Blogs.Microsoft Large-Scale Code of Conduct Phishing Campaign Targets 35,000 Users
Article Content
- •Over 35,000 users from 13,000 organizations were targeted in a phishing campaign.
- •The attack used code of conduct-themed lures and multi-step methods for credential theft.
- •Microsoft Defender identified the campaign as leading to AiTM token compromises.
A sophisticated phishing campaign themed around code of conduct documents has compromised over 35,000 users from 13,000 organizations. The multi-stage attack occurred between April 14 and April 16, 2026, primarily affecting users in the United States. Attackers utilized social engineering tactics and legitimate email services to distribute fully authenticated messages from domains they controlled. Microsoft Defender Research reported that the campaign led to the compromise of authentication tokens through an Account Takeover (AiTM) method. The attack highlights the evolving nature of phishing threats and the need for enhanced security measures. Current status indicates ongoing investigations and heightened awareness among targeted organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…