SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: ‘Dead’ Outlook add-in hijacked to phish 4,000 Microsoft Office Store users – Computerworld
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > AI > ‘Dead’ Outlook add-in hijacked to phish 4,000 Microsoft Office Store users – Computerworld
AI

‘Dead’ Outlook add-in hijacked to phish 4,000 Microsoft Office Store users – Computerworld

News Room
Last updated: February 12, 2026 7:13 pm
News Room
Share
1 Min Read
SHARE

“Microsoft reviews the manifest, signs it, and lists the add-in in their store. But the actual content – the UI, the logic, everything the user interacts with – is fetched live from the developer’s server every time the add-in opens,” said Koi Security’s researchers.

Orphaned URL

By grabbing the abandoned subdomain, the attacker gained control of whatever the URL in the original manifest pointed to. This content was replaced with a new URL pointing to a phishing kit comprising a fake Microsoft sign-in page for password collection, an exfiltration script, and a redirect. The original manifest also granted the attacker permission to read and modify emails.

“They didn’t submit anything to Microsoft. They weren’t required to pass any review. They didn’t create a store listing. The listing already existed – Microsoft-reviewed, Microsoft-signed, Microsoft-distributed. The attacker just claimed an orphaned URL, and Microsoft’s infrastructure did the rest,” said Koi Security.

Read the full article here

You Might Also Like

US Defense Department takes issue with Anthropic over ethical stance – Computerworld

Four new reasons why Windows LNK files cannot be trusted – Computerworld

Germany greenlights the EU AI Act, triggering countdown for enterprise compliance – Computerworld

Jack Dorsey shrinks Block to ‘intelligence‑native’ model, cutting 4,000 jobs – Computerworld

With physical AI, gunslingers and risk takers need not apply – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

How to pickpocket in Crimson Desert

April 3, 2026
Games

Xenonauts 2 review | PC Gamer

April 3, 2026
Games

The new PC games of April 2026: Pragmata, the next Diablo 4 expansion, and Final Fantasy 14’s big month

April 3, 2026
AI

Microsoft builds its own AI stack to help wean it from its reliance on OpenAI – Computerworld

April 3, 2026
Software

Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative

April 3, 2026
Games

The most hardcore Jak & Daxter heads in the world have finished their native PC ports of the entire trilogy

April 3, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?