Spear Phishing
The latest Spear Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
APT28's Noisy Brute Force Campaign Masks NTLM Relay Attacks Targeting Microsoft Outlook
Microsoft's security team has confirmed that Russian state-sponsored threat actor APT28, also tracked as Forest Blizzard, is conducting a sophisticated campaign that uses noisy brute force attacks as...
Microsoft Patches Critical LNK Shortcut Vulnerability CVE-2025-9491: UI Now Exposes Hidden Commands
Microsoft has finally addressed a critical security vulnerability in Windows shortcut handling that has been exploited by nation-state actors and cybercriminals for years, fundamentally changing how...
Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials
A new wave of phishing attacks targeting Microsoft 365 users is bypassing conventional email filters by weaponizing SVG image files and repurposing legitimate security tools as cloaking devices. The...
How Cybercriminals Exploit Trusted Email Security to Breach Microsoft 365
Cybercriminal activity is propelling a seismic change in the security calculus for organizations using Microsoft 365, with attackers now audaciously subverting the very email security mechanisms that...
Microsoft 365 Security: Navigating OAuth Abuse, MFA Bypass, and Evolving Cyber Threats
The escalating arms race between cyber adversaries and defenders is perhaps nowhere more visible than in the evolving threat landscape targeting Microsoft 365. Once considered a relatively safe...
Phishing in 2025: How AI and Microsoft Exploits Fuel a New Era of Cyber Threats
Phishing persists as a hydra-headed threat in 2025, evolving at a terrifying pace to outmaneuver the digital defenses of even the most sophisticated organizations. Fuelled by advances in artificial...
Calendar Phishing Alert: How Hackers Exploit Microsoft 365 Invites
Cybercriminals are increasingly exploiting Microsoft 365 calendar invites as a stealthy phishing vector, bypassing traditional email security filters. These attacks leverage the trust users place in...
How to Defend Against Calendar Phishing Scams in Microsoft 365
Microsoft 365 users are facing a sophisticated new threat that bypasses traditional email filters—calendar phishing scams. These attacks exploit the trusted nature of calendar invites, slipping...
Detect and stop Microsoft 365 calendar phishing attacks now
Cybercriminals are constantly evolving their tactics, and one of the latest threats targeting Microsoft 365 users is calendar phishing. These attacks exploit the trust users place in their digital...
Microsoft 365 Direct Send Phishing: How to Protect Your Business Now
Microsoft 365's Direct Send feature, designed to simplify email delivery for applications and devices, has become an unwitting accomplice in sophisticated phishing campaigns. Security researchers...
Rise of Internally Spoofed Phishing: Abusing Microsoft 365's Direct Send Feature
Rise of Internally Spoofed Phishing: Abusing Microsoft 365's Direct Send Feature A sophisticated phishing campaign is exploiting a legitimate Microsoft 365 feature to bypass security protocols and...
Microsoft 365 Direct Send Exploitation: How Hackers Bypass Email Security for Phishing
Microsoft 365's Direct Send feature, designed to simplify email routing for organizations, has become an unexpected weapon in sophisticated phishing campaigns. Security researchers have uncovered a...