New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports.
Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month.
The malware’s communication mechanism relies on the Microsoft Graph API and a compromised 365 account in Israel to hide its C&C communication within legitimate traffic.
Related breach coverage
- In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws2026-07-24
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek.
- Is Patching Dead? Vulnerability Management in the Post-Mythos Era2026-07-23
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.
- Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models2026-07-23
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
- When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover2026-07-22
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek.
