Blog

June 2, 2026

Eleven Months Undetected: The Wiley Rein Breach and the Configuration Gap MSPs Must Close

Chinese state actors held access to Wiley Rein's Microsoft 365 tenant for eleven months before detection. The breach reveals how unenforced security…

Read more →
May 26, 2026

The OAuth Gap: How Professional Services Firms Lose Client Data Through Microsoft 365 Misconfiguration

A midsize accounting firm's tenant was locked after OAuth tokens were harvested through fake compliance emails. The April 2026 breach exposed the…

Read more →
May 12, 2026

Why Professional Services Firms Keep Losing to the Same Microsoft 365 Misconfigurations

Between April phishing campaigns and the Vercel OAuth breach, professional services firms face threat actors who exploit the same Microsoft 365 configuration…

Read more →
May 6, 2026

The OAuth Token That Opened 340 Organizations

In February 2026, a Roblox cheat download led to production infrastructure compromise at Vercel—exposing how OAuth sprawl and unrestricted app permissions create…

Read more →
April 28, 2026

The DocketWise Breach and the OAuth Gap Nobody Fixed

OAuth app permissions enabled the DocketWise breach affecting 116,000 individuals and a device code phishing campaign compromising 340+ Microsoft 365 orgs in…

Read more →
April 22, 2026

When Compliance Documentation Doesn’t Match Configuration: DocketWise and Mercor Breaches

DocketWise exposed 116,666 records in April 2026. Mercor's whistleblower documented systematic gaps between SOC2 audits and actual tenant posture. Both incidents prove…

Read more →
April 15, 2026

How We Built a 40-Tool MCP Server for M365 Compliance Automation

Most MCP servers connect to one tool. Ours orchestrates 40+ across Microsoft Graph, SharePoint, Planner, ADO, and WordPress — powering compliance automation…

Read more →
March 31, 2026

MFA Won’t Save You From This: The OAuth Token Hijack Hitting Legal and Healthcare Firms Right Now

A phishing campaign exploiting Microsoft's own OAuth flow has compromised over 340 organizations — including legal and healthcare firms — since February…

Read more →
March 15, 2026

When “We Have DLP Enabled” Isn’t Actually a Defense

Three incidents from early 2026 — a LexisNexis breach, a Microsoft Copilot DLP bypass, and a surge in OAuth phishing — share…

Read more →
December 28, 2025

Why the Holidays Are “Phishing Season” (And How to Stay Safe)

While you are busy hunting for Cyber Monday deals and tracking last-minute shipments, cybercriminals are busy, too. The holiday season is historically…

Read more →