Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Microsoft 365
#Microsoft 365

How One Phishing Email Let Attackers Bypass MFA and Redirect a Company’s Vendor Payments

21 August 2026  |  dark6  |  Phishing

An HR-themed phishing lure led a finance employee to a fake Microsoft 365 login that stole an authenticated session cookie, letting attackers bypass MFA entirely. Over the following...

>> read more

Microsoft Is Merging Consumer and Enterprise Copilot — Security Teams Should Watch the Seams

17 August 2026  |  dark6  |  AI

Microsoft is consolidating its consumer and business Copilot apps into a single Microsoft 365 Copilot experience, reachable from a unified m365.cloud.Microsoft address. Microsoft insists personal and organizational data...

>> read more

New Outlook Flaw Lets Attackers Run Malicious Code Through a Single Booby-Trapped Email Attachment

14 August 2026  |  dark6  |  Vulnerability

Microsoft has patched a high-severity remote code execution flaw in Outlook, tracked as CVE-2026-70329, that can be triggered when a victim opens a specially crafted Office file. The...

>> read more

Microsoft Is Giving Teams Admins a Single Dashboard to Catch Phishing and Malware in Chats

10 August 2026  |  dark6  |  Phishing

Microsoft is rolling out a new Security Detection Report inside the Teams admin center that consolidates impersonation attempts, malicious links, and dangerous file types into one exportable dashboard....

>> read more

Greatness Phishing Service Lets Attackers Slide Past MFA Into Microsoft 365 Inboxes

6 August 2026  |  dark6  |  Phishing

A phishing-as-a-service platform called Greatness is stealing live authentication tokens rather than passwords, letting attackers walk past multi-factor authentication and into Microsoft 365 mailboxes. A recent campaign hid...

>> read more

Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm

30 July 2026  |  dark6  |  AI

A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...

>> read more

HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel

21 July 2026  |  dark6  |  Malware

Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...

>> read more

New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts

4 July 2026  |  dark6  |  Phishing

Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft's device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The...

>> read more