Medium CVSS: MEDIUM report

When Data Tools Become Dangerous: MS Power BI Links Used in Phishing Campaigns

Tracked since May 6, 2026

CVSS Breakdown

6
CVSS Base Score
MEDIUM
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Insurance Impact Assessment

🛡️
Moderate Impact

Medium-severity vulnerabilities generally have limited direct impact on coverage, but accumulations of unpatched medium findings can influence underwriting decisions.

Threat report published 2025-02-06T15:54:44.910Z. Types: threat-report. A sophisticated phishing campaign has been detected that exploits trusted platforms like SharePoint and Power BI to steal user credentials. The scheme uses a seemingly legitimate SharePoint link in an

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed