Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Tag

#Identity

7 articles covering Identity across campaign analysis, detection engineering, and defender tradecraft.

Coverage

7 entries

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Credential Theft

Field Analysis

Blue TeamTradecraft LabsMay 1, 202611 min read

Device Code Phishing: A Walkthrough and Detection Playbook

Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.

Read more:Microsoft Security BlogIETF

By PhishPond Desk

  • #Device Code
  • #OAuth
  • #Identity

Field Analysis

Blue TeamDetection & ValidationApr 29, 202614 min read

Detecting AitM Reverse Proxies: TLS Fingerprints, Cookie Artifacts, and Page-Side Tells

AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.

Read more:SekoiaMicrosoft Threat Intelligence

By PhishPond Desk

  • #AitM
  • #Detection Engineering
  • #TLS

Field Analysis

Blue TeamDetection & ValidationApr 25, 202610 min read

Passkeys Move From Security Project to Front-Line Phishing Control

Enterprise identity teams are treating phishing-resistant authentication as an operating control, not a future-state roadmap item.

Read more:BleepingComputerBleepingComputer

By PhishPond Desk

  • #Passkeys
  • #MFA
  • #Identity

Field Analysis

Red TeamCampaign AnalysisApr 24, 20269 min read

Approval Fatigue Becomes the New Credential Theft Front Door

Attackers are blending push prompts, urgent collaboration lures, and identity fatigue to move users from suspicion to accidental approval.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #Push Fraud
  • #OAuth
  • #Identity

Field Analysis

Red TeamCampaign AnalysisApr 22, 20269 min read

Ai-Powered Invoice Lures Shift to Thread-Hijacked Supplier Mailboxes

Enterprise responders are seeing invoice fraud migrate from bulk spoofing to thread-hijacking and linguistically adaptive payloads.

Read more:BleepingComputerKrebsOnSecurity

By PhishPond Desk

  • #BEC
  • #Supplier Fraud
  • #Thread Hijacking

Field Analysis

Red TeamInfrastructure IntelligenceApr 12, 202610 min read

The 2024–2026 AitM Phishing-as-a-Service Market: Tycoon, EvilProxy, Mamba, Greatness

Reverse-proxy phishing kits commoditized session-token theft over the last two years. The kit market now resembles SaaS, and that has implications for how defenders track operators.

Read more:Microsoft Threat IntelligenceSekoia

By PhishPond Desk

  • #AitM
  • #Threat Intelligence
  • #Phishing Kits

Browse Other Tags

#Detection Engineering#OAuth#Credential Theft#Supply Chain#AiTM#Campaign Analysis#Infrastructure Intelligence#MFA Bypass#SaaS Security#Tradecraft Labs#ClickFix#Developer Security