Phishing
The latest Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
Storm-237 Exploits Microsoft Device Code Auth to Bypass MFA on Microsoft 365
Storm-237: The Rising Threat of Device Code Phishing Targeting Microsoft 365 Microsoft 365 users are facing a sophisticated new threat from a Russian cybercriminal group known as Storm-237. This...
Storm-2372 device-code phishing bypasses MFA in Microsoft Teams attacks
Microsoft Teams has become the latest target in a sophisticated phishing campaign dubbed Storm-2372, putting millions of users at risk. Cybersecurity researchers have uncovered a new device code...
Storm-2372 Phishing Bypasses MFA: Device Code Attack Exposes Windows Users
The Storm-2372 phishing campaign has emerged as a sophisticated threat targeting Windows users, exploiting Device Code Authentication vulnerabilities to bypass multi-factor authentication (MFA). This...
Device Code Phishing: How Russian Spies Exploit Microsoft 365 via OAuth Protocols
Russian state-sponsored hackers have developed a sophisticated new phishing technique that bypasses traditional security measures by exploiting Microsoft 365's device code authentication flow. Known...
Russian Cyber Attacks Exploit Microsoft 365 Device Code Authentication in Phishing Campaigns
Russian state-sponsored hackers are actively exploiting Microsoft 365's device code authentication flow in sophisticated phishing campaigns targeting government and corporate networks. Cybersecurity...
Exploiting Microsoft Device Code Authentication: An Emerging Threat to Microsoft 365 Security
Introduction In recent months, cybersecurity researchers and Microsoft have uncovered a sophisticated new threat targeting Microsoft 365 (M365) accounts through an unexpected vulnerability: the...
Protecting Your Microsoft 365: Beware the New Phishing Campaign Targeting Device Code Authentication
Microsoft 365 users are facing a sophisticated new phishing campaign that exploits device code authentication, putting sensitive business data at risk. Security researchers have identified this...
Debunking the Email Security Myth: Enhancing Protection for Windows Users
Introduction In today's digital landscape, email serves as the backbone of both personal and professional communication. Windows users, in particular, often rely on popular cloud-based email services...
Outlook spoofing flaw CVE-2025-21259 demands immediate patch and config fixes
Microsoft Outlook Vulnerability CVE-2025-21259: Spoofing Risks and Mitigation A newly discovered vulnerability in Microsoft Outlook, tracked as CVE-2025-21259, has raised significant security...
Microsoft 365 SRS Feature Weaponized in Advanced PayPal Phishing Attacks
A sophisticated new phishing campaign is exploiting Microsoft 365's Sender Rewrite Scheme (SRS) feature to bypass email security measures and target PayPal users with convincing scam messages....
HTTP Client Attacks Bypass MFA in Microsoft 365—Deploy Conditional Access Now
Microsoft 365 remains one of the most widely used productivity suites in the enterprise world, but its popularity also makes it a prime target for cybercriminals. Among the latest threats, HTTP...
Microsoft 365 Security Guide: Essential Practices to Block 99.9% of Attacks
Microsoft 365 has become the backbone of productivity for millions of businesses worldwide, but its widespread adoption also makes it a prime target for cyber threats. As organizations increasingly...