Hackers Abuse Compromised M365 Accounts to Scale CodeStorm Phishing Operations
Hackers are taking phishing to new levels by abusing legitimate Microsoft 365 accounts to supercharge an operation known as CodeStorm. Instead of building fake infrastructure from scratch, attackers are hijacking real M365 accounts and using them as trusted launching pads. This approach lets malicious emails slip past filters that would normally flag suspicious senders, dramatically […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
