Follow the latest coverage, related explainers and connected technology stories.
Microsoft observed phishing campaigns that distributed a legitimate MSP360 installer under deceptive names, then used it to install ConnectWise ScreenConnect and create two recurring remote-access channels. The company did not observe exploitation of a vulnerability in ScreenConnect; rather, the attackers abused trusted administrative tools to conduct subsequent activities, including information gathering and credential access.
Microsoft researchers identified a widespread phishing campaign that used invisible Unicode characters to split finance-related words and evade email filters. The campaign peaked at 2.37 million messages per day, although Microsoft Defender for Office 365 blocked more than 99% of them based on other signals.