All updates
Written by May 4, 2026

security: Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

May 4, 2026

Microsoft Defender Research documented a large-scale credential theft campaign using code-of-conduct-themed lures, a multi-step phishing chain, and legitimate email services to send authenticated messages from attacker-controlled domains. The campaign led to adversary-in-the-middle (AiTM) token compromise.

Sponsored by GitAds