New Microsoft 365 Attack Bypasses Email Security Controls

Posted: 14th Mar 2025

Sometimes it can feel like Microsoft users are on the sharp end of the cybersecurity stick a little too often. Be that by way of multiple zero-day vulnerabilities actively exploiting Windows users, or Microsoft Account takeovers that bypass authentication protections. Microsoft 365 users, however, could certainly be excused for feeling hard done by in the attack stakes with hackers exploiting technical gaps to manipulate URLs, or basic authentication exploitation by spray and pray password campaigns. Now, Microsoft 365 users have been warned as a new and sophisticated attack bypasses traditional email security controls by embedding phishing lures within legitimate Microsoft communications. Here’s what you need to know.

View Full Article

Related Articles

Popular Articles

Cyber Risk Exposure Management (CREM), part of Trend Vision One™, proactively reduces cyber ri...
Business Email Compromise (BEC) attacks don’t need malware to do damage. All it takes is one c...
Ride the perfect Azure migration wave with Advantage PASS™ Time to unlock privileged Microsof...
Making business-critical data always available with Disaster Recovery as a Service Covenco’s ...