Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
2026-05-05T02:52:20Z•da92d32406747e8e0b7b3bd2b0740580f594d4139cc10a57087febac7e3d0fae
AiTMCAPTCHA-gated phishingCISO guidanceCVE-2026-31431Copy FailKubernetesLinux privilege escalationMicrosoft Agent 365QR code phishingSentinel UEBATycoon2FAcloud securitycredential theftdetectionemail threatsidentity securityphishingshadow AI agentstoken compromise
What happened
Collection of Microsoft Security Blog posts (late Apr–early May 2026) covering a range of active threats and defensive releases. Highlights include: a large-scale multi-stage ‘code of conduct’ credential-phishing campaign that used legitimate email services and fully authenticated mail from attacker-controlled domains to perform AiTM (adversary-in-the-middle) token compromise; a high-severity Linux vulnerability (CVE-2026-31431, “Copy Fail”) enabling root privilege escalation across cloud environments and Kubernetes workloads with a working exploit in the wild; Microsoft Agent 365 general-ava
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- da92d32406747e8e0b7b3bd2b0740580f594d4139cc10a57087febac7e3d0fae
- Enrichment time
- 2026-05-05T02:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.