Weekly Vulnerability Alert: August 7, 2026

ArisGate Security Team

•
August 7, 2026
ARISGATE SECURITY BRIEF · PHISHING & SOCIAL ENGINEERING
This phishing campaign never needs your password.
A Russia-linked group is tricking users into approving a real Microsoft consent screen, no credentials required.

Microsoft researchers uncovered a campaign called CaptiveCrunch, tied to the Russia-linked group Storm-2945, also known as Midnight Blizzard, that sent over 200 phishing emails to roughly 120 organizations in a month. The emails do not try to steal a password. Instead, victims are led to a genuine Microsoft login and consent screen, and one click on Accept hands the attacker a token with standing access to mail, files, Teams, and calendar data, no password or MFA prompt bypassed.

Why this matters for your firm

For a Florida firm running Microsoft 365, this is a direct hit on the systems holding privileged client communication, and it stays invisible to password based monitoring since no password was ever compromised.

Florida Bar Rule 4-1.6

Rule 4-1.6 requires reasonable efforts that extend to the permission layer behind the login screen, not just the screen itself.

What to do this week

  1. Review which applications have delegated permissions against your tenant and revoke anything unrecognized.
  2. Require administrator approval for new app consent requests.
  3. Train staff to slow down on any unexpected permission prompt.

How ArisGate helps

ArisGate is built to catch and close exactly this kind of gap. Schedule a free security audit today.

Schedule a Call