Practical write-ups on Microsoft 365 incidents — what happens, why it happens, and how to stop it.
Microsoft detected approximately 8.3 billion email-based phishing threats in Q1 2026. How modern campaigns bypass MFA, what attackers do once inside a Microsoft 365 account, and the warning signs to watch for.
Read articleA sophisticated attack targeting Stryker's Microsoft 365 environment used compromised admin credentials to issue mass Intune device wipes. What the attack chain looked like and which controls would have stopped it.
Read articleHow attackers gain access to Microsoft 365 accounts, what they do once inside, and the steps to contain the damage and recover control of the tenant.
Read articleWhy compromised Office 365 mailboxes get used for spam campaigns, how Microsoft responds with outbound limits, and what remediation actually looks like.
Read articleInternal phishing sent from a trusted Microsoft 365 account is harder to catch and more damaging than external spam. How these attacks propagate and how to investigate them.
Read article