❌

Reading view

There are new articles available, click to refresh the page.

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Bill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as...

Source

Copilot is one app — and other changes

MICROSOFT 365 By Peter Deegan Microsoft is finally fixing a mess of its own making by merging two Copilot apps into one. Less obvious are other changes happening at the same time: reducing Microsoft’s costs and nudging more people toward paid AI services. Just so you’re not caught unawares, let’s go through the Copilot app […]

Push off Passkeys

ISSUE 23.35.1 • 2026-09-01 By Susan Bradley Defer the Passkeys mandate for 365. Today, Microsoft begins its official effort to move Microsoft 365 customers from traditional authentication to what it calls “phishing-resistant” methods. This means Windows Hello, passkeys, or similar multifactor authentication (MFA) methods that are more secure. For consumers using 365, this will probably […]

Windows 10 and Office

MICROSOFT 365 By Peter Deegan Microsoft recently extended the Windows 10 ESU plan until October 2027. What you might not realize is that neither Microsoft 365 updates nor Office updates are part of the ESU offering. Office 2021 support ends in mere months. Microsoft’s original plan was to offer the Windows 10 Extended Security Updates […]

This phishing kit looks more like BEC-as-a-service

Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged “business email compromise-as-a-service” platform.

Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks — by 1,380% early this year compared to the same period last year — with an assist from artificial intelligence integration.

ARToken is notable, though, for the capabilities that go beyond what’s been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.

“These features indicate the platform is more mature than a simple device code phishing kit — it is a complete BEC operations environment,” wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.

Kelley told CyberScoop that “we’ve seen some offerings that touch on this capability, but this definitely seems more fleshed out and polished than previous instances.”

ARToken is also notable for its evasive capabilities, with a seven-layer anti-analysis system, the post states.

The research provides further details on what ARToken’s actual phishing lures look like in practice. They are targeted, rather than scattershot and opportunistic, as one lure the firm examined shows.

“The messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life sciences company — abusing a real vendor relationship rather than inventing a sender,” Kelley wrote. “The lure theme is an outstanding-invoice inquiry (‘the following invoices appear to still be outstanding… advise when this will be processed’), the kind of message accounts-payable staff are conditioned to act on.”

Kelley told CyberScoop that Cisco Talos doesn’t yet have a full sense of the breadth of the activity, nor who is making use of the capability.

“We’ve seen the public sector targeted but it’s unlikely to be the only one,” he said.

The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop.

Better spreadsheets with sensible AI

ISSUE 23.26 • 2026-06-29 MICROSOFT 365 By Peter Deegan Give AI a chance to help you with any Excel or spreadsheet app. AI can greatly speed up your time spent working on a workbook — rom explaining functions and improving formulas to making a full sheet from your description. Any version of Excel, including perpetual […]

Augmenting Security Testing and Analysis Activities with Microsoft 365 Products

Use of Microsoft 365 products in security testing is not a new concept. For a long time, I’ve incorporated various activities using Office products into my testing regimen. In the […]

The post Augmenting Security Testing and Analysis Activities with Microsoft 365 Products appeared first on Black Hills Information Security, Inc..

Wrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3)

Patterson Cake // PART 1 PART 2 In part one of “Wrangling the M365 UAL,” we talked about acquiring, parsing, and querying UAL data using PowerShell and SOF-ELK. In part […]

The post Wrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3) appeared first on Black Hills Information Security, Inc..

Wrangling the M365 UAL with SOF-ELK on EC2 (Part 2 of 3)

Patterson Cake // In PART 1 of “Wrangling the M365 UAL,” we talked about the value of the Unified Audit Log (UAL), some of the challenges associated with acquisition, parsing, […]

The post Wrangling the M365 UAL with SOF-ELK on EC2 (Part 2 of 3) appeared first on Black Hills Information Security, Inc..

Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3)

Patterson Cake // When it comes to M365 audit and investigation, the “Unified Audit Log” (UAL) is your friend. It can be surly, obstinate, and wholly inadequate, but your friend […]

The post Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3) appeared first on Black Hills Information Security, Inc..

Spoofing Microsoft 365 Like It’s 1995

Steve Borosh // Why Phishing? Those of us on the offensive side of security often find ourselves in the position to test our clients’ resilience to phishing attacks. According to […]

The post Spoofing Microsoft 365 Like It’s 1995 appeared first on Black Hills Information Security, Inc..

❌