Turning an approved blueprint into a rogue cloud identity. Well, I do not need to exploit Microsoft Graph, nor do I need to register an obviously malicious OAuth application or ask an administrator to approve a new set of permissions. … Read the rest
We’re in 2026, and inbox persistence is still here, and it’s one of the core pillars of the Microsoft 365 attack playbook. Once an attacker lands in a mailbox, they don’t rush to chase noisy privilege escalation. They go for … Read the rest
Exchange Online’s split architecture creates blind spots that BEC operators have been quietly exploiting. This post walks through four distinct techniques for creating inbox rules that evade standard detection surfaces, then examines the evasion combinations that leave most SIEM stacks … Read the rest