Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Attackers Adapt When You Block Macros

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.

The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run code from Word documents without any macros. Attackers adapt to every defense — so relying on a single control isn't enough.

Why layered defenses matter

When Microsoft began blocking macros in documents from the internet, it was a big win. Attackers immediately shifted to other techniques: new vulnerabilities, other file types, different ways of tricking users. Organizations with only one layer of protection were exposed again.

Layers that work together

  • Email filtering that inspects attachments before delivery.
  • Endpoint rules that stop Office apps from launching programs — regardless of the method.
  • Fast patching for actively exploited vulnerabilities.
  • Endpoint detection and response to catch what gets through.
  • User reporting of suspicious emails.

Questions to ask your team

  • Do we have endpoint rules that block Office from launching other programs?
  • How quickly did we patch Follina?
  • Do we test whether malicious attachments reach users?

What good looks like

Multiple independent layers, each covering gaps in the others, and regular testing.

The decision

Ask your team which single control, if it failed, would leave you most exposed. Then fund another layer behind it.

follina vulnerability impactFollina2022

More on this story