Tech News
← Home  ·  All topics

Microsoft 365

17 GoKawiil briefs on this topic

Microsoft seizes 50 EvilTokens phishing sites, two arrested in UK

Microsoft and partner organizations dismantled EvilTokens, a phishing-as-a-service operation that used AI tools and device code phishing to compromise over 12,000 inboxes across more than 10,000 organizations. Following a US court-enabled legal action, Microsoft seized 50 websites and disabled over 150 additional domains linked to the operators, tracked as Storm-2992. The UK's Metropolitan Police also arrested two men connected to the scheme this month; both were released on bail pending further investigation.

Microsoft sets end-of-2029 retirement date for Internet Explorer Mode in Edge

Microsoft has reissued a reminder to enterprise IT admins that IE Mode, the legacy compatibility feature in Edge that runs sites using Internet Explorer's old Trident/MSHTML engine, will be discontinued by the end of 2029. The notice, sent via the Microsoft 365 admin center, reaffirms a 2021 commitment and asks organizations to begin planning now to migrate old applications away from IE dependencies.

Microsoft to shut down Calendar, People and Files companion apps by December 2026

Microsoft announced it is retiring its Microsoft 365 companion apps—Calendar, People, and Files—effective December 16, 2026, after which they will stop functioning and lose support. The company is telling IT administrators to uninstall the apps from managed devices before that date. The move comes roughly a year after Microsoft began automatically pushing these taskbar-integrated apps to Windows 11 enterprise devices running Microsoft 365 desktop clients.

Wire survey finds most security teams can't track who has access to shared M365 files

A Wire survey found that 61% of security leaders say access to shared files in Microsoft 365 often stays active far longer than intended, while more than a third struggle to even identify who currently has access to sensitive shared content. The report points to routine sharing habits—like adding freelancers to SharePoint folders or inviting new members into Teams channels—as common ways access quietly persists beyond its original purpose.

Microsoft to let Teams admins customize blocked file extensions list

Microsoft plans to update Teams' Weaponizable File Protection feature so administrators can customize which file types get blocked in chats and channels, rather than relying solely on Microsoft's default list. The change is listed on the Microsoft 365 roadmap and is expected to roll out starting November 2026 across Android, desktop, iOS, macOS and web.

Swiss government and military begin shifting from Microsoft 365 to openDesk

Switzerland's Federal Chancellery and its Armed Forces Cyber Command are separately moving away from Microsoft 365 toward openDesk, a German-built open-source workplace suite covering email, calendars, documents and video conferencing. The Chancellery plans to run openDesk alongside Microsoft 365 for about 3,000 of 47,000 federal employees by the end of 2027, at an estimated cost of 9 million Swiss francs, while the military is proceeding faster on sensitive systems.

ShinyHunters-linked hackers use fake passkey alerts to breach Microsoft 365 accounts

Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.

Hackers Target Personal Phones to Breach Microsoft 365 via BYOD Policies

Microsoft says threat groups Storm-3032 and Storm-3121 have been calling or texting employees on personal devices since May, posing as internal IT helpdesks to steal credentials and bypass corporate authentication protections. The attackers then abuse the Microsoft Graph API to exfiltrate corporate data at scale, and researchers believe they hand off this access to extortion gangs such as ShinyHunters. No specific breaches have yet been tied directly to these campaigns.

Swiss government commits $11M to replace Microsoft 365 with openDesk suite

Switzerland's Federal Chancellery is spending 9 million Swiss francs to move 3,000 government workstations off Microsoft 365 tools like Outlook and Teams, adopting the open-source openDesk suite instead. The decision follows a successful pilot program called PoC BOSS, which tested the software with 172 federal employees who found it workable for standard office tasks, though large-scale video conferencing showed some limitations. The rollout is planned to be complete by the end of 2027, with potential to expand further across the federal workforce.

Switzerland Expands openDesk Pilot to 3,000 Federal Workstations

Following a proof-of-concept with 172 employees, Switzerland's Federal Council has expanded testing of the German open-source suite openDesk to 3,000 government workstations, about 7% of the federal workforce. The pilot, running alongside Microsoft 365, aims for full migration by end of 2027, while the country's Cyber Command plans to fully replace Microsoft 365 with openDesk by October 2026.

BigBear 2.0 phishing kit steals 5,000+ Microsoft 365 logins across 258 firms

CloudSEK researchers infiltrated the admin panel of a phishing-as-a-service tool called BigBear 2.0 and found it had harvested over 5,000 Microsoft 365 credentials from 258 organizations. The kit uses an Evilginx2-based adversary-in-the-middle proxy to intercept usernames, passwords, and session cookies even after victims complete multi-factor authentication, letting attackers replay stolen sessions to hijack accounts.

Switzerland expands open-source pilot to 3,000 federal workstations

The Swiss Federal Chancellery is spending CHF 9 million to test the openDesk open-source suite as a replacement for Microsoft 365 across 3,000 federal employees, roughly 7% of the workforce, with migration targeted for completion by end of 2027. The pilot follows a proof-of-concept with 172 employees that rated document editing and email positively but flagged limitations in large-scale video conferencing, and it will run alongside Microsoft 365 rather than replace it immediately.