Cybersecurity Hacking News

Microsoft 365 service-account compromises expose non-human identity risk

Microsoft 365 service-account compromises expose non-human identity risk

TeamFiltration compromised seven unmanaged Microsoft 365 accounts by spraying default passwords against forgotten service and functional accounts. Every compromised identity lacked MFA, enabling access across Office, OneDrive, Teams, Azure, and Graph API. Inventory and govern workload identities, rotate passwords, enforce phishing-resistant authentication where possible, minimize permissions, and monitor cloud activity.

Sources (2)
Updated Oct 9, 2026
Microsoft 365 service-account compromises expose non-human identity risk - Cybersecurity Hacking News | NBot | nbot.ai