A June 2026 wave of AWS console phishing sites relayed sign-in and MFA to the real AWS in real time, capturing session material from a curated list of engineers. AiTM has moved past Microsoft identity, and the detection has to move with it.
Read more:Datadog Security LabsNVISO Labs
By PhishPond Desk
Phishing-resistant authentication reduces token theft risk, but account recovery, device replacement, and exception handling can reintroduce phishable paths.
Read more:CISAMicrosoft Security Blog
By PhishPond Desk
Enterprise identity teams are treating phishing-resistant authentication as an operating control, not a future-state roadmap item.
Read more:BleepingComputerBleepingComputer
By PhishPond Desk
New phishing kits are pivoting from simple password theft to real-time token capture and replay workflows targeting modern MFA deployments.
Read more:The Hacker NewsThe Hacker News
By PhishPond Desk