A vulnerability in Microsoft Bookings allowed attackers to manipulate meeting details via HTML injection due to inadequate input validation. Exploited mainly through the “Reschedule” functionality, this flaw enabled phishing attacks and email manipulation, affecting organizations using Microsoft 365. Microsoft remedied the issue by February 2025, though some parameters remained vulnerable. Strong input validation is recommended.

Baltimore and New York archdiocese abuse survivors possibly exposed in cyber incident – CBS News
Survivors of abuse within the Baltimore and New York archdioceses may have had their personal information compromised in a recent cyber incident. The breach raises