:

HOLLOWGRAPH MALWARE HIJACKS MICROSOFT 365 FOR C2

SECURITY DESK1 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A newly discovered malware component called HollowGraph exploits Microsoft 365 calendar features to communicate with attackers. The malware uses compromised mailboxes as a covert command-and-control channel.

Security researchers have identified HollowGraph, a malicious component that weaponizes Microsoft Graph API to establish hidden communication channels within Microsoft 365 environments. The malware leverages the calendar feature in compromised mailboxes to receive commands from attackers and exfiltrate stolen data. By operating through legitimate Microsoft services, HollowGraph evades traditional security detection mechanisms that typically monitor external network traffic. The use of Microsoft Graph API represents an increasingly common evasion technique. Attackers abuse legitimate cloud services to blend malicious activity with normal business operations, making detection significantly more difficult for defenders. Organizations using Microsoft 365 should review mailbox access logs, monitor for suspicious calendar modifications, and ensure multi-factor authentication is enabled across all accounts. Security teams should also monitor API usage patterns for anomalous behavior indicative of compromised credentials.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researchers discovered that LG smart TVs continue recording audio and scanning local networks even when the display is powered down. The findings raise concerns about user privacy and device security.

JUST NOWIndustry Desk

ConnectWise has disclosed a new vulnerability in ScreenConnect remote access software without an immediate patch available. The company is offering temporary mitigation measures while preparing a fix for later this week.

JUST NOWIndustry Desk

Hackers are actively exploiting a chain of two newly disclosed vulnerabilities in MikroTik RouterOS to seize control of routers with exposed SSH services. The attacks target internet-facing devices and pose immediate risk to affected networks.

JUST NOWSecurity Desk

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.