Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
HollowGraph C2: Detecting Microsoft 365 Graph API Abuse via Future-Dated Calendar Events
Introduction Security operations teams must adapt to a sophisticated new evasion technique observed in the wild. Researchers at Group-IB hav...
Kratos PhaaS Microsoft 365 Credential Theft: OTX Pulse Analysis — Enterprise Detection Pack
Kratos PhaaS Campaign Targets Microsoft 365: US and EU Under Siege Threat Summary Recent intelligence from the AlienVault OTX community indi...
Misconfigured Infrastructure Exposes Evilginx Operations: Defending Against Microsoft 365 AiTM Phishing
Introduction In a stark reminder that operational security (OPSEC) failures affect even the adversary, French security firm Lexfo discovered...
DEBULL Tooling: Microsoft 365 Device Code Flow Attack - Detection and Mitigation
Introduction Security teams are actively contending with a sophisticated social engineering campaign codenamed "DEBULL" that is hijacking Mi...
ARToken PhaaS & EvilTokens M365 Toolkit: Detection and Defense Strategies
ARToken PhaaS & EvilTokens M365 Toolkit: Detection and Defense Strategies Introduction Security researchers have exposed a new Social Engine...
SearchLeak: Microsoft 365 Copilot Enterprise Data Exfiltration — Defense and Detection
Introduction A critical vulnerability chain, dubbed SearchLeak, has been identified in Microsoft 365 Copilot Enterprise, posing a severe ris...
UNC5221 APT: Detecting Brickstorm, Plenet, and AgentPSD in Microsoft 365
Introduction A Chinese espionage cluster tracked as UNC5221 is actively conducting targeted intrusions against Microsoft 365 environments. T...
FBI Alert: Kali365 Phishing-as-a-Service Hijacks M365 OAuth Tokens — Detection and Defense
The FBI has issued a warning regarding 'Kali365,' a sophisticated social engineering-as-a-service (SEaaS) platform specifically designed to ...
Storm-2949: Cloud-Wide Identity Breach Detection and Hardening Guide
Introduction Storm-2949 has redefined the scope of cloud intrusions, proving that a single compromised identity can serve as a master key fo...