Phishing
The latest Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft 365 ATO Attacks Exploit Axios and Node Fetch — How to Defend
Microsoft 365 remains one of the most targeted platforms for cybercriminals, with account takeover (ATO) and brute force attacks posing significant threats to enterprise security. As organizations...
Emerging Phishing Threat: Exploiting OAuth 2.0 in Azure AD
Introduction A sophisticated phishing campaign has recently been identified, targeting the OAuth 2.0 authorization code flow within Microsoft Azure Active Directory (Azure AD). This attack vector...
Microsoft Teams' AI & Security Upgrades Reshape Asia-Pacific Collaboration
The digital collaboration landscape across Asia-Pacific is shifting underfoot as Microsoft rolls out a series of consequential updates to its Teams platform, blending artificial intelligence...
Infrastructure Laundering Exposed: How FUNNULL Exploits AWS & Azure for Cybercrime
A sophisticated new cybercrime technique called "infrastructure laundering" is enabling threat actors to camouflage malicious operations within legitimate cloud platforms like Amazon Web Services...
Microsoft Teams Launches Real-Time AI Phishing Alerts for Enterprise Security
Microsoft Teams has taken a significant leap forward in cybersecurity with the introduction of built-in phishing alerts, offering organizations enhanced protection against one of the most pervasive...
Microsoft Teams Rolls Out Advanced Phishing Alert System to Combat Brand Impersonation and Enhance Security
Microsoft Teams Introduces Phishing Alert System: Enhancing User Protection Against Brand Impersonation Microsoft has launched a new phishing attack alert system within Microsoft Teams, a vital move...
Microsoft Edge Zero-Day Flaw Lets Attackers Spoof Trusted Websites
Understanding CVE-2025-21262: Microsoft Edge Spoofing Vulnerability Explained Microsoft Edge users face a new security threat with the discovery of CVE-2025-21262, a critical spoofing vulnerability...
Ransomware Attacks on Microsoft 365 Surge 300%—Deploy Zero Trust Now
Microsoft 365 has become the latest battleground in the escalating war against ransomware, with cybercriminals increasingly targeting enterprise accounts through sophisticated phishing campaigns and...
Microsoft 365 Users Warned of FIN7 Phishing and Ransomware Surge
Microsoft 365 users are facing an escalating wave of sophisticated cyber threats, with phishing campaigns and ransomware attacks exploiting the platform's collaboration features. Security researchers...
Microsoft 365 Users Warned: New FlowerStorm Phishing Bypasses 2FA
Microsoft 365 accounts are increasingly targeted by sophisticated phishing campaigns that bypass traditional two-factor authentication (2FA) protections. Security researchers have uncovered a new...
Phishing-as-a-Service Platforms Exploit 2FA Vulnerabilities in Microsoft 365
Introduction In recent years, cybercriminals have significantly advanced their tactics, particularly through the emergence of Phishing-as-a-Service (PhaaS) platforms. These services enable attackers...