Phishing
The latest Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
The Phishing Pipeline: How Attackers Weaponize Microsoft 365 Direct Send to Evade Every Defense
Microsoft 365’s Direct Send feature has become a double-edged sword. Designed to let printers, scanners, and applications relay mail without a dedicated mailbox, it now enables attackers to slip...
Microsoft Defender's New AI Agent Cuts Phishing Noise by 90%, Now in Public Preview
Microsoft has launched an AI-powered Phishing Triage Agent in public preview, embedding it directly into Microsoft Defender to automate the triage of user-reported phishing emails and slash...
Google Gemini Exploit Can Control Smart Homes, as Nvidia Rejects Government Backdoor Demands
A simple "thank you" is all it takes for attackers to hijack Google's Gemini AI and control your smart home, researchers revealed at Black Hat this week. The demonstration, which showed how a...
The 2025 Email Security Shift: Why Proofpoint, Mimecast, and Others Are Replacing Microsoft EOP
Microsoft Exchange Online Protection (EOP) has been the default email security gatekeeper for millions of businesses, but in 2025, a growing number of organizations are finding its basic defenses...
Internal Phishing Threats Exploiting Microsoft 365 Direct Send: Understanding and Defending Against SMTP Relay Abuse
A silent crisis is unfolding within Microsoft 365 environments as attackers turn the platform’s own trusted features against its users. The rise of sophisticated phishing campaigns leveraging...
How Phishing Attacks Exploit Enterprise Email Security Trust and Link Wrapping
For years, enterprise email security has been built on foundations of trust and automated threat detection—mechanisms like link wrapping and URL rewriting intended to shield organizations from the...
Exploiting Microsoft 365 Direct Send: A Rising Internal Phishing Threat and How to Mitigate It
The rapidly evolving landscape of cyber threats has once again placed Microsoft 365 at the forefront of organizational security concerns. Previously hailed as a linchpin of digital collaboration and...
The 2025 Surge in Sophisticated Phishing Attacks Targeting Microsoft Accounts: Strategies and Defenses
In 2025, the battleground for digital security has shifted dramatically, with Microsoft account holders standing on the front lines of an escalating war against increasingly sophisticated phishing...
2025 Microsoft 365 OAuth Phishing Attacks: Anatomy, Impact, and Defense Strategies
A rapidly escalating threat is reshaping the cybersecurity landscape for organizations dependent on Microsoft 365. In 2025, hackers unleashed a new wave of phishing attacks that leverage OAuth abuse...
Mitigating Phishing Attacks Exploiting Microsoft 365 Direct Send and SMTP Relay Vulnerabilities
Phishing attacks leveraging Microsoft 365’s Direct Send feature and unsecured SMTP relays are rapidly evolving, presenting significant risks for organizations across sectors. As cybercriminals...
How Cybercriminals Exploit Link Wrapping to Launch Sophisticated Microsoft 365 Phishing Attacks
Just as organizations have started to place their trust in security technologies designed to make email safer, a transformative threat has emerged that subverts these very foundations. Cybercriminals...
Rising Cyber Threats Exploit Email Link Wrapping Vulnerabilities in Microsoft 365
A sudden spike in sophisticated cyberattacks is shaking the foundations of email security for businesses leveraging Microsoft 365. Recent investigations have revealed an alarming vulnerability within...