A reported .NET Native AOT module shifts the communication layer toward Microsoft 365 calendar objects and adds a DNS recovery path, showing how cloud identity surfaces can become part of malware plumbing.
A Windows malware sample has been tied to a covert Microsoft Graph channel that turns a Microsoft 365 calendar into a hidden rendezvous point for attacker instructions.
A Windows malware implant is reported to hide its command traffic inside Microsoft 365 calendar activity, showing how trusted collaboration tools can be turned into covert control infrastructure.
A newly described espionage implant is using Microsoft 365 calendar objects as a covert relay, showing how trusted cloud APIs can double as low-noise channels for command and data theft.
A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.
A reported SearchLeak chain shows how enterprise AI can turn trusted work data into a disclosure risk without breaking login first.
SearchLeak shows how a single crafted link in Microsoft 365 Copilot Enterprise could turn everyday productivity into a high-risk disclosure path across mail, files, and collaboration data.
The Webworm campaign shows how collaboration tools, cloud APIs, and proxy layers can become part of an intrusion chain without looking overtly malicious on the wire.
A reported backdoor tied to Webworm uses Microsoft Graph and OneDrive as a command channel, underscoring how ordinary SaaS traffic can be repurposed for covert operations.
A suspected espionage cluster is using ordinary cloud services as covert traffic paths, turning familiar collaboration tools into harder-to-see command channels.
Three disclosure bugs tied to Microsoft 365 Copilot, Microsoft Copilot, and Copilot Chat in Edge show how an AI assistant can turn everyday enterprise context into a confidentiality problem.