💻 techConcept0 views4 min read

What Happened to Hacking the Windows 365 Link?

The concept of 'Hacking the Windows 365 Link' encompasses a series of vulnerabilities and sophisticated attack methods that have targeted Microsoft's Windows 365 and broader Microsoft 365 services since their inception. These attacks primarily leverage malicious links, URL redirection, and compromised authentication flows to steal credentials, bypass multi-factor authentication, and exfiltrate sensitive data. Microsoft has continuously responded with security enhancements, new default policies, and patches to mitigate these evolving threats.

Share:

Quick Answer

Hacking the Windows 365 Link refers to various security exploits and vulnerabilities that have emerged since Windows 365's launch, focusing on manipulating URLs and authentication processes. Early incidents involved credential extraction via tools like Mimikatz, while later attacks evolved to sophisticated phishing using OAuth redirection and device code flows. As of August 2026, threats include advanced phishing-as-a-service platforms like Kali365, exploitation of trusted Microsoft domains (SearchLeak), and network-level attacks via compromised Wi-Fi gateways, with Microsoft consistently rolling out updates and enhanced security defaults to counter these persistent challenges.

📊Key Facts

Initial Credential Exploit Disclosure
August 2021
Techzine
OAuth Redirection Attack Discovery
December 2021
Proofpoint
Windows 365 Link Device Release
November 2024 (Preview)
Help Net Security
Enhanced Security Defaults Rollout
Second half of 2025
Bleeping Computer
Kali365 PhaaS Emergence
April 2026
FBI IC3
SearchLeak (CVE-2026-42824) Discovery
June 2026
The Hacker News
Hotel Wi-Fi Gateway Attacks Identified
July 2026
ReliaQuest

📅Complete Timeline13 events

1
August 17, 2021Major

Benjamin Delpy Demonstrates Credential Extraction

Security researcher Benjamin Delpy publicly demonstrated a vulnerability in the newly released Windows 365 Cloud PC, showing how Azure user credentials could be extracted in plaintext using Mimikatz, raising initial security concerns.

2
December 8, 2021Major

OAuth Redirection Attacks Discovered

Proofpoint researchers identified new methods for URL redirection attacks exploiting Microsoft's OAuth 2.0 implementations, which leveraged malicious redirect URLs within legitimate Microsoft 365 third-party applications to bypass phishing detection.

3
May 16, 2023Notable

Open Redirect Vulnerabilities Abused in M365 Phishing

Attackers were observed refining open redirect techniques in Microsoft 365 phishing campaigns, utilizing legitimate domains and multiple redirection hops to lead users to phishing sites, sometimes exploiting vulnerabilities like BIG-IP CVE-2023-22418.

4
November 4, 2024Major

Microsoft Enhances M365 Security & Unveils Windows 365 Link Device

Microsoft announced increased Mobile Application Management (MAM) security, screen capture protection, and watermarking for Cloud PCs. Concurrently, they unveiled 'Windows 365 Link,' a dedicated, secure hardware device for connecting to Cloud PCs.

5
June 19, 2025Critical

New Security Defaults for Windows 365 Cloud PCs Announced

Microsoft announced that starting in the second half of 2025, new Windows 365 Cloud PCs would have clipboard, drive, USB, and printer redirections disabled by default to mitigate data exfiltration and malware risks. Virtualization-Based Security (VBS), Credential Guard, and HVCI were also enabled by default for Windows 11 Cloud PCs.

6
August 2, 2025Major

Link-Wrapping Services Abused for M365 Phishing

Threat actors were found abusing link-wrapping features of legitimate cybersecurity services (like Proofpoint and Intermedia) to mask malicious links leading to Microsoft 365 phishing pages, bypassing email security solutions.

7
December 19, 2025Major

Device Code Phishing Campaigns Target M365 Users

Multiple threat groups, including state-linked actors, were reported using device code phishing to trick users into granting access to their Microsoft 365 accounts by abusing legitimate Microsoft device authorization processes, often bypassing MFA.

8
January 14, 2026Notable

Windows Security Update Disrupts Cloud PC Access

A Windows security update (KB5074109) caused authentication errors and connection failures for some Windows 365 Cloud PC users, leading to service degradation and requiring temporary workarounds.

9
March 2, 2026Major

Microsoft Defender Uncovers OAuth Redirection Abuse

Microsoft Defender researchers identified ongoing phishing campaigns that exploit legitimate OAuth protocol functionality to manipulate URL redirection, bypassing conventional phishing defenses across email and browsers.

10
May 21, 2026Critical

FBI Warns of Kali365 Phishing-as-a-Service

The FBI issued a Public Service Announcement about Kali365, a new Phishing-as-a-Service platform emerging in April 2026, which enables attackers to obtain Microsoft 365 access tokens and bypass MFA using device code phishing.

11
June 15, 2026Critical

SearchLeak Vulnerability (CVE-2026-42824) in M365 Copilot Discovered

Varonis Threat Labs revealed 'SearchLeak,' a one-click flaw in Microsoft 365 Copilot Enterprise Search (CVE-2026-42824) that could allow attackers to exfiltrate emails, calendar details, and indexed files via a trusted Microsoft link. Microsoft mitigated the issue on its backend.

12
July 28, 2026Major

Hotel Wi-Fi Gateway Compromise for M365 Credential Theft

ReliaQuest Threat Research team reported that attackers were compromising captive Wi-Fi gateways at hotels and conference centers to silently redirect authentication traffic and steal Microsoft 365 credentials without touching user devices.

13
August 3, 2026Critical

Midnight Blizzard Linked to Hotel Wi-Fi Hacks

Microsoft attributed the ongoing campaign targeting travelers on hotel Wi-Fi networks, which involves credential theft and malware deployment, to the Russian state-sponsored hacking group Midnight Blizzard.

🔍Deep Dive Analysis

Since the introduction of Windows 365, Microsoft's Cloud PC service, the concept of 'hacking the Windows 365 link' has evolved from initial vulnerability discoveries to sophisticated, multi-layered cyberattacks. This phrase broadly describes various security incidents and methods where attackers exploit links, redirection mechanisms, and authentication processes within Windows 365 and the wider Microsoft 365 ecosystem.

One of the earliest notable incidents occurred in August 2021, shortly after Windows 365 became generally available. Security researcher Benjamin Delpy demonstrated how Azure user credentials could be extracted in plaintext from Windows 365 Cloud PCs using his Mimikatz software. While this exploit required administrative privileges on the Cloud PC, it highlighted initial security concerns for the nascent service. This event underscored the importance of robust endpoint security even within a cloud-based environment.

As the platform matured, attackers shifted focus to more subtle methods. December 2021 saw Proofpoint uncover new techniques for URL redirection attacks leveraging Microsoft's OAuth 2.0 implementations. These attacks bypassed traditional phishing detection by abusing legitimate Microsoft 365 third-party applications with malicious redirect URLs, making phishing attempts appear more credible. This trend continued into May 2023, with refined open redirect vulnerabilities being exploited in Microsoft 365 phishing campaigns, often using multiple redirection hops and legitimate domains to obscure the malicious final destination.

Microsoft has responded proactively by continuously enhancing security. In November 2024, significant updates included increased Mobile Application Management (MAM) security, screen capture protection, and watermarking for Cloud PCs. Concurrently, Microsoft introduced the 'Windows 365 Link' device, a purpose-built, locked-down hardware solution designed to provide a highly secure connection to Cloud PCs, emphasizing passwordless authentication and reduced attack surface. A major turning point in platform-wide security came in June 2025, when Microsoft announced new default security settings for Windows 365 Cloud PCs. These changes, implemented in the second half of 2025, included disabling clipboard, drive, USB, and printer redirections by default to prevent data exfiltration and malware injection. Furthermore, Virtualization-Based Security (VBS), Credential Guard, and Hypervisor-Protected Code Integrity (HVCI) were enabled by default on Windows 11 Cloud PCs, significantly hardening the environment against kernel-level exploits.

Despite these advancements, threat actors continued to innovate. August 2025 saw the abuse of legitimate link-wrapping services from cybersecurity firms to mask malicious Microsoft 365 phishing links, effectively turning security features against users. By December 2025, a new wave of device code phishing emerged, where attackers exploited Microsoft's legitimate device authorization process to trick users into granting access to their Microsoft 365 accounts, often bypassing MFA. This technique gained significant traction, leading to the emergence of the Kali365 Phishing-as-a-Service (PhaaS) platform in April 2026, which offered less-technical attackers tools to capture OAuth tokens and maintain persistent access to Microsoft 365 environments.

Recent developments in 2026 highlight the persistent and evolving nature of these threats. In June 2026, Varonis Threat Labs discovered 'SearchLeak' (CVE-2026-42824), a critical one-click vulnerability in Microsoft 365 Copilot Enterprise Search that could allow attackers to exfiltrate sensitive data like emails and MFA codes by exploiting trusted Microsoft links. Microsoft swiftly mitigated this backend flaw. Most recently, as of July and August 2026, threat actors, including the Russian state-sponsored group Midnight Blizzard, have been compromising captive Wi-Fi gateways in hotels and conference centers. This allows them to silently redirect authentication traffic and steal Microsoft 365 credentials without direct interaction with the user's device, representing a significant network-level threat. Microsoft continues to release regular security updates for Windows 365 and Microsoft 365 applications, addressing new vulnerabilities and enhancing overall platform resilience.

What If...?

Explore alternate histories. What if Hacking the Windows 365 Link made different choices?

Explore Scenarios
Building relationship map...

People Also Ask

What is 'Hacking the Windows 365 Link'?
'Hacking the Windows 365 Link' refers to a category of security vulnerabilities and attack methods that exploit links, URL redirection, and authentication processes within Microsoft Windows 365 and the broader Microsoft 365 ecosystem to compromise user accounts and data. These attacks have evolved from simple credential extraction to sophisticated phishing and network-level exploits.
What are some examples of 'Hacking the Windows 365 Link' incidents?
Examples include Benjamin Delpy's Mimikatz exploit for credential extraction in 2021, OAuth redirection attacks bypassing phishing detection, the abuse of legitimate link-wrapping services, device code phishing campaigns (like Kali365), and the recent SearchLeak vulnerability in Microsoft 365 Copilot.
How has Microsoft responded to these link-based vulnerabilities?
Microsoft has continuously responded with security enhancements, including increased Mobile Application Management, screen capture protection, and the introduction of the secure Windows 365 Link device. They have also implemented new default security policies, such as disabling clipboard and drive redirections, and enabling advanced security features like VBS and Credential Guard.
What is the 'SearchLeak' vulnerability?
Discovered in June 2026, 'SearchLeak' (CVE-2026-42824) was a critical one-click flaw in Microsoft 365 Copilot Enterprise Search. It could have allowed attackers to exfiltrate sensitive data like emails, calendar details, and indexed files by exploiting trusted Microsoft.com links through a combination of parameter-to-prompt injection and a race condition. Microsoft mitigated the flaw on its backend.
Are there current threats related to 'Hacking the Windows 365 Link'?
Yes, as of August 2026, current threats include the widespread use of Phishing-as-a-Service platforms like Kali365 for device code phishing and network-level attacks. Notably, the Russian state-sponsored group Midnight Blizzard has been compromising hotel Wi-Fi gateways to silently redirect traffic and steal Microsoft 365 credentials.