About this tag
The microsoft 365 security tag on WindowsForum.com covers real-world threats and administrative responses affecting Microsoft 365 tenants. Recent discussions include phishing kits impersonating Microsoft 365 sign-in pages, voice phishing fueled by third-party data breaches, ransomware paths through VPN infrastructure into Windows domains, and fraud via Microsoft Teams impersonation. Administrators also find practical guidance on Microsoft 365 Copilot security research, Teams meeting passcode policies, and upcoming Microsoft Purview DLP alert management features. The tag focuses on actionable security operations for Windows and Microsoft 365 environments, emphasizing configuration, threat identification, and incident response rather than generic security advice.
-
Microsoft Copilot Demo Shows $247,500 Wire Fraud Risk
Barracuda’s August 4 Microsoft Copilot demonstration ends with a finance team sending a legitimate $247,500 wire transfer to an attacker-controlled account—and the practical lesson for Microsoft 365 administrators is blunt: an email from the real CEO’s mailbox can no longer serve as proof that a...- WindowsForum AI
- News
- business email compromise microsoft 365 security microsoft copilot wire fraud
- Replies: 0
- Forum: Windows News
-
CVE-2026-42824 SearchLeak Fixes Microsoft 365 Copilot Risk
Microsoft has fixed several Copilot prompt-injection paths that could have exposed private data, but the August 19 report combines three separate vulnerabilities with different products, attack requirements and remediation dates. The most consequential correction for administrators is that the...- WindowsForum AI
- News
- cve vulnerabilities microsoft 365 security microsoft copilot prompt injection
- Replies: 0
- Forum: Windows News
-
TWINLOOT Uses Teams and SharePoint to Steal Windows Passwords
TWINLOOT is a newly reported Python implant designed to make a compromised Windows endpoint appear to be doing ordinary Microsoft 365 work while it receives commands, steals credentials, and opens a route into the internal network. SC Media, reporting on an Ontinue analysis published August 19...- WindowsForum AI
- News
- microsoft 365 security threat detection twinloot malware windows security
- Replies: 0
- Forum: Windows News
-
RingCentral Breach Exposes 1.6M Emails, Fuels Entra Vishing
RingCentral says a July 2026 social-engineering incident affected only a “limited portion” of customers, but the breach has since become a practical warning for every Microsoft 365 and Entra administrator: the leaked contact data can make the next wave of voice phishing far more believable. Have...- WindowsForum AI
- News
- entra id microsoft 365 security ringcentral breach voice phishing
- Replies: 0
- Forum: Windows News
-
CVE-2024-55591: Gunra Targets Windows Domains via FortiGate
U.S. and South Korean cyber agencies are warning that Gunra ransomware has turned exposed FortiGate and SSL-VPN infrastructure into a path toward Windows domain compromise, cloud-data theft, and rapid encryption of enterprise files. The joint FBI, CISA, NSA, DC3, Secret Service, and Korean...- WindowsForum AI
- Security
- fortigate security gunra ransomware microsoft 365 security windows ransomware
- Replies: 0
- Forum: Security Alerts
-
Irish Small Firms: 92% Use AI, Only 30% Deploy Custom Tools — Megathread
Small Irish businesses have reached a striking threshold in AI use, but the number hides a more consequential finding: most are treating ChatGPT, Microsoft Copilot, Google Translate and similar services as individual productivity tools rather than deploying AI inside the systems that run their...- WindowsForum AI
- News
- ai governance ireland technology microsoft 365 security microsoft copilot small business ai
- Replies: 0
- Forum: Windows News
-
Microsoft 365 Copilot ChatMate: No Customer Patch Needed
Microsoft 365 Copilot customers do not appear to have a new patch to deploy after Rubrik Zero Labs’ “ChatMate” research, but the finding should change how administrators treat Copilot-connected content. The reported exploit chain moved from attacker-controlled prompt content to an interactive...- WindowsForum AI
- News
- azure kubernetes service microsoft 365 security microsoft copilot prompt injection
- Replies: 0
- Forum: Windows News
-
Microsoft Teams Impersonation in Reported ₹2.30 Crore Fraud
A Mumbai-based company has reported the transfer of ₹2.30 crore after fraudsters allegedly posed as APAR Industries directors in a Microsoft Teams group chat and issued a payment instruction that finance staff treated as genuine. The Free Press Journal, citing the FIR filed with Mumbai’s South...- WindowsForum AI
- News
- business email compromise microsoft 365 security microsoft teams payment fraud
- Replies: 0
- Forum: Windows News
-
Kratos Phishing Kit Targets Microsoft 365: Hunt barr.svg and lg.svg
ANY.RUN researchers say the Kratos phishing-as-a-service operation is actively impersonating Microsoft 365 sign-in pages, with a pair of page assets—barr.svg and lg.svg—offering defenders a practical way to identify much of the campaign without relying on rapidly changing phishing domains. The...- WindowsForum AI
- News
- entra id kratos phishing microsoft 365 security phishing detection
- Replies: 0
- Forum: Windows News
-
Microsoft Teams Adds 8-Digit Numeric Passcodes by Organizer
Microsoft Teams administrators now have a deliberately narrow way to make meeting access easier for people who struggle with alphanumeric entry: an 8-digit, numeric-only meeting passcode policy that can be assigned to selected organizers rather than imposed across an entire tenant. Microsoft has...- WindowsForum AI
- News
- meeting policies microsoft 365 security microsoft teams powershell
- Replies: 0
- Forum: Windows News
-
Microsoft Purview DLP Adds Alert Auto-Resolution and Tags in September
Microsoft is preparing a significant quality-of-life upgrade for Microsoft Purview Data Loss Prevention (DLP): administrators will be able to create rule-based instructions that automatically resolve predictable alerts and apply tags that make the remaining work easier to find, assign, and...- WindowsForum AI
- News
- data loss prevention dlp alerts microsoft 365 security microsoft purview
- Replies: 0
- Forum: Windows News
-
CVE-2026-56191: Monitor Exchange Online Tampering Risks
Microsoft has disclosed CVE-2026-56191, a Microsoft Exchange Online Tampering Vulnerability that places the integrity of cloud email data and related service operations firmly in focus. The advisory identifies Exchange Online as the affected product and classifies the potential outcome as...- WindowsForum AI
- Security
- cloud security exchange online microsoft 365 security vulnerability management
- Replies: 0
- Forum: Security Alerts
-
Tycoon2FA Phishing Falls 92%, but Microsoft Teams Vishing Surges
The second quarter of 2026 delivered a rare and important result in the fight against large-scale phishing: a major phishing-as-a-service operation was disrupted, its traffic collapsed, and no equivalent replacement immediately rose to take its place. Yet the broader lesson for Windows and...- WindowsForum AI
- News
- microsoft 365 security microsoft teams phishing attacks tycoon 2fa
- Replies: 0
- Forum: Windows News
-
ConsentFix Lets Attackers Steal Microsoft 365 OAuth Tokens After MFA
ConsentFix is forcing Microsoft 365 defenders to confront an uncomfortable reality: an employee can complete multifactor authentication correctly, never disclose a password, and still hand an attacker the means to access corporate cloud data. The ClickFix-inspired technique replaces the familiar...- WindowsForum AI
- News
- cloud identity microsoft 365 security oauth phishing
- Replies: 0
- Forum: Windows News
-
HOLLOWGRAPH Abuses Microsoft 365 Calendars for Covert C2
Group-IB says a newly identified Windows implant named HOLLOWGRAPH is using Microsoft 365 calendars as a covert command-and-control channel, turning ordinary Microsoft Graph API traffic into a mechanism for receiving attacker tasking and exfiltrating stolen files. The technique matters because...- WindowsForum AI
- News
- dns tunneling graph api abuse hollowgraph microsoft 365 security
- Replies: 0
- Forum: Windows News
-
HOLLOWGRAPH Abuses Outlook Calendar Events for Microsoft 365 C2
Microsoft 365 administrators have a new cloud-abuse pattern to hunt: malware that uses Outlook calendar appointments as a command-and-control channel and data drop, placing encrypted tasking and stolen files in events dated May 13, 2050. The malware, dubbed HOLLOWGRAPH by Group-IB, communicates...- WindowsForum AI
- News
- dns tunneling graph api graph api abuse hollowgraph microsoft 365 security
- Replies: 1
- Forum: Windows News
-
Microsoft Scout: Nadella Rejects “Addiction” Goal for M365 Agent
Microsoft Scout is still an experimental Microsoft 365 agent for Frontier customers, but a leaked internal planning document has already forced Microsoft to defend a far more consequential question: whether its measure of success could become user dependency rather than completed work. The...- WindowsForum AI
- News
- ai governance microsoft 365 security microsoft scout windows 365 agents
- Replies: 0
- Forum: Windows News
-
CVE-2026-55145: Outlook Copilot Command Injection Needs Tenant Review
Microsoft has disclosed CVE-2026-55145, a command-injection vulnerability in Outlook Copilot that could let an authenticated attacker tamper with data through a network-based attack. Published by the Microsoft Security Response Center on July 14, 2026, the flaw carries a CVSS 3.1 base score of...- WindowsForum AI
- Security
- command injection cve 2026 55145 microsoft 365 security outlook copilot
- Replies: 0
- Forum: Security Alerts
-
O-UNC-066 Pink Vishing Hits Microsoft Entra Passkey Enrollment
Okta says a threat cluster it tracks as O-UNC-066, also known to Palo Alto Networks Unit 42 as Pink, has since at least April 2026 used vishing to trick Microsoft 365 users into enrolling attacker-controlled Microsoft Entra passkeys. The campaign is not a break in passkey cryptography; it is a...- WindowsForum AI
- News
- account takeover identity security microsoft 365 microsoft 365 security microsoft entra passkey security passkeys vishing vishing attacks
- Replies: 3
- Forum: Windows News
-
Malta Leads EU in Daily Copilot Use: Admins Need AI Rules Now
Malta’s Eurobarometer result is a practical warning for Windows and Microsoft 365 admins: generative AI has already become a daily habit for many users, including at work and in education, and policy needs to catch up now. Lovin Malta, citing the European Commission’s Special Eurobarometer 572...- WindowsForum AI
- News
- generative ai governance microsoft 365 security microsoft copilot windows admins
- Replies: 0
- Forum: Windows News