惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
博客园 - Franky
V
V2EX
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
博客园 - 叶小钗
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
M
MIT News - Artificial intelligence
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
D
Docker
博客园 - 【当耐特】
阮一峰的网络日志
阮一峰的网络日志

Forbes - Business

Pickleball Slam 4 Preview — History Of The Event And Behind The Scenes Prep With The Players How To Get Masters 2027 Tickets Lottery Dates And Odds ‘Malcolm In The Middle: Life’s Still Unfair’ Is Likely A Wrap For Show Tony Gonzales, Eric Swalwell Will Resign Following Sexual Misconduct Allegations Suspect In Sam Altman Molotov Attack Charged With Attempted Murder Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Dan Orlovsky Compares Ty Simpson To Brock Purdy, Names Surprising NFC Contender As Fit For 2026 NFL Draft Prospect IndyCar’s Chip Ganassi Racing, OpenAI Hope For ‘Competitive Advantage’ Shingles Altered Achilles Rehab For Pacers Star Tyrese Haliburton, But He’s Back On The Court NYT Pips Today: Hints, Answers And Walkthrough For Tuesday, April 14 LVMH Founder Bernard Arnault’s Fortune Falls $50 Billion This Year Inter Miami CF Kicks Off New Era For South Florida Soccer In Nu Stadium From Makers Of Weight-Loss Pills To Anti-Wrinkle Shots, Meet South Korea’s Lab-Grown Billionaires IndyCar’s AJ Foyt Racing Hires Toby Sowery As Reserve Driver IndyCar’s Chip Ganassi Racing Goes Green With Green Sports Alliance Rory McIlroy Claims Second Straight Masters Title At Augusta Rockets Claim Fifth Seed In West Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 Design Details In ‘The Drama’ Delve Deep Into Character AEW Dynasty 2026 Results, Winners And Live Updates On April 12 Former Dodgers Infielder, 3-Time MLB All-Star And Champion, Dies After Cancer Battle Townsend And Wild Secure Double Golds At Pro Pickleball Association Australia Moreton Bay Los Angeles Dodgers Prospect James Tibbs III Is Tearing Up Triple-A Hungary’s Authoritarian Orban—Boosted By Trump—Loses. European Leaders Celebrate. Review: Blackbraid Delivers Exteme Metal Masterclass To Dublin, Ireland Colorado Is Emerging As An Energy Innovation Hub U.S. Military Ships In Strait of Hormuz Violate Ceasefire, Iran Warns (Live Updates) Rosé’s All-Time Sales Chart Record Has Been Beaten IC3 Report Reveals Surge In Cryptocurrency Investment Scams
Microsoft Venom Attack Targets C-Suite Executives
Davey Winder · 2026-04-11 · via Forbes - Business
King cobra snake attack and skull isolated on green background.

Company executives warned of Microsoft Venom attacks.

getty

As if life in the C-Suite wasn’t stressful enough, it has now been confirmed that chief executive officers, chief financial officers and vice president-level executives have been targeted since November 2025 by a previously undocumented Microsoft SharePoint-exploiting attack platform called Venom. These attacks have not harvested their targets randomly; rather, victims across at least 20 industry verticals have been selected by name. Here’s what you need to know about Venom, which, threat intelligence analysts said, “operates through a rotating pool of compromised business email accounts.”

ForbesAdobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update

C-Suite Attack Warning—Venom Unleashed Using Microsoft SharePoint Notifications

It is not unusual, truth be told, for threat actors to target senior executives, including C-suite members, in attacks. I mean, if you can compromise an account belonging to one of the top dogs, you will likely have hit very valuable data pay dirt. Nor, for that matter, is it unusual for phishing to be a primary route to such compromise. Researchers at BlackFog were first to publish a report on the Venom stealer platform. But what makes Venom technically distinct, according to the threat intelligence experts at Abnormal AI who have analyzed it in depth, is everything from “an email engineered to defeat every layer of automated analysis, to a credential harvester that enrolls an attacker-controlled MFA device before the target’s browser has moved on.” This phishing-as-a-service platform, hired out to paying criminal customers, although not appearing to be advertised in any open seller criminal marketplaces or underground forums, impersonates Microsoft SharePoint document-sharing notifications and targets C-Suite members by name. That Venom is, it would seem, a closed-access platform that is only being distributed through highly vetted criminal channels, only serves to make it all the more concerning.

Like most phishing attacks, Venom operators begin with an email. A highly-targeted one, addressing C-Suite victims by name, and delivered by way of a rotating pool of compromised business email accounts. While impersonating a SharePoint document-sharing notification, the email purports to be an internal company alert from the SharePoint environment and includes a QR code for scanning to gain access.

Venom attack QR code.

Abnormal AI

Abnormal AI’s report explained that personalization is one layer of the email’s design, but it also employs others to evade detection. “To evade signature-based detection, every email contains throwaway HTML elements whose values are randomized on each send,” the report confirmed, “ensuring no two emails produce the same hash or string match.” There’s even an entirely fake email message thread included below the visible lure. “The thread is built around the target,” the report continued, “their email prefix is parsed into a display name, placed in the ‘From’ field of each message, and accompanied by a generated signature block containing their name, a fabricated phone number, their real email address, and their real company website.” A randomly-generated persona is the supposed correspondent, while message bodies are created using meeting proposal, business dissolution request or fake financial table templates. Not only is this a way of fooling the recipient into thinking the email is genuine, but it also fools spam classifiers. For all intents and purposes, the email is a perfectly legitimate corporate communication.

The QR code, if the victim is determined not to be a bot or malware detector, leads to a credential harvesting page which can present “their organization's logo, their own email address pre-filled, and if their account is federated, their actual IdP login page rather than a generic Microsoft form,” the analysis warned, adding “The experience is indistinguishable from a genuine sign-in because it is, in every visible respect, genuine.” When in Device Code mode, Abnormal Ai went on to confirm, the victim doesn’t even see a login form at all, but rather something purporting to be a Docusign notification. Copy a code, click through to Microsoft and approve the apparently routine device sign-in request. “That approval is the attack,” the Abnormal AI said, “.Microsoft authenticates the target against its own infrastructure and delivers the resulting access and refresh tokens directly to the attacker's polling backend.’ Which means, ultimately, that there is no credential form to detect, no proxy to identify, and no MFA to intercept. Genius. Evil genius.

ForbesAngry Hacker Drops Microsoft Zero-Day Exploit, 1 Billion Users WarnedBy Davey Winder

“Once a cookie session is stolen,” Brian Bell, CEO of FusionAuth, said, “MFA becomes irrelevant. No password, no second factor–just a valid session your system already trusts.” If you’re not enforcing continuous validation, short-lived sessions, device context, and real-time revocation, Bell advised, attackers won’t need to break in as they will already be inside. “Venom makes one thing clear: credential rotation is not a recovery strategy. If the attacker is still on the endpoint, you’re just handing them new keys.” Identity infrastructure can no longer be about recovering from a breach, but rather must be about operating securely during a breach “through short-lived, tightly scoped tokens and continuous validation,” Bell concluded, “without that, organizations are not actually removing the risk.”

Now you know about Venom and the Microsoft SharePoint lure, so make sure to act accordingly if you get one.