<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft-365 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/microsoft-365/</link><description>Recent content in Microsoft-365 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 09:33:57 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/microsoft-365/index.xml" rel="self" type="application/rss+xml"/><item><title>Executive Outlook Mailbox Spied on via OneDrive &amp; Dropbox</title><link>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</link><pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</guid><description>Attackers silently exfiltrated a stock exchange executive&amp;#39;s Outlook email for five months, hiding data theft behind Dropbox and OneDrive traffic.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">The Hacker News</a></p>
<hr>
<p>Unknown threat actors maintained covert access to a senior stock exchange executive&rsquo;s Outlook mailbox for at least five months, quietly exfiltrating email data in small batches to evade detection. The stolen data was routed through legitimate cloud storage services — Dropbox and OneDrive — to blend with normal business traffic. Symantec and Carbon Black attribute the campaign to espionage, suggesting a nation-state or sophisticated threat actor targeting financial sector intelligence.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review Microsoft 365 audit logs and Conditional Access policies for unusual mailbox delegation, mail forwarding rules, or OAuth app consents — particularly any third-party app with access to Mail.Read scopes. Implement Cloud App Security (Defender for Cloud Apps) policies to alert on bulk email access or large data transfers to consumer cloud storage services such as Dropbox and OneDrive.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">Hackers Spied on a Stock Exchange Executive&rsquo;s Outlook Mailbox for Five Months</a></p>
]]></content:encoded></item><item><title>Stock Exchange Exec Outlook Hacked via OneDrive Exfil</title><link>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox-exfiltration/</link><pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox-exfiltration/</guid><description>Attackers spent five months silently exfiltrating a stock exchange executive&amp;#39;s Outlook mailbox via OneDrive and Dropbox. Here&amp;#39;s what cloud architects need</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">The Hacker News</a></p>
<hr>
<p>Unknown threat actors maintained covert access to a senior stock exchange executive&rsquo;s Microsoft Outlook mailbox for at least five months, systematically exfiltrating email data in small batches to avoid detection. The stolen data was routed through Dropbox and OneDrive to blend with legitimate cloud traffic, making it harder for security tools to flag the activity. The campaign bears the hallmarks of a state-sponsored or sophisticated espionage operation targeting high-value financial intelligence.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review Microsoft 365 audit logs and Defender for Cloud Apps policies for anomalous mail export activity, particularly incremental inbox syncs or delegated access from unfamiliar locations — and enforce conditional access policies that restrict OAuth app permissions for third-party cloud storage providers such as Dropbox and OneDrive to prevent data staging and exfiltration via trusted cloud channels.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">Hackers Spied on a Stock Exchange Executive&rsquo;s Outlook Mailbox for Five Months</a></p>
]]></content:encoded></item><item><title>Microsoft 365 Android Debug Flag Exposes Account Tokens</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-365-android-debug-flag-account-token-theft/</link><pubDate>Wed, 03 Jun 2026 14:56:35 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-365-android-debug-flag-account-token-theft/</guid><description>A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html">The Hacker News</a></p>
<hr>
<p>A debug flag accidentally left enabled in production builds of multiple Microsoft 365 Android apps disabled a security check that restricts account token sharing to trusted Microsoft applications. As a result, any app installed on the same Android device could silently request and receive the signed-in user&rsquo;s authentication token, granting full access to email, files, calendar, and the ability to send messages on their behalf. No user interaction, credentials, or elevated permissions were required to exploit this.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your mobile application management (MAM) and Conditional Access policies to ensure app-based controls are enforced at the resource level and are not solely reliant on client-side token handling. Until Microsoft confirms a fully patched build is deployed, consider enforcing Continuous Access Evaluation (CAE) and restricting M365 access on Android to Intune-managed devices with compliant app versions.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html">Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag</a></p>
]]></content:encoded></item><item><title>Microsoft 365 Android Token Theft via Debug Flag Flaw</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-365-android-token-theft-debug-flag-vulnerability/</link><pubDate>Wed, 03 Jun 2026 14:56:35 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-365-android-token-theft-debug-flag-vulnerability/</guid><description>A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html">The Hacker News</a></p>
<hr>
<p>A debug flag accidentally left enabled in production builds of multiple Microsoft 365 Android apps disabled the trust check that normally restricts account-token sharing to authorised Microsoft applications. As a result, any app installed on the same Android device could silently request and receive a valid authentication token, granting full access to the victim&rsquo;s email, files, calendar, and messaging without any user interaction or additional permissions. The flaw affects any user running a vulnerable Microsoft 365 Android app while also having a malicious or compromised app on the same device.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Mandate immediate updates to all affected Microsoft 365 Android apps across your managed device estate via your MDM/UEM solution, and review Conditional Access policies to detect anomalous token usage or unexpected app sign-ins. Consider temporarily blocking unmanaged Android devices from accessing Microsoft 365 resources until patched app versions are confirmed deployed.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html">Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag</a></p>
]]></content:encoded></item></channel></rss>