Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild.
In this unusual supply chain attack detailed by Koi Security, an unknown attacker claimed the domain associated with a now-abandoned legitimate add-in to serve a fake Microsoft login page, stealing over 4,000 credentials in the process. The activity has been –
Read More – The Hacker News



![[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment AttackFeed by Joe Wagner | [Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment - The Hacker News](https://attackfeed.com/wp-content/uploads/2026/04/ghost-lkE03u.jpg)