Exchange Online is a technology platform tracked across 17 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 23, 2026.
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw…
A financially motivated threat actor known as Storm-2755 is targeting Canadian employees by hijacking their payroll accounts to redirect salary payments to attacker-controlled bank accounts. The attackers employ…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
Microsoft has disclosed a critical vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This zero-day flaw allows attackers to execute arbitrary JavaScript…
In early 2026, a surge in phishing attacks utilizing Amazon Simple Email Service (SES) has been reported, exploiting exposed AWS Identity and Access Management (IAM) access keys. Attackers leverage this trusted email…
Microsoft is addressing an Exchange Online incident, tracked as EX1436407, which began on July 19, 2026. The issue has caused mailboxes to be incorrectly quarantined due to excessive memory consumption from a recent…
Simply Data's Malaysia Cyber Threat Report 2025 reveals that Microsoft 365 was involved in 32% of escalated security incidents among Malaysian organizations. The report analyzed over 120.6 billion security logs,…
Microsoft has announced plans to deprecate support for legacy TLS versions (TLS 1.0 and TLS 1.1) for POP and IMAP connections to Exchange Online, starting in July 2026. This change will require all connections to use…