Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and the second week of July, researchers found over 200 phishing emails targeting around 120 organizations in a wide range of industries and countries. The email masquerades as a Microsoft Planner task-assignment notification, claiming that HR has shared … More →
The post Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks appeared first on Help Net Security.

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file.


