Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

2026-05-06T14:52:19Zcbe3e97ff5768265321e4956723a03072765a649278564b0402c51ed2fcb094e
AiTMCAPTCHA-gated phishingCISO best practicesCVE-2026-31431Copy FailDynamics 365KubernetesLinux privilege escalationMicrosoft Agent 365Power PlatformQR phishingSentinel UEBATycoon2FAcloud securitycredential theftemail threatsexploit-in-the-wildidentity protectionphishingshadow AItoken theft

What happened

Microsoft Security Blog round-up (Apr–May 2026): Microsoft Defender Research details a large-scale, multi-stage credential‑theft phishing campaign using ‘code of conduct’ lures and legitimate email services to deliver fully authenticated messages and AiTM (account‑in‑the‑middle) token theft. Separately, Microsoft warns of CVE-2026-31431 (“Copy Fail”), a high‑severity Linux vulnerability enabling root privilege escalation across cloud and Kubernetes environments with a working exploit in the wild. The feed also announces Microsoft Agent 365 general availability (with shadow‑AI discovery/manager

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
cbe3e97ff5768265321e4956723a03072765a649278564b0402c51ed2fcb094e
Enrichment time
2026-05-06T14:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise · Baitaphish