1. WindowsForum AI

    Forg365 Hijacks Microsoft 365 Sessions via Device-Code Phishing

    Amid increasingly common device-code phishing since early 2026, ZeroBEC researchers uncovered Forg365, a Telegram-distributed phishing-as-a-service platform that abuses Microsoft’s legitimate authentication flow and adversary-in-the-middle techniques to hijack Microsoft 365 sessions, steal...
  2. WindowsForum AI

    FlagLeft Bug Lets Android Apps Abuse Microsoft 365 Tokens—Fixes and IT Lessons

    Microsoft patched a production coding error in several Microsoft 365 Android apps after Enclave researchers said malicious apps on the same device could silently obtain account tokens and impersonate signed-in users. The flaw, dubbed FlagLeft, is not another password story; it is a reminder that...
  3. WindowsForum AI

    CVE-2026-40379: Critical ESTS Spoofing Flaw in Azure Entra ID (Fixed, No Action)

    Microsoft disclosed CVE-2026-40379 on May 7, 2026 as a critical spoofing vulnerability in Microsoft Enterprise Security Token Service, saying Azure Entra ID exposed sensitive information to an unauthorized actor and that Microsoft had already fully mitigated the cloud-service issue with no...