Follow the latest coverage, related explainers and connected technology stories.
Cloudflare has launched an automated remediation policy engine in CASB that responds as soon as risks are detected in SaaS applications, such as publicly accessible files, by revoking sharing or sending Webhooks to security tools. Currently supported actions begin with Microsoft and Google Workspace integrations, with a goal of completing remediation within five minutes or less.
Microsoft Security Research observed a series of intrusions that begin with calls and messages impersonating IT support, then exploit AiTM or device code flows to add an attacker-controlled MFA method, explore Microsoft Graph, and extract SharePoint, OneDrive, and email data. Microsoft says the activity has been ongoing since May 2026 and aims to turn temporary identity compromise into persistent cloud access.
Researchers found that the BigBear 2.0 phishing-as-a-service framework was used to hijack Microsoft 365 sessions after victims completed multi-factor authentication, and to steal thousands of credentials and cookies.