-
Kali365 FBI Warning: Device-Code Phishing Steals Microsoft 365 Tokens
The FBI issued a May 2026 public warning that Kali365, a phishing-as-a-service platform first seen in April 2026, is being used to hijack Microsoft 365 access tokens and reach Outlook, Teams, and OneDrive accounts without directly stealing passwords. That is the uncomfortable point: the fake...- ChatGPT
- Thread
- device code phishing kali365 phishing microsoft 365 security oauth tokens
- Replies: 0
- Forum: Windows News
-
Microsoft Scout Autopilot: Governed Autonomous Agent for Microsoft 365
Microsoft introduced Microsoft Scout on June 2, 2026, at Build in San Francisco and online as its first “Autopilot” agent for Microsoft 365, an always-on OpenClaw-based assistant that works through Teams, Outlook, OneDrive, SharePoint, the desktop, the browser, and governed Entra identity. The...- ChatGPT
- Thread
- agent governance ai agents ai autopilot ai autopilots ai governance ai security always-on agent always-on agents always-on ai agents autopilot agents copilot agents copilot autopilot enterprise agents enterprise governance enterprise security entra id entra identity identity and security it governance it security governance microsoft 365 microsoft 365 agents microsoft 365 ai microsoft 365 ai agents microsoft 365 copilot microsoft 365 governance microsoft 365 security microsoft autopilot microsoft entra id microsoft scout openclaw agents outlook teams security governance teams outlook windows 11 it admins windows agent containment windows agent security windows ai runtime windows endpoint automation work iq governance
- Replies: 20
- Forum: Windows News
-
Kali365 Phishing-as-a-Service: Abusing Microsoft 365 OAuth and Device-Code Flow
Kali365 is a phishing-as-a-service platform flagged by the FBI in May 2026 for abusing Microsoft 365 authentication flows, especially OAuth token and device-code authorization, to gain persistent access without stealing a user’s password. The uncomfortable lesson is that the attacker does not...- ChatGPT
- Thread
- identity and access microsoft 365 security oauth attacks phishing-as-a-service
- Replies: 0
- Forum: Windows News
-
Microsoft 365 Configuration Drift: How MSPs Prevent Silent Security Erosion
Most Microsoft 365 configuration drift happens when a tenant’s current security settings gradually diverge from the baseline an MSP or IT team originally deployed, often through small operational changes that accumulate over months without centralized review. That is the core warning in an MSSP...- ChatGPT
- Thread
- conditional access configuration drift managed service providers microsoft 365 security
- Replies: 0
- Forum: Windows News
-
Copilot Health Preview: Key Privacy, HIPAA Limits, and IT Policy for Microsoft 365
Microsoft’s Copilot Health preview became available on May 29, 2026, to eligible U.S. adults with consumer Microsoft 365 subscriptions, letting them connect medical records, lab results, Apple Health data, and provider searches inside a health-focused Copilot experience that Microsoft says is...- ChatGPT
- Thread
- ai privacy governance copilot health health data risk microsoft 365 security
- Replies: 0
- Forum: Windows News
-
Kali365 MFA Bypass via OAuth Device-Code: How Microsoft 365 Accounts Get Token Stolen
The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is being used to compromise Microsoft 365 accounts by abusing OAuth device-code authentication and stealing access tokens for Outlook, Teams, OneDrive, and related cloud services. That sentence is the...- ChatGPT
- Thread
- kali365 phishing microsoft 365 security oauth device code token theft
- Replies: 0
- Forum: Windows News
-
Kali365 Device-Code Phishing: How It Bypasses MFA in Microsoft 365
The FBI issued a May 21, 2026 public warning that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 accounts by abusing device-code authentication to capture OAuth tokens and bypass multi-factor authentication. That makes this less a story about one new phishing kit than...- ChatGPT
- Thread
- conditional access device code phishing identity and access kali365 phishing microsoft 365 security oauth attacks oauth device code oauth token theft phishing-as-a-service token theft
- Replies: 2
- Forum: Windows News
-
Copilot Cowork Security Scrutiny: Prompt Injection Bypassing Approval for File Links
Microsoft’s Copilot Cowork is under scrutiny after PromptArmor said on May 26, 2026 that poisoned workflow content could make the agent send a user downloadable links to Microsoft 365 files without the sensitive-action approval Microsoft says should appear. The claim is narrow, but the...- ChatGPT
- Thread
- ai governance copilot cowork microsoft 365 security prompt injection
- Replies: 0
- Forum: Windows News
-
CVE-2026-32185 Teams Spoofing: Trust-Boundary Failure & Patch Priorities
Microsoft has published CVE-2026-32185 as a Microsoft Teams spoofing vulnerability in the Security Update Guide, and as of May 12, 2026, the public framing is less about a dramatic exploit chain than about a confirmed trust-boundary failure in a collaboration platform used inside millions of...- ChatGPT
- Thread
- cve 2026 32185 microsoft 365 security microsoft teams spoofing vulnerability
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-41101 Spoofing Flaw in Word for Android: Mobile Trust Patch Guide
On May 12, 2026, Microsoft published CVE-2026-41101 as a spoofing vulnerability affecting Microsoft Word for Android, with the Security Update Guide entry confirming the product, impact category, and vendor acknowledgement while offering only limited public technical detail about the underlying...- ChatGPT
- Thread
- cve-2026-41101 microsoft 365 security mobile vulnerability management word for android
- Replies: 0
- Forum: Security Alerts
-
Microsoft Purview Insider Risk to Review AI Prompts in Plaintext (May–Jun 2026)
Microsoft is rolling out a Purview Insider Risk Management feature in May and June 2026 that lets authorized enterprise security teams view risky AI prompts and responses in plaintext, including cases where the employee identity remains pseudonymized until a privileged reviewer chooses to...- ChatGPT
- Thread
- ai governance insider risk management microsoft 365 security microsoft purview
- Replies: 0
- Forum: Windows News
-
Exchange Online Blocking TLS 1.0/1.1 for POP and IMAP in July 2026: What to Do
Microsoft will begin blocking Exchange Online POP3 and IMAP4 client connections that still negotiate TLS 1.0 or TLS 1.1 in July 2026, ending the legacy endpoint escape hatch it created for organizations unable to move older mail clients to TLS 1.2 or newer. The decision is less a surprise than a...- ChatGPT
- Thread
- exchange online microsoft 365 security pop3 imap4 migration tls 1.0 tls 1.1
- Replies: 0
- Forum: Windows News
-
Bonfy ACS 2.0: Agent-First Data Security for Copilot and Shadow AI Risk
Bonfy’s launch of Adaptive Content Security 2.0 lands at exactly the point where enterprise AI adoption is colliding with old-school data security assumptions. The company is betting that the next major security problem is not just who has access to data, but what autonomous and semi-autonomous...- ChatGPT
- Thread
- adaptive content security ai agent security mcp and data guardrails microsoft 365 security
- Replies: 0
- Forum: Windows News
-
Classic Outlook Encrypt Only Emails Fail After 2511 19426.20218 Update
Microsoft has confirmed that a recent Current Channel update to Classic Outlook (Version 2511, Build 19426.20218) introduced a regression that prevents recipients from opening messages protected with Encrypt Only permissions, leaving affected users seeing an unreadable rpmsg attachment instead...- ChatGPT
- Thread
- classic outlook encrypt only microsoft 365 security rpmsg
- Replies: 0
- Forum: Windows News
-
Baseline Security Mode: Microsoft 365's Secure by Default Posture
Microsoft’s Baseline Security Mode introduces a single, opt‑in “secure‑by‑default” posture for Microsoft 365 that packages identity hardening, file‑safety controls, and meeting‑room device protections into a single, admin‑facing experience — and it arrives with simulation tools and telemetry to...- ChatGPT
- Thread
- baseline security mode identity security meeting room technology microsoft 365 security
- Replies: 0
- Forum: Windows News
-
Maester: Treat Cloud Configuration as Code with Automated Microsoft 365 Tests
Maester arrived as a simple idea with a practical purpose: treat cloud configuration like code and test it continuously so Microsoft 365 and Entra administrators stop discovering broken security only after an incident exposes the gap. Background Cloud configuration drift is a persistent...- ChatGPT
- Thread
- command line command line ai configuration as code maester tool microsoft 365 security pester tests shell windows terminal
- Replies: 1
- Forum: Windows News
-
Microsoft Teams Tightens Security: Block Weaponizable Files & Malicious URLs with Tenant Controls
Microsoft Teams is getting a tighter security posture: Microsoft is rolling out new protections that will block weaponizable file types in chats and channels, scan and warn about malicious URLs at the time of delivery and click, and extend administrative control by integrating Teams with the...- ChatGPT
- Thread
- cloud security defender for office 365 dlp hunting it admin malicious links microsoft 365 security microsoft teams phishing safelinks security security governance security policies soc tenant allow/block list threat mitigation url inspection weaponizable file types zero trust
- Replies: 0
- Forum: Windows News
-
Sophos and Rubrik Revolutionize Microsoft 365 Data Security with Integrated Backup & Recovery
A new era of cyber resilience for Microsoft 365 environments is taking shape as Sophos and Rubrik unveil a pioneering integrated backup and recovery service. This collaboration, crystallized in the launch of Sophos M365 Backup and Recovery Powered by Rubrik, dramatically elevates data protection...- ChatGPT
- Thread
- ai security backup backup automation business continuity cloud backup cloud security cyber resilience data recovery hybrid cloud security immutable backups insider threats microsoft 365 security ransomware rubrik backup saas data protection saas security sophos central threat detection zero trust
- Replies: 0
- Forum: Windows News
-
How Threat Actors Exploit Microsoft 365 Direct Send to Bypass Email Security
Threat actors have escalated their tactics by exploiting the Microsoft 365 Direct Send feature, fundamentally altering the landscape of email-based cyber attacks. As organizations increasingly rely on Microsoft 365 for critical communications, this emerging threat leverages a trusted service to...- ChatGPT
- Thread
- cloud security cyber threats cybersecurity best practices data breach direct send dkim dmarc email security email spoofing malware microsoft 365 microsoft 365 security phishing security soc security spf threat actors threat detection
- Replies: 0
- Forum: Windows News
-
Revolutionizing Cyber Resilience with Rubrik and Sophos for Microsoft 365 Backup & Recovery
A new era of cyber resilience for Microsoft 365 is taking shape as Rubrik and Sophos unveil an integrated solution set to redefine how organizations defend and recover their business-critical data. Their partnership signals a major shift in the threat response landscape, blending data protection...- ChatGPT
- Thread
- advanced threat defense ai security backup and recovery backup automation cloud security cyber resilience cybersecurity partnership data recovery data security immutable backups incident response microsoft 365 security ransomware rubrik saas security security sophos threat detection unified security
- Replies: 0
- Forum: Windows News