惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Register - Security
The Register - Security
美团技术团队
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
C
Check Point Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
S
Securelist
T
Tor Project blog
GbyAI
GbyAI
L
LINUX DO - 热门话题
V
Visual Studio Blog
AWS News Blog
AWS News Blog
The Cloudflare Blog
腾讯CDC
K
Kaspersky official blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recorded Future
Recorded Future
李成银的技术随笔
W
WeLiveSecurity
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
M
Microsoft Research Blog - Microsoft Research
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Schneier on Security
Schneier on Security
B
Blog
IT之家
IT之家
爱范儿
爱范儿
H
Help Net Security
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
J
Java Code Geeks
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
Cyberwarzone
Cyberwarzone
博客园 - 叶小钗
MyScale Blog
MyScale Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Project Zero
Project Zero
F
Future of Privacy Forum
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hacker News: Ask HN
Hacker News: Ask HN
D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
V
Vulnerabilities – Threatpost

TechCrunch

Beauty booking startup Fresha hits $1 billion valuation with KKR backing General Catalyst just led a $63M bet on India’s travel payments market Imperagen raises £5 million to use quantum physics, AI on enzyme engineering Jensen Huang says he’s found a ‘brand new’ $200B market for Nvidia Anthropic says it’s about to have its first profitable quarter The SpaceX IPO filing is filled with AI bets, Starship dreams, and Elon Musk at the center Clouted wants to take the guesswork out of making short videos go viral xAI burned $6.4B last year. SpaceX’s IPO filing shows why the spending is far from over Nvidia posts another record quarter, reveals $43 billion of holdings in startups Musk’s xAI is being sued over its data center generators. Now, it’s buying $2.8B more. Anthropic will pay xAI $1.25 billion per month for compute Sam Altman makes ‘mic drop’ offer to every Y Combinator startup You don’t need to be an AI startup to raise. Lucra has $20M to prove it. The SpaceX IPO filing has arrived Microsoft’s carbon removal plans aren’t dead after all OpenAI claims it solved an 80-year-old math problem — for real this time IrisGo, a startup backed by Andrew Ng, looks to become the AI desktop buddy you never knew you needed Tesla’s Full Self-Driving software is creeping into Europe Airbnb gets into hotels, expands AI for host onboarding and customer support Truecaller gets into the eSIM business to diversify its revenue streams Global EV market goes K-shaped as the U.S. gets left behind OpenAI barrels towards IPO that may happen in September OpenAI barrels toward IPO that may happen in September Jeff Bezos, you were so close to making a good point Customers say Trump Mobile is leaking their personal information Intuit to lay off over 3,000 employees to refocus on AI AI search startups are blowing up Stability AI release a new audio model that can create six-minute songs Startup Battlefield 200 applications close in 1 week: Window to nominate and apply for the most promising startups closes May 27 Startup Battlefield 200 applications close in one week: Window to nominate and apply for the most promising startups ends May 27 NanoClaw creator turns down $20M buyout offer, raises $12M seed instead GitHub says hackers stole data from thousands of internal repositories Figma adds an AI assistant to its collaborative canvas This startup raised $43M to build a hive mind for ships Quartermaster is building a maritime hive mind ‘Ask YouTube’ brings AI-powered conversational search to video, adds Gemini Omni to Shorts Google just declared itself a contender in AI design at IO 2026 You can now talk to your Gmail inbox, as seen at Google IO 2026 How to use Google’s new AI agents to go beyond your standard searches Discord enables end-to-end encrypted voice and video calling for every user Mach Industries just spent $50M to solve a major defense tech problem From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing Elon Musk said Sam Altman “stole” a non-profit — but the trial showed he had similar aims Google takes a page out of Meta’s book, announces new audio-powered smart glasses Google takes a page out of Meta’s book, announces new audio-powered smart glasses at IO 2026 Google’s Genie world model can now simulate real streets with Street View With Gemini 3.5 Flash, Google bets its next AI wave on agents, not chatbots How to use Google’s new information agents Google Search as you know it is over Google launches Antigravity 2.0 with an updated desktop app and CLI tool at IO 2026 Google updates its Gemini app to take on ChatGPT and Claude at IO 2026 OpenAI is making it easier to check if an image was made by their models Google’s Gemini Omni turns images, audio, and text into video — and that’s just the start Google just declared itself a contender in AI design Google’s AI Studio now lets anyone build Android apps in minutes Google’s AI now lets you talk to your Gmail inbox Google’s new Universal Cart wants to follow you across the entire internet Google updates its Gemini app to take on ChatGPT and Claude Google introduces Gemini Spark, a 24/7 agentic assistant with Gmail integration Google adds voice-based prompting to Docs and Keep Agentic app coding gets an upgrade with Google’s release of Android CLI Google launches Antigravity 2.0 with an updated desktop app and CLI tool Google’s new Universal Cart wants to follow your entire shopping journey across the internet OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team The minimalist Light Phone teams up with Andrew Yang’s Noble Mobile, which pays you to stop doomscrolling Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack US cyber agency CISA exposed reams of passwords and cloud keys to the open web Apple announces Apple Intelligence powered accessibility feature updates Forget the feed: Status AI raises $17M to turn social media into interactive entertainment ‘Survivor’ stars Kyle Fraser and Kamilla Karthigesu introduce a goal-tracking app, Paprclip Stilta raises $10.5M from a16z and YC to help companies rediscover the patents they forgot they had Solar to dominate energy by 2035, but AI data centers will keep fossil fuels in business Theo Baker spent four years investigating Stanford. Before he leaves, here’s what he found. OSHA probing worker death at SpaceX’s Starbase site SandboxAQ brings its drug discovery models to Claude — no PhD in computing required Anthropic has acquired the dev tools startup used by OpenAI, Google, and Cloudflare Elon Musk has lost his lawsuit against Sam Altman and OpenAI NYC Health and Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people Kin Health raises $9M to build an AI notetaker for patients Amazon’s new Alexa+ powered feature can generate podcast episodes Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom South Korea’s LetinAR is building optics behind AI glasses Apple’s Siri revamp could include auto-deleting chats Why trust is a big question at the Elon Musk-OpenAI trial If you’re giving a commencement speech in 2026, maybe don’t mention AI TechCrunch Mobility: The AI skills arms race is coming for automotive For Eclipse, the $2.5B Cerebras win is just the start of realizing its physical-world thesis The haves and have nots of the AI gold rush Marketing operating system Nectar Social raises $30M Series A led by Menlo Research repository ArXiv will ban authors for a year if they let AI do all the work The offline desk gadget that actually got me to sit up straight OpenAI co-founder Greg Brockman reportedly takes charge of product strategy $60B AI chip darling Cerebras almost died early on, burning $8M a month Users turn to jailbreaking their older Kindles as Amazon ends support RJ Scaringe has raised more than $12 billion across three startups and investors still want more General Catalyst posted VC rage bait and it worked, especially on a16z A hotel check-in system left a million passports and driver’s licenses open for anyone to see Silicon Valley’s vacationland needs a new energy provider just as AI is driving prices up Tesla reveals two Robotaxi crashes involving teleoperators OpenAI launches ChatGPT for personal finance, will let you connect bank accounts
Scammers are abusing an internal Microsoft account to send spam links
Zack Whittak · 2026-05-21 · via TechCrunch

For months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts.

It’s not clear how the scammers are abusing the system, but they have been able to set up new Microsoft accounts as if they are new customers, and use that access to send out emails purportedly from the tech giant itself, potentially tricking people into thinking that these emails may be genuine.

Microsoft doesn’t yet appear to have gotten a handle on the issue.

Last week, I received several, similarly structured emails containing subject lines and web links to scammy sites from Microsoft across different email accounts. These crudely made emails were sent from msonlineservicesteam@microsoftonline.com, an email account that Microsoft uses to send important notifications to users, such as two-factor authentication codes and other critical alerts about their online account.

Some of these emails’ subject lines resembled official emails that would alert users to fraudulent transactions, while other emails claimed to have a private messaging waiting for the recipient at a web address mentioned in the email body.

a copy of the spammy email, which comes from "msonlineservicesteam@microsoftonline.com" but contains clearly spammy content.
Image Credits:TechCrunch (screenshot) /

In a social post on Tuesday, anti-spam non-profit, The Spamhaus Project, said it had also seen Microsoft’s account notification email address being abused to send spam, and that the activity dated back “several months.”

“Automated notification systems should not allow this level of customization,” wrote Spamhaus. The non-profit added that it has notified Microsoft of the issue.

When contacted by TechCrunch earlier this week, a Microsoft spokesperson acknowledged our inquiry, but has not yet commented or said if the company has stopped the abuse of its account notification email.

This is the latest in a rash of incidents in which hackers or scammers have abused company systems to trick unsuspecting customers in recent months. Earlier this year, hackers broke into a platform used by fintech firm Betterment to send out fraudulent notifications that purported to triple the value of any crypto users send in — a widely known scam used to steal people’s cryptocurrency.

Back in 2023, hackers similarly abused access to an email account run by Namecheap to send out phishing emails aimed at stealing people’s credentials.

Other users commenting on social media say that other companies’ email addresses are also being used to send out spam, suggesting the issue is not limited to Microsoft.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio