#microsoft-365 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #microsoft-365, aggregated by home.social.
-
Microsoft adds screenshot blocking on Purview-protected PDFs in the Edge browser and OneDrive and SharePoint PDF viewers.
#MicrosoftEdge #MicrosoftOneDrive #MicrosoftSharePoint #Microsoft #Microsoft365 #Screenshots #PDF #DataProtection
-
----------------
🎯 Threat Intelligence
===================Group-IB Threat Intelligence has identified HOLLOWGRAPH, a .NET NativeAOT-compiled DLL malware attributed with high confidence to the Cavern backdoor framework. The malware transforms Microsoft 365 calendars into covert command-and-control channels using the Microsoft Graph API, communicating through a compromised Israeli mailbox.
🔹 Technical Overview
HOLLOWGRAPH operates with only two commands: get and send. Both execute exclusively through trusted Microsoft cloud infrastructure. The malware never reaches out directly to attacker-owned servers. Instead, it uses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead-drop.
🔹 C2 Mechanism
The calendar-based C2 works as follows:
1. Tasking: Operators plant calendar events containing encrypted commands as attachments.
2. Exfiltration: The implant creates its own calendar events with encrypted stolen data attached as files.
3. Concealment: Every event is dated to 13 May 2050, ensuring the mailbox owner is unlikely to notice them.All Graph payloads use hybrid RSA + AES encryption. Two separate key pairs keep tasking and exfiltration channels cryptographically independent.
🔹 Credential Renewal Channel
HOLLOWGRAPH maintains a secondary communication channel through DNS tunneling. It performs IPv6 AAAA record queries against the attacker-controlled domain cloudlanecdn[.]com to refresh its Microsoft Entra ID (Azure AD) credentials. Updated values are written to an on-disk configuration file named logAzure.txt.
This dual-channel architecture provides resilience. Even if the primary Graph API channel is disrupted, the malware can continue receiving refreshed authentication tokens through DNS.
🔹 Victimology
Group-IB identified 12 systems carrying the implant. Only approximately three were actively communicating with attacker infrastructure. The recovered indicators, an Israeli mailbox used for exfiltration and malware samples uploaded from Israel, suggest focused interest in Israeli entities rather than broad opportunistic compromise.
🔹 Detection Considerations
Defenders monitoring Microsoft 365 environments should look for:
• Calendar events with future dates far beyond typical scheduling horizons (e.g., 2050)
• Unusual file attachments on calendar entries
• DNS queries to cloudlanecdn[.]com with AAAA record types
• The on-disk artifact logAzure.txt
• Authentication patterns from .NET NativeAOT binaries interacting with Microsoft Graph API🔹 Attribution
Group-IB links HOLLOWGRAPH to the Cavern backdoor framework with high confidence, based on code and behavioral similarities with known Cavern components.
🔹 HOLLOWGRAPH #ThreatIntelligence #C2 #Microsoft365 #MalwareAnalysis
🔗 Source: https://www.group-ib.com/blog/hollowgraph-microsoft-365/
-
----------------
🎯 Threat Intelligence
===================Group-IB Threat Intelligence has identified HOLLOWGRAPH, a .NET NativeAOT-compiled DLL malware attributed with high confidence to the Cavern backdoor framework. The malware transforms Microsoft 365 calendars into covert command-and-control channels using the Microsoft Graph API, communicating through a compromised Israeli mailbox.
🔹 Technical Overview
HOLLOWGRAPH operates with only two commands: get and send. Both execute exclusively through trusted Microsoft cloud infrastructure. The malware never reaches out directly to attacker-owned servers. Instead, it uses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead-drop.
🔹 C2 Mechanism
The calendar-based C2 works as follows:
1. Tasking: Operators plant calendar events containing encrypted commands as attachments.
2. Exfiltration: The implant creates its own calendar events with encrypted stolen data attached as files.
3. Concealment: Every event is dated to 13 May 2050, ensuring the mailbox owner is unlikely to notice them.All Graph payloads use hybrid RSA + AES encryption. Two separate key pairs keep tasking and exfiltration channels cryptographically independent.
🔹 Credential Renewal Channel
HOLLOWGRAPH maintains a secondary communication channel through DNS tunneling. It performs IPv6 AAAA record queries against the attacker-controlled domain cloudlanecdn[.]com to refresh its Microsoft Entra ID (Azure AD) credentials. Updated values are written to an on-disk configuration file named logAzure.txt.
This dual-channel architecture provides resilience. Even if the primary Graph API channel is disrupted, the malware can continue receiving refreshed authentication tokens through DNS.
🔹 Victimology
Group-IB identified 12 systems carrying the implant. Only approximately three were actively communicating with attacker infrastructure. The recovered indicators, an Israeli mailbox used for exfiltration and malware samples uploaded from Israel, suggest focused interest in Israeli entities rather than broad opportunistic compromise.
🔹 Detection Considerations
Defenders monitoring Microsoft 365 environments should look for:
• Calendar events with future dates far beyond typical scheduling horizons (e.g., 2050)
• Unusual file attachments on calendar entries
• DNS queries to cloudlanecdn[.]com with AAAA record types
• The on-disk artifact logAzure.txt
• Authentication patterns from .NET NativeAOT binaries interacting with Microsoft Graph API🔹 Attribution
Group-IB links HOLLOWGRAPH to the Cavern backdoor framework with high confidence, based on code and behavioral similarities with known Cavern components.
🔹 HOLLOWGRAPH #ThreatIntelligence #C2 #Microsoft365 #MalwareAnalysis
🔗 Source: https://www.group-ib.com/blog/hollowgraph-microsoft-365/
-
🐛 SIGINT // Cybersecurity Watch — 2026-07-22
New HollowGraph malware abuses Microsoft 365 Calendar for stealthy C2 comms, blending malicious traffic into legit cloud activity.
https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/
#Malware #InfoSec #Microsoft365 #ThreatIntel -
HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato
Group-IB ha scoperto HollowGraph, un impianto legato al framework iraniano Cavern che usa eventi di calendario Microsoft 365 datati al 2050 come dead drop per comandi e dati rubati, mascherando tutto da traffico Graph API legittimo. Colpita un'organizzazione israeliana. -
HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato
Group-IB ha scoperto HollowGraph, un impianto legato al framework iraniano Cavern che usa eventi di calendario Microsoft 365 datati al 2050 come dead drop per comandi e dati rubati, mascherando tutto da traffico Graph API legittimo. Colpita un'organizzazione israeliana. -
https://winbuzzer.com/2026/07/21/microsoft-warns-of-increased-acr-stealer-activity-xcxwbn/
Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.
#AcrStealer #ClickFix #Microsoft #Malware #CyberThreats #Cyberattacks #MicrosoftDefender #MicrosoftSecurity #Microsoft365
-
https://winbuzzer.com/2026/07/21/microsoft-warns-of-increased-acr-stealer-activity-xcxwbn/
Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.
#AcrStealer #ClickFix #Microsoft #Malware #CyberThreats #Cyberattacks #MicrosoftDefender #MicrosoftSecurity #Microsoft365
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel
Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap with an Iran-nexus backdoor framework and appears to be running a narrow espionage campaign against Israeli organizations. -
Microsoft has delayed Exchange Online PowerShell's credential cutoff to December, while scripts using stored passwords could break after module updates.
#ExchangeOnline #PowerShell #Microsoft #Authentication #MultiFactorAuthentication #Microsoft365 #MicrosoftExchange
-
Microsoft has delayed Exchange Online PowerShell's credential cutoff to December, while scripts using stored passwords could break after module updates.
#ExchangeOnline #PowerShell #Microsoft #Authentication #MultiFactorAuthentication #Microsoft365 #MicrosoftExchange
-
https://winbuzzer.com/2026/07/20/microsoft-made-copilot-cowork-a-metered-agent-in-june-xcxwbn/
Microsoft made Copilot Cowork available worldwide on June 16, pairing completed multi-tool work with usage billing and direct administrator cost controls.
#AI #CopilotCowork #Microsoft #MicrosoftCopilot #Microsoft365Copilot #Microsoft365 #AIAgents #AgenticAI #EnterpriseAI
-
https://winbuzzer.com/2026/07/20/microsoft-made-copilot-cowork-a-metered-agent-in-june-xcxwbn/
Microsoft made Copilot Cowork available worldwide on June 16, pairing completed multi-tool work with usage billing and direct administrator cost controls.
#AI #CopilotCowork #Microsoft #MicrosoftCopilot #Microsoft365Copilot #Microsoft365 #AIAgents #AgenticAI #EnterpriseAI
-
🎯 Schon ausprobiert? KI kann Präsentationen und Infografiken im Corporate Design Deiner Firma generieren. So erstellst Du dein eigenes "Marken-Kit" in M365 Copilot:
-
🎯 Schon ausprobiert? KI kann Präsentationen und Infografiken im Corporate Design Deiner Firma generieren. So erstellst Du dein eigenes "Marken-Kit" in M365 Copilot:
-
🔍 UPDATE: Wie funktioniert die Dateisuche in #Microsoft365 – mit und ohne KI?
https://www.malter365.de/microsoft365/suchen/ -
🔍 UPDATE: Wie funktioniert die Dateisuche in #Microsoft365 – mit und ohne KI?
https://www.malter365.de/microsoft365/suchen/ -
Microsoft will gradually end OneDrive updates and support for Windows 10 versions 21H2 and 22H2. Discover the complete timeline and alternatives for users.
-
Microsoft will gradually end OneDrive updates and support for Windows 10 versions 21H2 and 22H2. Discover the complete timeline and alternatives for users.
-
How to Create and Reset a User Password in the Microsoft 365 Admin Center
A complete, screenshot-by-screenshot walkthrough for IT admins and small business owners — written from over a decade of hands-on Microsoft 365 administration. Managing user accounts is one of the most routine — and most important — tasks for any Microsoft 365 administrator. Whether you're onboarding a new employee or helping a teammate who's locked out of their account, knowing how to create a user and reset a password correctly saves time and keeps your organization secure. In more […] -
How to Create and Reset a User Password in the Microsoft 365 Admin Center
A complete, screenshot-by-screenshot walkthrough for IT admins and small business owners — written from over a decade of hands-on Microsoft 365 administration. Managing user accounts is one of the most routine — and most important — tasks for any Microsoft 365 administrator. Whether you're onboarding a new employee or helping a teammate who's locked out of their account, knowing how to create a user and reset a password correctly saves time and keeps your organization secure. In more […] -
https://winbuzzer.com/2026/07/17/microsoft-reportedly-trains-sales-team-to-target-ai-rivals-xcxwbn/
Microsoft is reportedly coaching sales staff to challenge OpenAI and Anthropic with a cost, security, and integrated platform pitch for its own Copilot AI.
#AI #Microsoft #OpenAI #Anthropic #Claude #MicrosoftCopilot #Microsoft365Copilot #Microsoft365 #MicrosoftAI #AIModels #EnterpriseAI
-
https://winbuzzer.com/2026/07/17/microsoft-reportedly-trains-sales-team-to-target-ai-rivals-xcxwbn/
Microsoft is reportedly coaching sales staff to challenge OpenAI and Anthropic with a cost, security, and integrated platform pitch for its own Copilot AI.
#AI #Microsoft #OpenAI #Anthropic #Claude #MicrosoftCopilot #Microsoft365Copilot #Microsoft365 #MicrosoftAI #AIModels #EnterpriseAI
-
☁️ Endlich einfach erklärt: Warum gibt es zwei Speicherorte in der Cloud? Und wie unterscheiden sich OneDrive und SharePoint?
-
☁️ Endlich einfach erklärt: Warum gibt es zwei Speicherorte in der Cloud? Und wie unterscheiden sich OneDrive und SharePoint?
-
🟦 Organizational Prompts in M365 Copilot
Stop teams prompting differently. Admins can publish trusted prompts centrally.
Published prompts appear in Copilot Chat Edge and Teams.
Admins can pin edit bulk import and monitor adoption analytics.
The feature reached general availability in July 2026.💡 Centralized curated prompts library
🔍 Auto suggestions in Copilot Chat Edge Teams
⚖️ Admin control pin edit bulk import analyticsReady to standardize Copilot prompts and speed adoption? 🚀
#Microsoft365 #Copilot #AI #Admin -
🟦 Organizational Prompts in M365 Copilot
Stop teams prompting differently. Admins can publish trusted prompts centrally.
Published prompts appear in Copilot Chat Edge and Teams.
Admins can pin edit bulk import and monitor adoption analytics.
The feature reached general availability in July 2026.💡 Centralized curated prompts library
🔍 Auto suggestions in Copilot Chat Edge Teams
⚖️ Admin control pin edit bulk import analyticsReady to standardize Copilot prompts and speed adoption? 🚀
#Microsoft365 #Copilot #AI #Admin -
🎖️ Of course, I'm proud and grateful.
This is my 12th consecutive year as a Microsoft MVP (Most Valuable Professional).
This international award is given to selected community members in recognition of their expertise and contributions. I will continue to create and share independent content about Microsoft 365 – especially Copilot and OneNote.
Looking forward to connecting with fellow MVPs around the world. Congratulations to all award recipients! 🙋🏻♂️
-
🎖️ Of course, I'm proud and grateful.
This is my 12th consecutive year as a Microsoft MVP (Most Valuable Professional).
This international award is given to selected community members in recognition of their expertise and contributions. I will continue to create and share independent content about Microsoft 365 – especially Copilot and OneNote.
Looking forward to connecting with fellow MVPs around the world. Congratulations to all award recipients! 🙋🏻♂️
-
Zwei neue Phishing-Kits namens Jalisco und OmegaLord bedrohen Microsoft-365-Konten. Sie hebeln selbst die Multi-Faktor-Authentifizierung aus. #Microsoft365 #Phishing https://winfuture.de/news,159992.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Zwei neue Phishing-Kits namens Jalisco und OmegaLord bedrohen Microsoft-365-Konten. Sie hebeln selbst die Multi-Faktor-Authentifizierung aus. #Microsoft365 #Phishing https://winfuture.de/news,159992.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
🎯 NEUE THEMENSEITE
Hier bekommst Du einen umfassenden Überblick über #Microsoft365. Du lernst die vielseitige Software-Sammlung für Job und Schule kennen – von den Grundlagen und Voraussetzungen bis zu den ersten Schritten:
-
🎯 NEUE THEMENSEITE
Hier bekommst Du einen umfassenden Überblick über #Microsoft365. Du lernst die vielseitige Software-Sammlung für Job und Schule kennen – von den Grundlagen und Voraussetzungen bis zu den ersten Schritten:
-
⭐⭐⭐⭐⭐ Anne Windisch ist Schulleiterin im sächsischen Eibenstock. Sie hat mein neues Handbuch für #Microsoft365 als Testleserin begutachtet und würde es auch ihrem Kollegium empfehlen:
"Gerade für Menschen, die digitalen Themen eher unsicher oder zurückhaltend begegnen, senkt die Hemmschwelle enorm. Man bekommt nicht das Gefühl, etwas schon können zu müssen, sondern wird Schritt für Schritt mitgenommen, ohne von technischen Details erschlagen zu werden."
-
⭐⭐⭐⭐⭐ Anne Windisch ist Schulleiterin im sächsischen Eibenstock. Sie hat mein neues Handbuch für #Microsoft365 als Testleserin begutachtet und würde es auch ihrem Kollegium empfehlen:
"Gerade für Menschen, die digitalen Themen eher unsicher oder zurückhaltend begegnen, senkt die Hemmschwelle enorm. Man bekommt nicht das Gefühl, etwas schon können zu müssen, sondern wird Schritt für Schritt mitgenommen, ohne von technischen Details erschlagen zu werden."
-
📘 Kostenlose Leseprobe als Download
Du kannst jetzt vorab in mein neues Handbuch für #Microsoft365 schauen. Lade Dir jetzt die PDF-Datei mit dem kompletten Inhaltsverzeichnis und den ersten Kapiteln herunter:
https://www.malter365.de/microsoft365/microsoft365-handbuch/
-
📘 Kostenlose Leseprobe als Download
Du kannst jetzt vorab in mein neues Handbuch für #Microsoft365 schauen. Lade Dir jetzt die PDF-Datei mit dem kompletten Inhaltsverzeichnis und den ersten Kapiteln herunter:
https://www.malter365.de/microsoft365/microsoft365-handbuch/
-
Gekauft heißt nicht behalten: Wie Microsoft Office 2019 für Mac per Zertifikat entwertet
Am 13. Juli 2026 ist ein digitales Zertifikat abgelaufen. Keine Sicherheitslücke, keine Schlagzeile, keine Pressekonferenz. Trotzdem hat genau dieses eine Zertifikat gereicht, um sämtlichen Mac-Nutzer*innen mit einer alten, längst bezahlten Office-Lizenz von einem Moment auf den anderen die Arbeitsfähigkeit zu entziehen. Wer noch Office 2019 für den Mac verwendet, kann seine eigenen Dateien seit diesem Tag öffnen, ansehen und ausdrucken. Bearbeiten, speichern, neu anlegen geht nicht mehr. Und Microsoft sagt selbst, dass es dafür keinen Weg zurück gibt.
Ein abgelaufenes Zertifikat reicht, und deine bezahlte Office-2019-Lizenz für den Mac kann ab jetzt nur noch lesen, nicht mehr bearbeiten. Microsoft spricht offen von Lizenzkontrolle, ganz ohne Sicherheitsvorwand. Was du jetzt tun kannst, ohne dich noch fester ans Microsoft-Konto zu binden. Reden wir drüber!
#chrislo #DigitaleUnabhängigkeit #Microsoft #Office2019 #LibreOffice #OnlyOffice #Mac #Microsoft365 #Windows10 #OpenSource #Vereine
-
De Belastingdienst zet de verdere uitrol van Microsoft 365 voorlopig stop. Daarmee kiest de overheid voor een opvallende koerswijziging. Nog geen jaar geleden werd Microsoft 365 juist gepresenteerd als de meest realistische oplossing voor de digitale werkplek van duizenden medewerkers. Nu wil staatssecretaris Eelco Eerenberg eerst opnieuw onderzoeken of een alternatief, waarbij de software volledig op eigen infrastructuur draait, inmiddels haalbaar is.
De aanleiding is een kritisch advies van het Adviescollege ICT-toetsing (AcICT). Volgens het college biedt de huidige aanpak onvoldoende zekerheid dat de Belastingdienst op een veilige, toekomstbestendige en goed beheersbare manier kan werken. Daarom wordt de verdere invoering voorlopig stilgezet totdat een nieuw onderzoek is afgerond.