“Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected
ID: 6bd2f062-fe12-534f-bb76-a0cacc973d82
STIX ID: report--6bd2f062-fe12-534f-bb76-a0cacc973d82
Feed Name: securityonline.info
Varonis Threat Labs disclosed “Exfil Out&Look,” an attack technique that leverages a logging gap in Outlook Web Access (OWA) where add-in installation and execution generate no audit entries; malicious or compromised add-ins can therefore forward copies of sent/received email to external servers without leaving forensic traces. The researchers outline scenarios including malicious insiders, compromised accounts, privileged abuse, and supply‑chain poisoning, and note Microsoft has classified the issue as low-severity with no immediate patch, requiring organizations to adopt their own mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
