daily cyber × ai intelligence

index

tagged

[hollowgraph]

2 editions · 2 items

July 21, 2026

  • HOLLOWGRAPH turns compromised Microsoft 365 mailboxes into a command-and-control channel, using the Microsoft Graph API to pull operator tasks and exfiltrate stolen files as attachments on calendar events dated to the year 2050 — blending malicious traffic into legitimate M365 flows. Group-IB attributes the .NET NativeAOT DLL to the Cavern backdoor framework and a suspected Israel-linked actor; the two-command implant (get/send) exploits no vulnerabilities, relying entirely on trusted cloud infrastructure to evade network detection. Group-IB (via NCSC-FI), The Hacker News. · Threat Activity & Tradecraft

in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live