:

HOLLOWGRAPH MALWARE HIJACKS MICROSOFT 365 FOR C2

SECURITY DESK1 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A newly discovered malware component called HollowGraph exploits Microsoft 365 calendar features to communicate with attackers. The malware uses compromised mailboxes as a covert command-and-control channel.

Security researchers have identified HollowGraph, a malicious component that weaponizes Microsoft Graph API to establish hidden communication channels within Microsoft 365 environments. The malware leverages the calendar feature in compromised mailboxes to receive commands from attackers and exfiltrate stolen data. By operating through legitimate Microsoft services, HollowGraph evades traditional security detection mechanisms that typically monitor external network traffic. The use of Microsoft Graph API represents an increasingly common evasion technique. Attackers abuse legitimate cloud services to blend malicious activity with normal business operations, making detection significantly more difficult for defenders. Organizations using Microsoft 365 should review mailbox access logs, monitor for suspicious calendar modifications, and ensure multi-factor authentication is enabled across all accounts. Security teams should also monitor API usage patterns for anomalous behavior indicative of compromised credentials.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect to breach corporate networks. Arctic Wolf disclosed the active exploitation campaign.

2H AGOSecurity Desk

Meta's Ray-Ban smartglasses can record video without obvious indicators, raising child safety concerns. The company places responsibility on users to avoid 'actively exploiting' the technology rather than implementing technical safeguards.

4H AGOAI Desk

Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.

4H AGOSecurity Desk

The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.

9H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.