Breaking 18:30 AMD invests $5 billion in Anthropic as AI chip race intensifies against Nvidia 17:00 Amazon reduces workforce in artificial general intelligence division amid ongoing restructuring 15:30 Trump escalates warning to Iran with threat to strike infrastructure over Hormuz attacks 12:15 Jazz saxophonist Plas Johnson, iconic voice behind The Pink Panther Theme, dies at 94 11:30 United States prepares broader tariff strategy as new trade measures take effect 11:15 Ryan Reynolds confirms a new Deadpool movie is in development 11:00 Pentagon estimates Iran conflict has cost the United States $37.5 billion 09:48 Former Venezuelan leader Nicolas Maduro to appear before New York court in drug trafficking case 09:20 Kalshi launches election forecasting hub ahead of US midterm elections 09:16 US launches $5 billion AI initiative to advance health and construction research 08:00 Bloomsbury to receive compensation under landmark $1.5 billion Anthropic copyright settlement 19:45 JPMorgan CEO warns investors may be underestimating growing risks in global markets 19:30 US condemns Ortega’s authoritarian stance after Nicaragua rejects elections 19:16 Amgen agrees to $74 million settlement in shareholder lawsuit over tax disclosure claims 19:15 Anthropic reaches $1.5 billion copyright settlement with authors over AI training data 18:52 Washington signals possible new tariff measures against dozens of countries 18:45 Canada and US agree to intensify trade talks after Trump tariff warning

Scammers send phishing emails from official Microsoft address

Friday 22 May 2026 - 08:31
By: Dakir Madiha
Scammers send phishing emails from official Microsoft address

Phishing operators have exploited a vulnerability in Microsoft’s email notification systems to send fraudulent messages from a legitimate internal address used for security alerts and authentication codes. The abuse involves the address msonlineservicesteam@microsoftonline.com, which normally delivers two-factor authentication codes and account notifications to hundreds of millions of users worldwide. The misuse gives attackers a powerful way to bypass user suspicion by appearing as trusted system communication.

The attack appears to rely on creating or compromising Microsoft accounts and leveraging them to trigger automated system emails that carry fraudulent content. In some cases, attackers replicate security alerts warning of unauthorized transactions. In others, messages direct users to external links embedded in the email body. Because the messages originate from a legitimate Microsoft-controlled infrastructure, they often pass basic authentication checks and appear authentic to recipients.

Security researchers have also documented related techniques involving Microsoft’s identity management system, where attackers manipulate tenant configuration fields to inject deceptive text into automated notifications. This method can alter subject lines and message content in system-generated emails, including fake purchase confirmations or cryptocurrency-related alerts. The result is a hybrid form of phishing where legitimate infrastructure is used to generate convincing fraudulent communications at scale.

A cybersecurity monitoring group has reported that the same Microsoft notification address has been abused for months to distribute spam and phishing messages. The group has flagged the issue to Microsoft and warned that such levels of customization in automated notification systems create structural risks for abuse. Microsoft has acknowledged inquiries but has not publicly detailed corrective measures. The incident reflects a broader trend in which attackers increasingly target trusted enterprise communication systems rather than relying on external spoofed domains. Users are advised to avoid clicking links in unexpected security emails and to verify account activity directly through official platforms.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.