New Phishing Trends Modern phishing has evolved by leveraging legitimate authentication workflows, trusted infrastructure and encrypted browser sessions. Here are some of the key strategic priorities for cybersecurity leaders to stay ahead of the game: Strategic Priority 1 #1: Identity Assurance Beyond Credentials Device code phishing is an increasing trend that makes use of the legitimate Device Code authentication flow from Microsoft by threat actors such as Kali365. 2) Prepared for a token compromise Incident response plans should include revocation of sessions and refresh tokens, reviewing OAuth consent and investigating mailbox, document and SaaS activity to quickly confirm abuse, identify impacted accounts and assess business impact.

Attribution Time, Beyond MTTI Phishing investigations don’t stop with detection. Investigators should be able to correlate related activity, determine campaign scope, identify impacted users and assess business impact. 1.

Develop tailored response scripts for various types of phishing attempts. 2. ANY.RUN TI Feeds taps into real-world threat data from more than 15,000 organizations to continuously update and analyze indicators in SIEM, SOAR, TIP and EDR platforms, improving security teams’ ability to quickly identify and respond to new phishing campaigns.

ANY. Now, with faster triage and simplified investigations, investigation times are reduced by up to 21 minutes per case, detection rates are up 36%, and encrypted phishing activity is up to 5x higher, thanks to inspection of attacks hiding within HTTPS sessions.RUN TI Feeds helps security teams stay ahead of evolving threats.