Security Insights

Latest threat analysis, industry news, and security best practices from our expert team.

Has:
microsoft-36515 articles
Jul 30, 2026

Microsoft Copilot for Word Self-Replicating Prompt Injection: Detection and Mitigation

Introduction On July 28, 2026, researcher Håkon Måløy disclosed a critical manipulation technique affecting Microsoft 365 Copilot within Wor...

criticalzero-daycve
Vulnerability ManagementRead Now
Jul 25, 2026

Microsoft 365 Outage: Technical Analysis of the Automated Maintenance Routing Bug

Introduction On [Current Date 2026], organizations worldwide experienced significant disruptions to Microsoft 365 and Azure services. This w...

penetration-testingred-teamoffensive-security
Platform & AutomationRead Now
Jul 25, 2026

Hotel Wi-Fi DNS Hijacking: Defending Against Microsoft 365 Credential Harvesting

Introduction Business travelers are facing a renewed and sophisticated threat at the network edge. Recent intelligence confirms that attacke...

mdrthreat-huntingendpoint-detection
SOC & MDRRead Now
Jul 24, 2026

CVE-2026-50517: M365 Copilot RCE via Deserialization — Defense and Hardening Guide

Introduction Today, the NVD published CVE-2026-50517, assigning it a CVSS score of 9.9 (CRITICAL). This vulnerability affects Microsoft 365 ...

cve-2026-50517criticalcve
Vulnerability ManagementRead Now
Jul 20, 2026

HollowGraph Malware: Detecting Microsoft Graph API Abuse in M365 Calendars

Introduction The democratization of cloud services has fundamentally shifted the threat landscape. We no longer face just malware that exfil...

incident-responseransomwarebreach-response
Incident ResponseRead Now
Jul 20, 2026

HollowGraph C2: Detecting Microsoft 365 Graph API Abuse via Future-Dated Calendar Events

Introduction Security operations teams must adapt to a sophisticated new evasion technique observed in the wild. Researchers at Group-IB hav...

incident-responseransomwarebreach-response
Incident ResponseRead Now
Jul 18, 2026

Kratos PhaaS Microsoft 365 Credential Theft: OTX Pulse Analysis — Enterprise Detection Pack

Kratos PhaaS Campaign Targets Microsoft 365: US and EU Under Siege Threat Summary Recent intelligence from the AlienVault OTX community indi...

darkwebotx-pulsedarkweb-credentials
Darkweb CredentialsRead Now
Jul 13, 2026

Misconfigured Infrastructure Exposes Evilginx Operations: Defending Against Microsoft 365 AiTM Phishing

Introduction In a stark reminder that operational security (OPSEC) failures affect even the adversary, French security firm Lexfo discovered...

managed-socmdrsecurity-monitoring
SOC & MDRRead Now
Jul 7, 2026

DEBULL Tooling: Microsoft 365 Device Code Flow Attack - Detection and Mitigation

Introduction Security teams are actively contending with a sophisticated social engineering campaign codenamed "DEBULL" that is hijacking Mi...

managed-socmdrsecurity-monitoring
SOC & MDRRead Now
Previous
Page 1 of 2
Next