Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days on the annual plan.Learn More
MERENA
Advisory Alert

Microsoft Outlook bug let attackers run code on a user’s computer

Microsoft has fixed a flaw in Outlook Web Access that may have let attackers take over email accounts simply by getting someone to open a message in the web version of Outlook. Reports suggest the activity focused on government and organizations, but anyone using this webmail service should make sure protections are up to date.


Who is at risk

People and organizations that use Outlook Web Access, especially government offices and workplaces that rely on the web version of Outlook, are most at risk.

What to watch for

Watch for unusual email activity such as messages you did not send, missing emails, unfamiliar inbox rules, or sign-in alerts you do not recognize.

What to do

Make sure Microsoft security updates have been applied, sign out of all Outlook web sessions, change your email password, and turn on two-step verification if it is available.