A ransomware allegation naming Microsoft surfaced with a single hash and no victim website, leaving only a narrow signal and no verified breach.
Exfilsquad is tied to a fresh victim entry that alleges millions of records, but the breach itself and the data claim remain unverified.
Microsoft corrected a public-by-default configuration and code flaws in a cloud automation service that may have created a cross-tenant identity risk, without any confirmed exploitation in the available material.
A maintenance bug in an automated network system reportedly removed IP routes from more devices than intended, showing how quickly a shared cloud backbone can turn a small error into a wide service disruption.
Attackers are using Microsoft Teams conversations to pose as internal IT support, turning a trusted workplace channel into a path for credentials, remote access, and account takeover attempts.
Microsoft’s warning points to a harder problem for defenders: attackers are increasingly exploiting the trust built into workplace communication tools, with Teams emerging as a prime social-engineering surface.
A reported campaign against hotel and conference-center Wi-Fi gateways shows how DNS manipulation and risky login flows can push Microsoft 365 users toward attacker-controlled infrastructure without email lures or endpoint malware.
A compromise at the hotel or conference network edge can steer Microsoft 365 sign-ins off course, showing how DNS tampering can become an identity attack without phishing or malware.
An ongoing outage affecting Teams, SharePoint, Excel, and the Microsoft 365 Admin Center exposes how quickly cloud productivity can turn into a business continuity problem.
Researchers flagged exploitable flaws in Microsoft’s passkey handling, a reminder that passwordless systems still depend on careful implementation, especially around privileged access.
Microsoft is working to resolve an Exchange Online issue that is mistakenly quarantining customer mailboxes, a reminder that cloud email controls can fail without any attacker in sight.
Defender for Office 365 is now being used to blunt prompt injection, a reminder that enterprise email is becoming an input channel for assistants as much as a message stream for humans.
Defender for Office 365 is now inspecting inbound email for hidden AI instructions before they can reach a mailbox or be consumed by Microsoft 365 Copilot.
The October cutoff for Exchange 2016 and Exchange 2019 turns a support notice into a planning deadline for any organization still depending on those mail servers.
A legitimate Microsoft sign-in path is being treated as an attack surface, where user approval can hand an adversary a valid session without breaking the protocol itself.
AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.
A law-enforcement takedown of the Kratos phishing kit underscores a harder truth for cloud defenders: attackers are increasingly chasing live Microsoft 365 sessions, not just login credentials.
AiTM phishing can turn a routine vendor request into a live browser hijack, letting attackers reuse an authenticated Microsoft 365 session even after MFA is completed.
The expanded Microsoft-Mistral partnership shows how enterprise AI is shifting toward regulated deployments, local control, and model choice across cloud, edge, and disconnected environments.
A critical deserialization flaw in Microsoft SharePoint Server has moved from patch note to active-risk territory, reminding defenders how fast a single missed update can become an entry point.