Phishing
The latest Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
March 2025 Patch Tuesday: Microsoft Addresses 50+ Security Flaws Including 6 Zero-Day Exploits
Microsoft's March 2025 Patch Tuesday has arrived with critical updates addressing over 50 security vulnerabilities, including six actively exploited zero-day flaws affecting Windows 10, Windows 11,...
Microsoft Uses AI to Thwart 61% More Phishing, Spreads Defense Across Windows and Azure
Microsoft is leading a cybersecurity revolution by integrating advanced AI into its defense strategies, transforming how Windows and Azure users combat modern threats. As cyberattacks grow more...
PhaaS Kit Fuels Credential Theft on 1.4B Windows Devices and Microsoft 365
Phishing-as-a-Service (PhaaS) has emerged as a growing cybersecurity threat, particularly targeting Windows and Microsoft 365 users. This underground business model allows cybercriminals with minimal...
Microsoft Edge Zero-Day CVE-2025-26643 Sparks Active Phishing Attacks
Microsoft Edge users face a new security challenge with the discovery of CVE-2025-26643, a critical spoofing vulnerability that could expose millions to phishing attacks. This zero-day flaw in...
Master Microsoft Japanese IME: Ultimate Guide to Typing & Customization
The Microsoft Japanese Input Method Editor (IME) is an essential tool for typing in Japanese on Windows systems. It seamlessly converts Romanized input (romaji) into Japanese scripts—hiragana,...
Outage Crisis: 40,000+ Outlook Reports & Windows User Survival Guide
A major Microsoft 365 service disruption on Saturday afternoon sent shockwaves through the Windows ecosystem, with outage reports peaking at over 40,000 according to Downdetector data. The incident,...
Microsoft 365 URL @-sign exploit enables phishing attacks bypassing security filters
Microsoft 365 users are facing a new cybersecurity threat: @ Gap URL exploits. These sophisticated phishing attacks bypass traditional security measures by exploiting a little-known URL parsing...
Russian Hackers Exploit Microsoft Teams in Sophisticated M365 Phishing Attacks Using Device Code Authentication
Overview In a startling development in cybersecurity, Russian-linked threat actors have adopted a sophisticated phishing technique leveraging Microsoft Teams to target Microsoft 365 (M365) accounts....
Tycoon 2FA Phishing Kit: How to Defend Against Advanced Session Hijacking
Protect Yourself from Evolving Phishing Attacks: Tycoon 2FA Insights Cybersecurity is an ever-evolving battlefield where attackers constantly adapt to bypass defenses, and recent developments...
Storm-2372 Exploits Microsoft 365 Device Code Flow to Bypass MFA
The digital landscape for Microsoft 365 users has grown more treacherous with the emergence of Storm-2372, a sophisticated threat actor deploying a cunning phishing technique that exploits the very...
Storm-2372 Phishing Campaign Exploits Microsoft 365 Device Code Flow
The digital shadows lengthen as cybersecurity professionals sound the alarm: a sophisticated phishing campaign dubbed "Storm-2372" is actively exploiting Microsoft 365's authentication protocols,...
Russian Hackers Hijack Microsoft Device Code Auth to Bypass MFA in Phishing Attacks
Russian state-sponsored threat actors have been exploiting Microsoft's device code authentication flow in sophisticated phishing campaigns targeting Microsoft 365 users. This emerging attack vector...