens, maintain persistence with Primary Refresh Tokens, and access Outlook, SharePoint, and OneDrive. It uses Cloudflare Workers for deployment, supports multi-tenant campaigns, and includes inbox rules, keyword monitoring, and data exfiltration tools. The kit mirrors EvilTokens’ device-code phishing flow to bypass MFA, with research suggesting a shared ecosystem and AI-enabled workflows that automate BEC-style fraud. Security teams should prioritize behavioral AI defenses and robust email security controls.

ConsentFix: Fast Token Theft Targets Microsoft 365 Sign-Ins
technology1 month ago

ConsentFix: Fast Token Theft Targets Microsoft 365 Sign-Ins

A new attack variant called ConsentFix hijacks Microsoft 365 OAuth sign‑in flows by tricking users into dragging a localhost callback link, stealing OAuth tokens and granting attackers ongoing access to email and other services without passwords or MFA. Attackers use trusted phishing lures, map targets via LinkedIn, and publicly share the blueprint, lowering the bar for criminals. Defenses require more than awareness—look for abnormal PowerShell activity, unusual logins, and strengthen endpoint/identity monitoring to detect session/token theft before damage occurs.

Microsoft to Auto-Install Copilot on Windows 11 for 365 Business, Opt-Out Within 30 Days
technology2 months ago

Microsoft to Auto-Install Copilot on Windows 11 for 365 Business, Opt-Out Within 30 Days

Microsoft will resume automatic installation of the Microsoft 365 Copilot app on eligible Windows devices with Microsoft 365 desktop apps, rolling out between mid-June and mid-July. Admins can opt out, with the European Economic Area exempt from changes. The Copilot app is delivered via the Office updater (not Windows Store) and Copilot features are being integrated across Word, Excel, PowerPoint, Outlook, Teams, and the web. Users can disable Copilot per app or via privacy settings, and admins can use policies to block it, though complete removal isn’t simple and may require broader configuration.

Office 2021 Exits Support This October as Microsoft Pushes 365
technology2 months ago

Office 2021 Exits Support This October as Microsoft Pushes 365

Microsoft will end official support for Office 2021 on October 13, 2026, leaving users without patches or security updates. The company is nudging users toward Microsoft 365 or Office 2024. To stay on Office 2021, you can run offline, download and scan files locally, keep Windows Security updated, freeze add-ins, and consider hybrid workflows or alternate tools like LibreOffice; otherwise plan an upgrade before the deadline.

Microsoft Scout: OpenClaw-Powered Personal AI for Microsoft 365
technology2 months ago

Microsoft Scout: OpenClaw-Powered Personal AI for Microsoft 365

Microsoft is previewing Scout, an always-on personal AI assistant built on OpenClaw that integrates with Microsoft 365 apps to manage calendars, emails, travel, and tasks. It reads Teams and email to surface what matters, can suggest optimal travel times, and is designed to run in the cloud with a desktop Frontier preview in the US before broader rollout, backed by security measures like sandboxing, Defender, and privacy reviews. Microsoft is contributing to the OpenClaw core rather than shipping a separate product, while Google pursues Gemini Spark to connect with Workspace apps, signaling a new enterprise AI race.

Dell secures $9.7B DoD software deal amid political ties
defense2 months ago

Dell secures $9.7B DoD software deal amid political ties

Dell Federal Systems won a five-year, roughly $9.7 billion Department of Defense contract to supply Microsoft 365, cloud services and on-premises licensing under a second-generation enterprise software agreement, with expected annual savings of about $422 million through consolidated licensing; the award followed a competitive process and comes amid public ties between Dell founder Michael Dell and Donald Trump, including a pledge to fund 'Trump accounts' for children.

FBI Warns Kali365 PhaaS Bypasses MFA on Microsoft 365
cybersecurity3 months ago

FBI Warns Kali365 PhaaS Bypasses MFA on Microsoft 365

The FBI issued a PSA about Kali365, a phishing‑as‑a‑service that exploits Microsoft’s OAuth device-code flow to hijack Entra and Microsoft 365 accounts, stealing session tokens and bypassing MFA. Kali365, distributed via Telegram, provides AI‑generated phishing lures, automated campaigns, and real‑time dashboards, with two attack modes: device‑code phishing and a Cookie Link adversary‑in‑the‑middle. Arctic Wolf observed global campaigns targeting Microsoft 365 environments, including creating malicious inbox rules and registering new devices. The FBI urges blocking device‑code authentication with Conditional Access, auditing usage, reporting incidents to IC3, and preserving phishing emails and suspicious activity. Device-code phishing has surged in 2026, with other PhaaS tools like EvilTokens and Tycoon2FA using similar methods.

Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365
security3 months ago

Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365

A new Tycoon2FA variant uses device-code phishing via a Trustifi click-tracking URL to hijack Microsoft 365 accounts by steering victims to the legitimate device-login flow at microsoft.com/devicelogin, granting attackers OAuth tokens and access to email, calendar, and files. After a takedown, the kit resurfaced with obfuscation and new delivery chains, prompting defenders to disable the device-code flow when not needed, restrict OAuth permissions, enable Continuous Access Evaluation, and monitor Entra logs for deviceCode activity and related IoCs.