CuraSec

tag: Microsoft-365 · 12 items

  • Engineer — Plan: AiTM phishing that defeats standard MFA is a config problem, not a patch problem — audit your Entra ID Conditional Access policies and prioritize migrating M365 users to phishing-resistant MFA (FIDO2/passkeys) this quarter, as TOTP and SMS are insufficient against this class of attack.
  • SOC/IR — Act: This campaign is active and broadly targeting US enterprises via M365; hunt for AiTM indicators in Entra ID sign-in logs now — flag token issuance from unexpected IPs, session establishment followed by unusual API activity, and impossible-travel events from the same session cookie.
  • Leader — Act: With 4,500 organizations targeted and ~48% of targeted addresses potentially compromised, confirm with your team this week that phishing-resistant MFA is enforced for M365 and assess whether your domain appeared in ANY.RUN’s targeting data; this is board-question territory given the scale.
2026-08-19 · The Hacker News · source ↗ #malware#microsoft-365#c2
  • Engineer — Learn: No exploitation signals or patch action required, but this technique highlights the risk of trusting M365 egress unconditionally; review whether SharePoint/Teams API access from non-user contexts is logged and anomaly-monitored in your environment.
  • SOC/IR — Plan: TWINLOOT’s C2-over-SharePoint-Online pattern blends into legitimate M365 traffic — build or tune detections for unusual SharePoint file polling cadence and Teams API calls from non-interactive service contexts to catch implants using this framework.
  • Leader — Learn: Newly documented implant class that weaponizes trusted M365 services, useful context for future conversations about M365 security controls and monitoring investment, but no confirmed active campaigns require immediate leadership action.
2026-08-07 · The Hacker News · source ↗ #phishing#microsoft-365#aitm
  • Engineer — Plan: Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.
  • SOC/IR — Act: Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.
  • Leader — Plan: An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.
  • Engineer — Plan: AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.
  • SOC/IR — Plan: Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.
  • Leader — Learn: Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.
2026-08-04 · BleepingComputer · source ↗ #apt29#microsoft-365#credential-theft
  • Engineer — Learn: No patch or configuration fix addresses this attack path — it exploits network position, not a software vulnerability. Review M365 Conditional Access policies to enforce device compliance and block legacy auth as a longer-term hardening measure.
  • SOC/IR — Act: APT29 campaign with confirmed M365 targeting warrants a hunt for anomalous OAuth token activity and sign-ins from hotel/travel IP ranges since early 2026; tune Conditional Access sign-in logs for impossible-travel or unfamiliar network anomalies and brief on-call on the TTP.
  • Leader — Plan: Nation-state targeting of business travelers via hotel networks is a reputational and credential-risk issue worth a travel security advisory this quarter; if your org has frequent international travel, update travel security policy and consider M365 session controls for roaming users.
2026-07-25 · BleepingComputer · source ↗ #microsoft-365#cloud-outage#vendor-risk
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Plan: The incident underscores M365 concentration risk — review business continuity and failover plans for M365 dependency, and request a resilience briefing from your Microsoft account team this quarter.
2026-07-25 · BleepingComputer · source ↗ #phishing#dns-hijacking#microsoft-365
  • Engineer — Plan: Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.
  • SOC/IR — Act: Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.
  • Leader — Learn: A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.
2026-07-22 · The Hacker News · source ↗ #phishing#mfa-bypass#microsoft-365
  • Engineer — Learn: Kratos used adversary-in-the-middle techniques to steal M365 session tokens and bypass MFA — a reminder that TOTP/push-based MFA is insufficient against phishing; engineers should evaluate phishing-resistant MFA (FIDO2/passkeys) for privileged M365 accounts.
  • SOC/IR — Learn: No IOCs or detection specifics are provided, so no immediate hunt is actionable; the takedown does validate that AiTM session-token theft against M365 was widespread, which reinforces monitoring for anomalous token reuse and impossible-travel sign-ins if not already covered.
  • Leader — Learn: The scale of Kratos confirms that MFA bypass via phishing is not theoretical — useful evidence when making the case for phishing-resistant MFA investment or reviewing identity risk with the board; no immediate action required given the infrastructure has been seized.
2026-07-21 · The Hacker News · source ↗ #microsoft-365#c2-abuse#espionage
  • Engineer — Plan: Novel Graph API abuse using calendar write access highlights over-permissioned OAuth app risk. Audit which apps hold Microsoft Graph calendar read/write scopes and revoke unnecessary permissions this quarter.
  • SOC/IR — Act: The year-2050 calendar event timestamp is a highly specific, huntable indicator — sweep M365 audit logs for calendar events created with 2050 dates and flag Graph API calls that write calendar entries with large attachments.
  • Leader — Learn: Espionage actors using legitimate Microsoft 365 infrastructure for C2 blurs the line between sanctioned SaaS activity and intrusion; useful context for understanding the M365-as-attack-surface risk but no immediate leadership action required.
2026-07-21 · BleepingComputer · source ↗ #malware#microsoft-365#c2
  • Engineer — Learn: Novel living-off-the-land C2 technique abusing legitimate Microsoft Graph calendar APIs to blend into normal M365 traffic; no patch exists but worth reviewing M365 conditional-access and app-permission scopes to limit blast radius of compromised accounts.
  • SOC/IR — Plan: Build or tune detection for anomalous Graph API calendar activity (unexpected event creation, unusual read patterns from non-user agents) in M365 audit logs; no published IOCs yet, but the TTP is concrete enough to start a detection rule in Sentinel or Elastic against Graph audit data.
  • Leader — Learn: Illustrates how attackers leverage licensed SaaS infrastructure to evade network-level controls; useful context for future budget conversations around M365 audit-log retention and cloud SIEM coverage, but no immediate leadership action required.
2026-07-17 · The Hacker News · source ↗ #infostealer#clickfix#microsoft-365
  • Engineer — Plan: ClickFix is a social-engineering delivery vector, not a patchable vuln — review AppLocker/WDAC policies to restrict arbitrary Run-dialog execution, and audit M365 Conditional Access token-lifetime and revocation settings to limit stolen-session utility.
  • SOC/IR — Act: Microsoft Defender Experts documented two active delivery chains; hunt for PowerShell or cmd.exe spawned via user-initiated Run dialog (explorer.exe lineage), and sweep M365 Unified Audit Log for anomalous OAuth grants, bulk file access, or SharePoint/OneDrive exfiltration events since the campaign is live.
  • Leader — Plan: Session-token theft bypasses MFA and directly targets M365 documents — worth a leadership brief this quarter on lure-based infostealer risk, and a review of whether security-awareness training covers ClickFix-style social engineering.
2026-07-13 · The Hacker News · source ↗ #phishing#microsoft-365#aitm
  • Engineer — Plan: Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.
  • SOC/IR — Act: Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.
  • Leader — Learn: The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.