Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Microsoft 365

Articles in Microsoft 365.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Incident Teardowns

Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream

In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...

Microsoft 365How-To & Hardening

How to Use Token Protection and Compliant-Device Policies Against Token Theft

MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...

Microsoft 365Incident Teardowns

EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365

Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...

Microsoft 365How-To & Hardening

How to Block Device Code Flow With Conditional Access

Device code phishing kits like EvilTokens trick users into completing MFA on an attacker's behalf. Blocking device code flow with Conditional Access removes...

Microsoft 365Incident Teardowns

ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide

In July 2025, Chinese state actors and a ransomware group exploited ToolShell zero-days in on-premises SharePoint Server, stealing machine keys that let them persist after patching. SharePoint Online wasn't affected. Here is what happened and what to do with the servers you still run.

Microsoft 365Incident Teardowns

EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot

EchoLeak (CVE-2025-32711) was the first widely reported zero-click prompt injection against Microsoft 365 Copilot: a crafted email could cause Copilot to leak data with no user interaction. Microsoft fixed it server-side. Here is what it teaches about AI assistant risk.

Microsoft 365Platform Changes

Microsoft 365 Copilot Wave 2 (Sept 2024): New Oversharing Controls in SharePoint

On September 16, 2024, Microsoft announced Copilot Wave 2 — Pages, agents and more — alongside tools to tackle the oversharing that stalled many pilots. Here is what changed and a practical playbook for scaling Copilot safely.

Microsoft 365Incident Teardowns

Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App

In January 2024, Microsoft disclosed that Midnight Blizzard read email of its senior leaders. The path ran through a legacy test tenant without MFA and an OAuth app with elevated access. Here is the chain and how to find the same risks in your tenant.

Microsoft 365Platform Changes

Microsoft 365 Copilot Goes GA for Enterprise (Nov 2023): The Oversharing Problem Arrives

Microsoft 365 Copilot reached enterprise general availability on November 1, 2023. It respects existing permissions — which is exactly the problem in tenants with years of oversharing. Here is how Copilot uses your data and how to prepare.

Microsoft 365Incident Teardowns

Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email

In 2023, a China-based actor used a stolen Microsoft consumer signing key to forge tokens and read government email. A customer caught it because it had detailed audit logs. Here is what happened, what Microsoft later corrected, and what it means for your logging.

Microsoft 365Detection & Response

Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries

Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.

Microsoft 365CIO Briefings

CIO Brief: Phishing Kits Are Now a Subscription Business

The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...

Microsoft 365Detection & Response

Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries

Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker

The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...

Microsoft 365Platform Changes

Windows 10 End of Support (Oct 2025): Unpatched Endpoints in Your Microsoft 365 Estate

On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...

Microsoft 365How-To & Hardening

How to Use Intune Compliance Policies to Block Unsupported Devices

After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...

Microsoft 365How-To & Hardening

Windows 11 Migration Security Checklist

Use this checklist to plan a Windows 11 migration with security improvements built in.

Microsoft 365CIO Briefings

CIO Brief: The Security Cost of Delaying Windows 11

The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...

Microsoft 365How-To & Hardening

How to Migrate or Isolate On-Premises SharePoint Servers

ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.

Microsoft 365Detection & Response

Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries

SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...

Microsoft 365CIO Briefings

CIO Brief: On-Prem SharePoint Is Now a Liability

The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...

Microsoft 365How-To & Hardening

How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP

Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...

Microsoft 365Detection & Response

Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries

Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.

Microsoft 365CIO Briefings

CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data

The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...

Page 1 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.