Bottom line: Microsoft 365 users are at risk of data theft and extortion due to sophisticated phishing attacks.
What's happening: Cybersecurity threat actors, reportedly linked to the APT10 group, have been targeting executives through Microsoft 365 help desk vishing attacks, using the platform's own security features to impersonate legitimate IT support.
What to do: Security leaders should ensure that all Microsoft 365 users are aware of the risks and take steps to implement multi-factor authentication and regular security audits to prevent unauthorized access.