Weekly Vulnerability Alert: August 7, 2026

ArisGate Security Team

August 7, 2026

Microsoft researchers this week uncovered a phishing campaign researchers are calling CaptiveCrunch, tied to a Russia linked group tracked as Storm-2945, the same actor also known publicly as Midnight Blizzard. Over a one month period, attackers sent more than 200 phishing emails to roughly 120 organizations. What makes this campaign worth your attention is not the volume. It is the method. These emails do not try to steal a password at all.

Instead, the attacker registers their own application inside Microsoft's ecosystem and sends a link that leads to a real Microsoft login and consent screen, the same kind your staff sees dozens of times a week when a legitimate app asks for calendar or file access. Because the login page is genuine, there is no fake password field to spot and no MFA prompt to bypass. The victim is not logging in for the attacker. They are authorizing the attacker's application, and one click on Accept hands over a token with standing access to mail, files, Teams, SharePoint, OneDrive, and calendar data, all without the attacker ever needing a password or a second factor.

For a solo or small Florida law firm running Microsoft 365 for email and document storage, this is a direct hit on exactly the systems that hold privileged client communication. A single consent grant can expose years of case correspondence, trust account communications, and calendar detail on client meetings, all while every password stays exactly as strong as it was before the click. Because no login credential is stolen, this kind of compromise can sit invisible to the password monitoring most firms rely on as their primary defense.

Florida Bar Rule 4-1.6 requires attorneys to make reasonable efforts to prevent unauthorized access to client information. An attacker sitting inside a firm's mailbox and file library through a consent grant is a confidentiality exposure regardless of whether a password was ever compromised, and reasonable efforts has to extend to the permission layer sitting behind the login screen, not just the login screen itself.

Three things worth doing this week. First, have whoever manages your Microsoft 365 tenant review the list of applications with delegated or granted permissions, sometimes called Enterprise Applications, and revoke access for anything unrecognized or unused. Second, restrict user consent so that new app permission requests require administrator approval rather than letting any staff member grant access on the spot, closing the exact door this campaign relies on. Third, train staff to slow down on any screen asking them to review and accept permissions for an app they were not expecting, especially ones with generic names like document viewer or secure mail access, since that pause is the only moment this attack can be stopped.

This is precisely the kind of gap that lives outside the password conversation most firms are already having, and it is exactly what ArisGate is built to catch and close for solo and small Florida law firms. If you are not certain what applications currently have standing access to your firm's mailbox and files, that is worth thirty minutes of your time this week. Schedule a free security audit with ArisGate and get a clear answer.

Schedule a Call