<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Adversary-in-the-Middle on CuraSec</title><link>https://curasec.metacog.co.kr/tags/adversary-in-the-middle/</link><description>Recent content in Adversary-in-the-Middle on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/adversary-in-the-middle/index.xml" rel="self" type="application/rss+xml"/><item><title>Greatness PhaaS expands to AiTM and device-code attacks on M365</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.&lt;/li>
&lt;/ul></description></item></channel></rss>