Scammers abusing a real Microsoft account-alert sender are part of a wider pattern: attackers are turning legitimate SaaS notification workflows into authenticated phishing infrastructure.
Read more:TechCrunchAbnormal AI
By PhishPond Desk
Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.
Read more:FBI IC3The Hacker News
By PhishPond Desk
Runtimes, platforms, and brands rotate every quarter. The six handoffs that move a victim from manufactured urgency to durable persistence have barely changed in five years, and they are what defenders can actually build for.
Read more:FBI IC3Microsoft Security Blog
By PhishPond Desk
Vendor headlines about AI phishing blend volume, effectiveness, and survey sentiment into single numbers. Defenders need to separate those measurements to instrument the threat honestly.
Read more:HoxhuntBarracuda
By PhishPond Desk
A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.
Read more:The Hacker NewsMicrosoft Learn
By PhishPond Desk
Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.
Read more:Microsoft Security BlogIETF
By PhishPond Desk
AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.
Read more:SekoiaMicrosoft Threat Intelligence
By PhishPond Desk
What started as a niche fake-CAPTCHA gimmick became one of 2026's most common stage-one execution pivots. This is what defenders are seeing in telemetry and what the response patterns look like.
Read more:Microsoft Threat IntelligenceProofpoint
By PhishPond Desk
Detection teams are reducing alert fatigue by combining message artifacts with identity and endpoint context in tiered scoring pipelines.
Read more:Microsoft Security BlogCISA
By PhishPond Desk