HollowGraph uses Microsoft 365 calendars as a covert C2 channel
Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control c
Kratos taken down, the phishing kit behind thousands of campaigns per month
German and US law enforcement dismantled Kratos’s infrastructure, a phishing-as-a-service platform considered among the most widely used in the world. The operation was led by th
Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel
Identity abuse is one of the clearest operational threats in the feed, especially around Microsoft 365 and Entra ID. Attackers are using fake passkey enrollment, device-code flow a

