Live
Malicious Microsoft 365 Logins Surge 25% from US, UK—Stop Trusting Low-Risk Country Checkmarks·MSFT +2.1%Huntress Flags Rampant M365 Identity Gaps: MFA Neglect, Admin Overprivilege, Weak Passwords·NVDA +0.2%FBI Warns of Kali365 Phishing Platform Hijacking Microsoft 365 via Device Code Attacks·GOOGL +1.7%Microsoft's Agentic Enterprise Platform Unifies AI Agent Governance Across M365, Azure, and Security·AMZN +1.1%Always On, Always Governed: Inside Microsoft Scout's Agent Identity Model·MSFT +2.1%MSPs Combat Microsoft 365 Configuration Drift to Stop Silent Security Erosion·NVDA +0.2%Microsoft Copilot Health Preview Raises HIPAA, Privacy Risks for M365 IT Admins·GOOGL +1.7%FBI Warns Kali365 Phishing Steals OAuth Tokens to Bypass MFA in Microsoft 365·AMZN +1.1%Malicious Microsoft 365 Logins Surge 25% from US, UK—Stop Trusting Low-Risk Country Checkmarks·MSFT +2.1%Huntress Flags Rampant M365 Identity Gaps: MFA Neglect, Admin Overprivilege, Weak Passwords·NVDA +0.2%FBI Warns of Kali365 Phishing Platform Hijacking Microsoft 365 via Device Code Attacks·GOOGL +1.7%Microsoft's Agentic Enterprise Platform Unifies AI Agent Governance Across M365, Azure, and Security·AMZN +1.1%Always On, Always Governed: Inside Microsoft Scout's Agent Identity Model·MSFT +2.1%MSPs Combat Microsoft 365 Configuration Drift to Stop Silent Security Erosion·NVDA +0.2%Microsoft Copilot Health Preview Raises HIPAA, Privacy Risks for M365 IT Admins·GOOGL +1.7%FBI Warns Kali365 Phishing Steals OAuth Tokens to Bypass MFA in Microsoft 365·AMZN +1.1%

Microsoft 365 Security

The latest Microsoft 365 Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:50 PM
Latest Most Read Breaking
Sort
Identity And Access · Mfa And Conditional Access

Malicious Microsoft 365 Logins Surge 25% from US, UK—Stop Trusting Low-Risk Country Checkmarks

Malicious login attempts targeting Microsoft 365 accounts from the United States and United Kingdom soared by roughly 25 percent in April 2026, according to new data from Barracuda Networks. The...

Advertisement
Agent Governance · Ai Agents

Always On, Always Governed: Inside Microsoft Scout's Agent Identity Model

Microsoft took the wraps off Scout on June 2, 2026 at its Build conference, an always-on AI agent for Microsoft 365 that operates with its own governed Entra identity—a major step beyond simple...

AI AI & Copilot Desk·7w ago
Conditional Access · Configuration Drift

MSPs Combat Microsoft 365 Configuration Drift to Stop Silent Security Erosion

When a mid-sized accounting firm underwent a routine cyber insurance assessment, the results shook the IT director. The company’s Microsoft 365 environment, initially configured with strict...

SE Security Desk·7w ago
Ai Privacy Governance · Copilot Health

Microsoft Copilot Health Preview Raises HIPAA, Privacy Risks for M365 IT Admins

Microsoft opened the Copilot Health preview to consumer Microsoft 365 subscribers in the United States on May 29, 2026, giving eligible adults the ability to connect medical records, lab results, and...

AI AI & Copilot Desk·7w ago
Conditional Access · Device Code Phishing

FBI Warns Kali365 Phishing Steals OAuth Tokens to Bypass MFA in Microsoft 365

The FBI has issued an urgent public warning about a phishing-as-a-service platform called Kali365 that is systematically targeting Microsoft 365 accounts by abusing device-code authentication. The...

SE Security Desk·7w ago
Ai Governance · Copilot Cowork

Prompt Injection in Copilot Cowork Lets Attackers Steal M365 Files Without Approval

A critical vulnerability in Microsoft's Copilot Cowork agent can be exploited to exfiltrate sensitive Microsoft 365 files, security researchers warned on May 26, 2026. PromptArmor disclosed that by...

AI AI & Copilot Desk·8w ago
Cve 2026 32185 · Microsoft 365 Security

CVE-2026-32185: Microsoft Teams Spoofing Exposes Critical Trust-Boundary Failure, Patch Now

{ "title": "CVE-2026-32185: Microsoft Teams Spoofing Exposes Critical Trust-Boundary Failure, Patch Now", "content": "Microsoft published CVE-2026-32185 in its Security Update Guide on May 12,...

SE Security Desk·10w ago
Cve-2026-41101 · Microsoft 365 Security

Word for Android Spoofing Flaw: CVE-2026-41101 Fix via Play Store

Microsoft’s May 2026 security updates include a fix for CVE-2026-41101, a spoofing vulnerability in Word for Android that could undermine trust in the mobile document editing experience. Published...

SE Security Desk·10w ago
Ai Governance · Insider Risk Management

Microsoft Purview to Reveal Risky AI Prompts in Plaintext by June 2026

Microsoft has confirmed that a powerful new capability is coming to its Purview Insider Risk Management platform, set to roll out between May and June 2026. Enterprise security teams will soon be...

AI AI & Copilot Desk·10w ago