Medium
CVSS: MEDIUM report
When Data Tools Become Dangerous: MS Power BI Links Used in Phishing Campaigns
Tracked since May 6, 2026
CVSS Breakdown
6
CVSS Base Score
MEDIUM
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A
Insurance Impact Assessment
🛡️
Moderate Impact
Medium-severity vulnerabilities generally have limited direct impact on coverage, but accumulations of unpatched medium findings can influence underwriting decisions.
Threat report published 2025-02-06T15:54:44.910Z. Types: threat-report. A sophisticated phishing campaign has been detected that exploits trusted platforms like SharePoint and Power BI to steal user credentials. The scheme uses a seemingly legitimate SharePoint link in an
Assess your exposure
Is your organization vulnerable? Run a free domain exposure scan to check.
Related Threats
Twitter Feed - MichalKoczwara - 07-03-2025
CVSS 6 medium
Malware Filter - Phishing List - 07-03-2025
CVSS 6 medium
SmokeLoader Malware Targets Ukraine's Auto & Banking Sectors via Open Directories
CVSS 6 medium
Not-so-SimpleHelp exploits enabling deployment of Sliver backdoor
CVSS 6 medium
SideWinder targets the maritime and nuclear sectors with an updated toolset
CVSS 6 medium