CyberSecurity News
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading
· September 10, 2026AI summary
Threat actors are using the Microsoft Graph API to identify potential targets, and then selling access to these targets to extortion groups. This exploitation allows attackers to reach Microsoft 365 and corporate data, taking advantage of bring-your-own-device policies. The access is being passed to groups such as ShinyHunters, who likely use it for malicious purposes.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Dark Reading.

