<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phishing on Cyber Mixology</title>
    <link>https://sedward5.com/tags/phishing/</link>
    <description>Recent content in Phishing on Cyber Mixology</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 11 May 2026 10:00:00 +0000</lastBuildDate>
    <atom:link href="https://sedward5.com/tags/phishing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Beyond the Bait: Behavioral Sigma Detections for AiTM Phishing</title>
      <link>https://sedward5.com/beyond-the-bait/</link>
      <pubDate>Mon, 11 May 2026 10:00:00 +0000</pubDate>
      <guid>https://sedward5.com/beyond-the-bait/</guid>
      <description>&lt;p&gt;Phishing campaigns are a moving target. The sender domain rotates every 48 hours. The PDF hash changes with each wave. The landing page infrastructure spins up on fresh hosting and disappears before anyone can block it. Chasing those indicators is necessary. It is also a treadmill.&lt;/p&gt;&#xA;&lt;p&gt;Microsoft&amp;rsquo;s Defender Research team recently published a detailed analysis of a large-scale adversary-in-the-middle phishing campaign that targeted more than 35,000 users across 13,000 organizations using code of conduct lures, multi-stage CAPTCHA gating, and a polished AiTM session hijacking flow. The full technical breakdown is worth reading at the Microsoft Security Blog. Their detections &amp;ndash; Anomalous Token alerts, Impossible Travel flags, and Defender for Office 365 URL click detections &amp;ndash; are the right first line of response for Microsoft shops.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
