A vulnerability in Microsoft Bookings allowed attackers to manipulate meeting details via HTML injection due to inadequate input validation. Exploited mainly through the “Reschedule” functionality, this flaw enabled phishing attacks and email manipulation, affecting organizations using Microsoft 365. Microsoft remedied the issue by February 2025, though some parameters remained vulnerable. Strong input validation is recommended.

Marks & Spencer Hackers Tricked IT Workers Into Resetting Passwords
Recent reports indicate that cyberattacks on Marks & Spencer (M&S) and Co-op involved hackers tricking IT employees into resetting passwords, allowing unauthorized access to their