Topics
Follow your own topics →
DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

security: Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint

1 · Sujith Quintelier · Jan. 22, 2026, 7:05 a.m.
Cybersecurity Phishing Business Email Compromise SharePoint
Summary
This blog post discusses a resurgence of a multi-stage AiTM phishing and BEC campaign that exploits SharePoint, as reported by Microsoft Defender researchers. It highlights the targeting of organizations in the energy sector and references guidance provided by Microsoft Security Blog.
Read full post on quintelier.dev →
MORE POSTS LIKE THIS
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
Research Eye · Jun 2, 2026
Tech blog Cybersecurity
security: Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Sujith Quintelier · May 5, 2026
Phishing Cybersecurity
You had six days to patch the latest SharePoint flaw before attackers moved in
Thestack · Jul 23, 2026
microsoft SharePoint
Google Is Suing Chinese Scammers Who Are Using Gemini
Bruce Schneier · Jul 7, 2026
AI china
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Blog Talosintelligence · Jul 1, 2026
Threat Advisory Phishing
Inherited Circuits, Learned Semantics: How Security Fine-Tuning Can Create Hidden Evasion Risk
Blogs Cisco · Jun 29, 2026
Artificial Intelligence (AI) AI Security
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google