Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

2026-05-05T02:52:20Zda92d32406747e8e0b7b3bd2b0740580f594d4139cc10a57087febac7e3d0fae
AiTMCAPTCHA-gated phishingCISO guidanceCVE-2026-31431Copy FailKubernetesLinux privilege escalationMicrosoft Agent 365QR code phishingSentinel UEBATycoon2FAcloud securitycredential theftdetectionemail threatsidentity securityphishingshadow AI agentstoken compromise

What happened

Collection of Microsoft Security Blog posts (late Apr–early May 2026) covering a range of active threats and defensive releases. Highlights include: a large-scale multi-stage ‘code of conduct’ credential-phishing campaign that used legitimate email services and fully authenticated mail from attacker-controlled domains to perform AiTM (adversary-in-the-middle) token compromise; a high-severity Linux vulnerability (CVE-2026-31431, “Copy Fail”) enabling root privilege escalation across cloud environments and Kubernetes workloads with a working exploit in the wild; Microsoft Agent 365 general-ava​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
da92d32406747e8e0b7b3bd2b0740580f594d4139cc10a57087febac7e3d0fae
Enrichment time
2026-05-05T02:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.