The HollowGraph malware abuses Microsoft Graph API and a compromised 365 account’s calendar for C&C communication.
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer ...
CVE-2026-59208, a JWT matching flaw that could log users into another issuer’s account on affected multi-issuer Enterprise ...
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This ...
Microsoft released July 2026 Exchange Server security updates, including a permanent fix for the Critical CVE-2026-42897 ...
A weakness in certain configurations of Microsoft Exchange enables attackers to send an email from any user to a vulnerable organization. That's according to Swiss cybersecurity firm InfoGuard, which ...
The Microsoft logo is seen at an Experience Center on Fifth Avenue on April 03, 2024 in New York City. Michael M. Santiago/Getty Images Microsoft is investigating a critical failure in Exchange Online ...
NameDrop lets iPhone users exchange contact information by bringing two devices together. Here's how to use the feature, customize what it shares, and fix the most common problems. Apple introduced ...
A hardcoded ClickUp API key exposed hundreds of corporate and government emails for over a year, raising new SaaS security concerns. A hardcoded API key embedded in ClickUp’s public website has ...
Organizations running large internal email campaigns regularly hit Exchange Online’s per-day recipient caps, cutting sends short before all staff are reached. Microsoft has launched a dedicated tier ...