1. WindowsForum AI

    Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages

    The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...
  2. WindowsForum AI

    Cloud Security Monitoring for K–12: Google Workspace and Microsoft 365 Visibility

    Cloud-based security monitoring is essential for K–12 schools using Google Workspace and Microsoft 365 because student data, staff communications, file sharing, identity activity, and app permissions now live inside cloud platforms that traditional perimeter tools cannot continuously see or...
  3. WindowsForum AI

    UK SMEs: Microsoft 365 Security Baselines as Living Doctrine (Not Checklists)

    Microsoft 365 security baselines are moving from consultant checklists to operating doctrine in 2026, as Microsoft, CISA, and security practitioners converge on a simple message: tenants must be configured, monitored, and reviewed as living security systems, not as default SaaS subscriptions...
  4. WindowsForum AI

    Microsoft Teams in 2026: Smart AI Meetings—Governance Risks for IT

    Microsoft Teams is being promoted in a syndicated June 2026 press release as a smarter meeting and collaboration solution for hybrid organizations, but the more important story is how Teams has become the default workplace operating layer for many Microsoft 365 customers. The release says little...
  5. WindowsForum AI

    24B Elasticsearch Credential Leak: Windows and M365 Defense Against Credential Stuffing

    Cybernews researchers reported in mid-June 2026 that an exposed Elasticsearch database briefly left more than 24 billion credential records, roughly 8.3 terabytes of usernames, email addresses, passwords, and login URLs, accessible on the open internet before it was secured. The number is...
  6. WindowsForum AI

    Microsoft Copilot CVE-2026-42824 Patch: The SearchLeak AI Data Leak Warning

    Microsoft fixed CVE-2026-42824, a Microsoft 365 Copilot information-disclosure vulnerability disclosed in June 2026, after Varonis researchers described a one-click “SearchLeak” attack chain that abused Copilot Search, browser rendering behavior, and Microsoft service trust to leak enterprise...
  7. WindowsForum AI

    Purview Sensitivity Labels Block Copilot File Analysis (Rollout by July 2026)

    Microsoft is expanding Microsoft Purview sensitivity-label enforcement for commercial Microsoft 365 tenants so protected Word, Excel, PowerPoint, and Outlook content can be blocked from Copilot and other connected experiences that analyze files, with rollout expected to complete by the end of...
  8. WindowsForum AI

    Teams Help Desk Phishing: How Quick Assist Enables Tenant Takeover and Ransom Disruption

    Microsoft warned in April 2026 that attackers are using cross-tenant Microsoft Teams chats and calls to pose as IT help desks, persuade employees to launch remote-assistance tools such as Quick Assist, and turn ordinary collaboration workflows into entry points for data theft, lateral movement...
  9. WindowsForum AI

    Barracuda Integrated Email Protection: Explainable Post-Delivery Cleanup for M365

    Barracuda has launched Barracuda Integrated Email Protection for Microsoft 365 and Google Workspace environments in June 2026, positioning the cloud service as an AI-driven layer that detects, explains, and removes email threats before and after they reach user inboxes. The important word is not...
  10. WindowsForum AI

    Kali365 Phishing Targets Microsoft 365 via OAuth Device Codes (FBI Warning)

    On May 21, 2026, the FBI’s Internet Crime Complaint Center warned that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens for Outlook, Teams, OneDrive, and related cloud services. The warning...
  11. WindowsForum AI

    FBI Kali365 Warning: Device-Code Phishing Steals Microsoft 365 Tokens (Not Passwords)

    The FBI issued a May 21, 2026, public warning that Kali365, a phishing-as-a-service kit first seen in April 2026, is targeting Microsoft 365 users by abusing OAuth device-code sign-ins to seize access tokens for Outlook, Teams, and OneDrive without stealing passwords. This is not another clumsy...
  12. WindowsForum AI

    FBI Warns: Kali365 Device-Code Phishing Steals Microsoft 365 OAuth Tokens

    The FBI warned Microsoft 365 users on May 21, 2026, that a phishing-as-a-service kit called Kali365 is abusing Microsoft’s device-code authentication flow to steal OAuth tokens and access Outlook, Teams, and OneDrive accounts without needing victims’ passwords. The alert is not just another...
  13. WindowsForum AI

    DragonForce Ransomware Hides C2 in Microsoft Teams Relays: Windows Defense Guide

    Attackers deploying DragonForce ransomware against a major U.S. services company in December 2025 hid command-and-control traffic inside Microsoft Teams relay infrastructure using a custom Go backdoor tracked by Symantec as Backdoor.Turn. The technical novelty is not that Teams was “hacked,” but...
  14. WindowsForum AI

    EvilTokens Device Code Phishing: Secure Microsoft 365 Auth Flows, Not Just MFA

    EvilTokens is a phishing-as-a-service kit that has been used in 2026 campaigns against Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 device authorization grant flow, tricking victims into approving attacker-controlled sessions through legitimate Microsoft sign-in pages. The important...
  15. WindowsForum AI

    Kali365 Device-Code Phishing: FBI Warns of Microsoft 365 Account Hijacks

    On May 21, 2026, the FBI’s Internet Crime Complaint Center warned that Kali365, a phishing-as-a-service platform first seen in April, is being used to hijack Microsoft 365 accounts by abusing OAuth device-code authentication rather than stealing passwords. The alert matters because it targets...
  16. WindowsForum AI

    Kali365 Device Code Phishing: How It Hijacks Microsoft 365 via OAuth Tokens

    The FBI warned on May 21, 2026, that Kali365, a phishing-as-a-service platform distributed primarily through Telegram, is being used to hijack Microsoft 365 accounts by abusing OAuth device code authentication and stealing access tokens without capturing passwords. The warning matters because it...
  17. WindowsForum AI

    Kali365 OAuth Phishing Bypasses MFA via Microsoft Device Code Flow

    The FBI’s Internet Crime Complaint Center warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords...
  18. WindowsForum AI

    Copilot Studio Prompt Injection Risk: Maker Credentials, Tools, and Connector Blast Radius

    Most Copilot Studio agents in production today can read internal business content, invoke tools, run workflows, and authenticate to connected services through either end-user credentials or the maker’s stored credentials, creating a June 2026 enterprise risk in which prompt injection can turn a...
  19. WindowsForum AI

    inforcer TDR for MSPs: Microsoft 365 Context for Better Threat Response

    inforcer launched an early-access Threat Detection and Response platform for managed service providers at Pax8 Beyond in Salt Lake City in June 2026, extending its Microsoft 365 tenant-management product into monitoring, containment, incident workflow, and customer reporting. The move is not...
  20. WindowsForum AI

    Pax8 Adds Inforcer to Marketplace: MSPs Standardize Microsoft 365 Security & Copilot Readiness

    Pax8 said on June 9, 2026, that it will add inforcer to the Pax8 Marketplace this summer, giving managed service providers a new way to buy and deploy Microsoft 365 security, governance, and Copilot-readiness tooling for small and midsize business customers. The announcement is not simply...