Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Category

Research Reports

Longer-form research notes, measurement studies, and periodic threat briefs.

  • 8research notes
  • 7blue-team studies
  • 1red-team studies
  • 0dual-use studies
  • May 20, 2026latest note

Lead Research Note

Research Note: Measuring AI-Generated Phishing Without the Survey Noise

The interesting question is not whether AI phishing is rising. It is which measurements are decision-grade and which are marketing.

May 20, 20269 min readPhishPond Desk

Research Lanes

  • Infrastructure CorrelationDomains, certificates, hosting reuse, and takedown-ready clustering.
  • Control QualityAuthentication, reporting, containment, and measurement beyond click rate.
  • Operational TranslationHow findings become SOC workflows, detections, and program decisions.

Research Archive

8 entries

Field Analysis

Blue TeamResearch ReportsMay 20, 20269 min read

Research Note: Measuring AI-Generated Phishing Without the Survey Noise

Vendor headlines about AI phishing blend volume, effectiveness, and survey sentiment into single numbers. Defenders need to separate those measurements to instrument the threat honestly.

Read more:HoxhuntBarracuda

By PhishPond Desk

  • #Research
  • #AI Phishing
  • #Detection Engineering

Field Analysis

Blue TeamResearch ReportsMay 16, 20269 min read

Recent Linux LPEs Turn Local Footholds Into Infrastructure Control

Copy Fail, Dirty Frag, and ssh-keysign-pwn show why local Linux privilege escalation still belongs in phishing and infrastructure-defense planning.

Read more:CERT-EUDirty Frag

By PhishPond Desk

  • #Linux
  • #Privilege Escalation
  • #Infrastructure

Field Analysis

Blue TeamResearch ReportsMay 3, 20269 min read

Research Note: Phishing-Resistant MFA Still Depends on Recovery Workflow Quality

Phishing-resistant authentication reduces token theft risk, but account recovery, device replacement, and exception handling can reintroduce phishable paths.

Read more:CISAMicrosoft Security Blog

By PhishPond Desk

  • #MFA
  • #Passkeys
  • #Account Recovery

Field Analysis

Blue TeamResearch ReportsApr 30, 20268 min read

Q1 Email Threat Data Points Defenders Toward Links, QR Codes, and BEC

Microsoft's Q1 2026 email threat review shows link-based phishing dominance, QR code growth, CAPTCHA-gated flows, and persistent business email compromise pressure.

Read more:Microsoft Security Blog

By PhishPond Desk

  • #Research Reports
  • #QR Phishing
  • #BEC

Field Analysis

Blue TeamResearch ReportsApr 27, 20268 min read

Research Note: QR Phishing Needs Measurement Beyond Message Volume

QR phishing programs are easier to understand when teams measure scan context, report timing, landing-page behavior, and control coverage instead of only counting delivered messages.

Read more:Microsoft Security BlogCISA

By PhishPond Desk

  • #QR Phishing
  • #Metrics
  • #Email Security

Field Analysis

Blue TeamResearch ReportsApr 22, 202610 min read

Research Note: OAuth Consent Debt Builds Quietly Until Incident Response Needs It Gone

OAuth app grants accumulate over time, and stale consent can become a hidden access path when vendors, users, or integrations are later compromised.

Read more:Microsoft LearnThe Hacker News

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Consent Governance

Field Analysis

Red TeamResearch ReportsApr 16, 20267 min read

Quarterly Phishing Brief: Regional Targeting Intensifies in Health Systems

Healthcare organizations are experiencing clustered phishing campaigns aligned to regional staffing and patient billing cycles.

Read more:The Hacker NewsCISA

By PhishPond Desk

  • #Healthcare
  • #Regional Campaigns
  • #Awareness

Field Analysis

Blue TeamResearch ReportsMar 24, 20268 min read

Inside the Metrics: Measuring Mitigation Quality, Not Just Click Rate

Security leaders are expanding phishing KPIs beyond user clicks to include reporting speed, containment time, and repeat exposure risk.

Read more:Microsoft Security Blog

By PhishPond Desk

  • #Metrics
  • #Program Maturity
  • #Resilience

Explore Other Categories

  • Campaign Analysis
  • Tradecraft Labs
  • Infrastructure Intelligence
  • Detection & Validation