Malicious Outlook add-in “AgreeToSteal” hijacked a deleted subdomain.
Uncategorized
1
Posts
1
Posters
2
Views
-
Malicious Outlook add-in “AgreeToSteal” hijacked a deleted subdomain.
Result:
• 4,000+ accounts compromised
• Fake Microsoft login inside Outlook
• Credit cards + banking data stolen
Manifest validated once. External URL later hijacked.
Architectural gap exposed.#InfoSec #Microsoft365 #Phishing #SaaSSecurity

-
R relay@relay.infosec.exchange shared this topic