microsoft365 (4)

31267256481?profile=RESIZE_400xA new social engineering campaign has been discovered in which attackers are using fake passkeys and IT support requests to gain access to Microsoft 365 accounts. Microsoft Threat Intelligence has tracked the activity since May 2026 and says several threat actors, including Storm-3121 and Storm-3032, use these initial-access methods.  The company links Storm-3121 activity to ShinyHunters and Falcon extortion, while Storm-3032 represents actors that split from BlackFile and now operate under the

31266419499?profile=RESIZE_180x180Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time.  The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems.  Victims are directed to what appears to be a legitimate login process, allowing the service to collect credentials and intercept the authenticated session after the user enters a password and completes multi-fac

31175848294?profile=RESIZE_400xThe US Federal Bureau of Investigation (FBI) has issued a public service announcement warning organizations and individuals about Kali365, a Phishing-as-a-Service (PhaaS) platform first observed in April 2026.  The service is distributed primarily through Telegram and enables even less-technical attackers to hijack Microsoft 365 accounts by stealing OAuth access and refresh tokens, bypassing the need for passwords or multi-factor authentication (MFA).  This gives almost anyone the means to carry

31125377479?profile=RESIZE_400xAcross boardrooms and IT departments, a dangerous assumption continues to grow because data resides in Microsoft 365 and Azure it is automatically secure.  This belief is fundamentally flawed and creates a false sense of protection that masks real exposure, turning what should be a strategic cloud advantage into a ticking time bomb quietly building risk inside the organization’s own environment.[1]

Microsoft builds the platform; it does not defend your specific environment.  What you monitor, ho