Breaking 09:48 Former Venezuelan leader Nicolas Maduro to appear before New York court in drug trafficking case 09:20 Kalshi launches election forecasting hub ahead of US midterm elections 09:16 US launches $5 billion AI initiative to advance health and construction research 08:00 Bloomsbury to receive compensation under landmark $1.5 billion Anthropic copyright settlement 19:45 JPMorgan CEO warns investors may be underestimating growing risks in global markets 19:30 US condemns Ortega’s authoritarian stance after Nicaragua rejects elections 19:16 Amgen agrees to $74 million settlement in shareholder lawsuit over tax disclosure claims 19:15 Anthropic reaches $1.5 billion copyright settlement with authors over AI training data 18:52 Washington signals possible new tariff measures against dozens of countries 18:45 Canada and US agree to intensify trade talks after Trump tariff warning 18:30 US administration pauses over $1 billion in Medicaid payments to California and Minnesota 18:15 Elon Musk’s fortune falls below $800 billion after Starship launch setback 17:00 US lawmakers press Trump to challenge EU tech regulations through trade action 16:16 US prepares new tariff measures targeting around 60 economies 15:15 Intel prepares another round of layoffs as it restructures its data center business 13:27 Trump administration weighs cutting ties with UN refugee agency 13:15 Meliá ends operations in Cuba after more than three decades amid US pressure 12:30 AMD unveils Helios AI system as it challenges Nvidia’s dominance with Microsoft support 11:01 3M raises annual profit outlook as industrial business drives recovery 10:42 Alphabet reportedly develops AI chip with Gemini technology built into its architecture

Scammers send phishing emails from official Microsoft address

Friday 22 May 2026 - 08:31
By: Dakir Madiha
Scammers send phishing emails from official Microsoft address

Phishing operators have exploited a vulnerability in Microsoft’s email notification systems to send fraudulent messages from a legitimate internal address used for security alerts and authentication codes. The abuse involves the address msonlineservicesteam@microsoftonline.com, which normally delivers two-factor authentication codes and account notifications to hundreds of millions of users worldwide. The misuse gives attackers a powerful way to bypass user suspicion by appearing as trusted system communication.

The attack appears to rely on creating or compromising Microsoft accounts and leveraging them to trigger automated system emails that carry fraudulent content. In some cases, attackers replicate security alerts warning of unauthorized transactions. In others, messages direct users to external links embedded in the email body. Because the messages originate from a legitimate Microsoft-controlled infrastructure, they often pass basic authentication checks and appear authentic to recipients.

Security researchers have also documented related techniques involving Microsoft’s identity management system, where attackers manipulate tenant configuration fields to inject deceptive text into automated notifications. This method can alter subject lines and message content in system-generated emails, including fake purchase confirmations or cryptocurrency-related alerts. The result is a hybrid form of phishing where legitimate infrastructure is used to generate convincing fraudulent communications at scale.

A cybersecurity monitoring group has reported that the same Microsoft notification address has been abused for months to distribute spam and phishing messages. The group has flagged the issue to Microsoft and warned that such levels of customization in automated notification systems create structural risks for abuse. Microsoft has acknowledged inquiries but has not publicly detailed corrective measures. The incident reflects a broader trend in which attackers increasingly target trusted enterprise communication systems rather than relying on external spoofed domains. Users are advised to avoid clicking links in unexpected security emails and to verify account activity directly through official platforms.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.