Cyber Security News

New Security Vulnerability Let Attackers Microsoft Corporate Email Accounts

A newly discovered security vulnerability allows attackers to impersonate Microsoft corporate email accounts, significantly increasing the risk of phishing attacks.

Security researcher Vsevolod Kokorin, also known as Slonser, found this bug, which Microsoft has not yet patched.

Kokorin revealed the bug on X (formerly Twitter) after Microsoft dismissed his initial report, claiming they could not reproduce the issue.

To demonstrate the vulnerability, Kokorin sent an email to TechCrunch that appeared to be from Microsoft’s account security team.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

The bug specifically affects emails sent to Outlook accounts; according to Microsoft’s latest earnings report, Outlook has a user base of at least 400 million people worldwide.

Kokorin expressed his frustration over Microsoft’s response, stating, “Microsoft just said they couldn’t reproduce it without providing any details. Microsoft might have noticed my tweet because a few hours ago, they reopened one of my reports that I had submitted several months ago”.

Despite the public disclosure, Kokorin did not provide technical details that could be used to exploit the bug maliciously.

The implications of this vulnerability are severe, as it allows threat actors to send phishing emails that appear to come from legitimate Microsoft corporate accounts, making them more convincing and potentially more harmful.

This flaw adds to a series of security challenges Microsoft has faced recently, including breaches by state-sponsored hackers from China and Russia.

In response to these ongoing security issues, Microsoft President Brad Smith testified before the House Homeland Security Committee, pledging to prioritize cybersecurity and address the company’s security shortcomings.

This commitment follows several high-profile breaches, including the theft of U.S. federal government emails by Chinese hackers and the Russian hackers’ compromise of Microsoft corporate email accounts.

As of now, it remains unclear whether the bug has been exploited by malicious actors other than Kokorin.

Microsoft has not yet commented on the issue, and the vulnerability poses a significant risk to Outlook users worldwide.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago