logo

Attackers Weaponize Microsoft 365 Outlook Add-ins to Quietly Exfiltrate Email Data

ID: ca5a86b7-7065-5e86-b7aa-27fb5a853f11

STIX ID: report--ca5a86b7-7065-5e86-b7aa-27fb5a853f11

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Divya

...
...

Varonis describes “Exfil Out&Look,” a proof-of-concept technique that uses Outlook Web Access add-ins to silently read outgoing email content and exfiltrate it to an external server while leaving little or no trace in Microsoft 365’s Unified Audit Log; the technique exploits a visibility gap in OWA (not a software vulnerability) and can scale to tenant-wide exfiltration if an administrator deploys a malicious manifest. Varonis reported the behavior to Microsoft, which classified it as a low-severity product bug/suggestion and allowed public disclosure; organizations are advised to restrict who can upload manifests, audit organization-wide add-ins and service principals, and monitor network egress from Outlook clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.