Microsoft Outlook bug let attackers run code on a user’s computer
Microsoft has fixed a flaw in Outlook Web Access that may have let attackers take over email accounts simply by getting someone to open a message in the web version of Outlook. Reports suggest the activity focused on government and organizations, but anyone using this webmail service should make sure protections are up to date.
Who is at risk
People and organizations that use Outlook Web Access, especially government offices and workplaces that rely on the web version of Outlook, are most at risk.
What to watch for
Watch for unusual email activity such as messages you did not send, missing emails, unfamiliar inbox rules, or sign-in alerts you do not recognize.
What to do
Make sure Microsoft security updates have been applied, sign out of all Outlook web sessions, change your email password, and turn on two-step verification if it is available.
