SOC status:Duty analyst on shift

UK Cyber Defence

Insights

Answers, not alarms.

Research, detection engineering notes and plain-English explanations for the questions UK boards, IT managers and security leads actually ask. One substantial piece a week; a short threat brief in between.

Get the fortnightly briefing

Double opt-in. Unsubscribe in one click. No sharing, ever.

TopicsAdversary-in-the-middle 1AI in security 2Alert fatigue 1Banking 14Board and governance 3Board governance 1Case study 4CISO 1Cloud security 5Compliance 5Consulting 1Cross-sector 3Data breach 1DDoS 2Defence 14Detection engineering 2DORA 1Education 1Energy 1FCA 1Finance 1Financial services 14Government 14Hacktivism 12
Insights

The phishing page that let Microsoft do the reconnaissance

I spent a few minutes yesterday poking at a phishing page that behaved exactly like the real Microsoft 365 sign-in, because it was the real Microsoft 365 sign-in, relayed through the attacker's server. What made it worth writing about was not the theft of credentials but the quiet way it used Microsoft's own sign-in endpoints to work out, before a password was ever typed, whether it had caught a real account at the right company.

Peter Bassill13 min read · 7 reads

219 articles · page 1 of 19