Analysis of roughly 3,000 live ClickFix payloads shows the clipboard command is now served by a backend that hands every visitor a freshly scrambled variant. The delivery moved server-side, and so did the detection problem.
Read more:The Hacker NewsSplunk Security Content
By PhishPond Desk
Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.
Read more:Proofpoint Threat ResearchMicrosoft Learn
By PhishPond Desk
Chrome's Device Bound Session Credentials, now generally available and on by default for Workspace, tie session cookies to a device's security chip so a stolen cookie is useless off the machine it came from. Here is what it stops and what it does not.
Read more:Google Security BlogBleepingComputer
By PhishPond Desk
GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.
Read more:GitHub ChangelogCISA
By PhishPond Desk
A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.
Read more:The Hacker NewsMicrosoft Learn
By PhishPond Desk
Restricting new consent is only half the work. Existing app grants need review, ownership, and a path to removal when risk changes.
Read more:Microsoft LearnMicrosoft Learn
By PhishPond Desk
The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.
Read more:The Hacker NewsThe Hacker News
By PhishPond Desk
Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.
Read more:The Hacker NewsMicrosoft Learn
By PhishPond Desk
AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.
Read more:SekoiaMicrosoft Threat Intelligence
By PhishPond Desk
Enterprise identity teams are treating phishing-resistant authentication as an operating control, not a future-state roadmap item.
Read more:BleepingComputerBleepingComputer
By PhishPond Desk
Most M365 phishing incidents are decided in the first hour. This walkthrough lays out a 60-minute response chain from user report to refresh-token revocation and consent reversal.
Read more:Microsoft LearnMicrosoft Threat Intelligence
By PhishPond Desk
QR-based payload delivery continues to evade static scanning workflows and pushes users toward unmanaged mobile browsing paths.
Read more:Microsoft Security Blog
By PhishPond Desk
Detection teams are reducing alert fatigue by combining message artifacts with identity and endpoint context in tiered scoring pipelines.
Read more:Microsoft Security BlogCISA
By PhishPond Desk
Investigators report a rise in hidden forwarding and deletion rules used to suppress fraud conversations after initial compromise.
Read more:BleepingComputer
By PhishPond Desk