Back to news

HollowGraph Hides Espionage in M365 Calendars; Microsoft Patches Record 570 Flaws

A novel malware strain exploits Microsoft 365 calendar events as a covert command channel while Microsoft issues its largest-ever Patch Tuesday, fixing 570 vulnerabilities.

HollowGraph Hides Espionage in M365 Calendars; Microsoft Patches Record 570 Flaws

What happened

Security researchers at Group-IB have identified a sophisticated espionage implant, dubbed HollowGraph, that weaponizes Microsoft 365 calendar infrastructure to receive operator commands and exfiltrate stolen data. The malware plants instructions and smuggles captured files as attachments on calendar entries stamped with dates in the year 2050, a technique that keeps malicious traffic buried within routine Microsoft Graph API calls. Separately, Microsoft's July Patch Tuesday addressed a staggering 570 security vulnerabilities across Windows and related products — nearly triple the previous month's record-breaking count. The company attributed the accelerating discovery rate in part to AI-assisted vulnerability research.

Why it matters for your business

HollowGraph's abuse of legitimate cloud infrastructure means conventional network monitoring tools that whitelist Microsoft Graph API traffic may completely miss an active intrusion. Organizations that have not implemented behavioral anomaly detection or calendar-activity auditing inside Microsoft 365 tenants are particularly exposed. The record patch volume compounds the risk: a backlog of 570 fixes demands immediate triage, and security teams should prioritize any vulnerabilities rated Critical or those associated with remote code execution. Practically, businesses should audit Microsoft 365 audit logs for calendar events with anomalous far-future dates and accelerate patch deployment cycles given the unprecedented volume of this release.

What to watch next

Security teams should monitor whether threat actors adopt HollowGraph's calendar-as-C2 blueprint more broadly, as the technique could easily be adapted to other cloud productivity platforms such as Google Workspace. On the patching front, the sustained surge in discovered vulnerabilities — now aided by AI tooling — suggests monthly patch volumes may remain elevated, pressuring organizations to mature their vulnerability management programs. Additional technical indicators of compromise from Group-IB are expected to follow as the investigation matures.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp