readwriteitem (1)

31083913879?profile=RESIZE_400xResearchers at Varonis Threat Labs have disclosed a proof-of-concept attack technique that enables the silent exfiltration of outgoing emails from Microsoft 365 accounts using legitimate Outlook add-ins.  Named Exfil Out&Look, the method exploits Outlook Web Access (OWA) to intercept and transmit email content without generating forensic traces in audit logs.  The technique involves creating a custom Outlook add-in with standard web technologies, including a manifest file that specifies minimal