Sunday 26 July 2026 13:44:12 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Microsoft Graph


CAV3RN’s New Build Trades WebSockets for Outlook Calendar Access

Published: 21 July 2026 16:19Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A reported .NET Native AOT module shifts the communication layer toward Microsoft 365 calendar objects and adds a DNS recovery path, showing how cloud identity surfaces can become part of malware plumbing.

When a Calendar Becomes a Command Line: The HOLLOWGRAPH Abuse of Microsoft 365

Published: 21 July 2026 08:14Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A Windows malware sample has been tied to a covert Microsoft Graph channel that turns a Microsoft 365 calendar into a hidden rendezvous point for attacker instructions.

When a Calendar Becomes a Spy Channel: HOLLOWGRAPH and the New Abuse of Microsoft 365

Published: 21 July 2026 08:09Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Windows malware implant is reported to hide its command traffic inside Microsoft 365 calendar activity, showing how trusted collaboration tools can be turned into covert control infrastructure.

When a Calendar Becomes a Command Line: HollowGraph and the New SaaS Hideout

Published: 20 July 2026 18:31Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A newly described espionage implant is using Microsoft 365 calendar objects as a covert relay, showing how trusted cloud APIs can double as low-noise channels for command and data theft.

The ARToken Panel Shows How Phishing Became a Token Factory

Published: 02 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.

One Click, One Search Box, and a Hidden Leak Path Inside Microsoft 365 Copilot

Published: 16 June 2026 08:09Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A reported SearchLeak chain shows how enterprise AI can turn trusted work data into a disclosure risk without breaking login first.

When a Trusted Copilot Becomes a Data Trap

Published: 15 June 2026 17:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

SearchLeak shows how a single crafted link in Microsoft 365 Copilot Enterprise could turn everyday productivity into a high-risk disclosure path across mail, files, and collaboration data.

When a State-Linked Crew Turns Discord Into a Back Door

Published: 22 May 2026 10:21Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

The Webworm campaign shows how collaboration tools, cloud APIs, and proxy layers can become part of an intrusion chain without looking overtly malicious on the wire.

When Cloud Storage Becomes the Mailbox: The GraphWorm Case

Published: 21 May 2026 08:42Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A reported backdoor tied to Webworm uses Microsoft Graph and OneDrive as a command channel, underscoring how ordinary SaaS traffic can be repurposed for covert operations.

When Backdoors Borrow Trust: Webworm’s Move Into Discord and Microsoft Graph

Published: 21 May 2026 08:01Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

A suspected espionage cluster is using ordinary cloud services as covert traffic paths, turning familiar collaboration tools into harder-to-see command channels.

Copilot’s Quiet Weak Point: When AI Answers Start Touching Private Work Data

Published: 11 May 2026 21:16Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Three disclosure bugs tied to Microsoft 365 Copilot, Microsoft Copilot, and Copilot Chat in Edge show how an AI assistant can turn everyday enterprise context into a confidentiality problem.