The images in this article were generated with artificial intelligence. How we publish
E-mail remains the preferred route by the attackers and, in 2026, techniques have matured to turn many campaigns into real stealth exercises: messages generated by IA, supplanting reliable business identities and legitimate authentication flows that defenders interpret as benign. These changes require rethinking not only the tools, but also the operational strategies for detection and response in security equipment.
On 8 July 2026, BleepingComputer organize an online seminar that promises to address these challenges with a practical and case-based perspective, presented by Dan Nickolaisen (Abnormal AI) and Eric Danneker (Novant Health). Assisting can serve both to validate operational concerns and to collect concrete techniques to reduce the manual load that today suffocates many SOCs.

The attackers no longer rely solely on emails with orthographic errors or obvious links. The use of legitimate compromised accounts and flows such as the Device Code (device authorization) allows to circumvent MFA and credentials monitoring systems because the authentication transaction appears to be valid. Microsoft documents how the Device Code flow works and why it requires additional controls; knowing these technical details helps design effective mitigation ( learn).
The typical answer - multiplying rules in the mail gateway or relying exclusively on MFA - is no longer enough. The real advance today is to incorporate contextual and behavioural signals: who usually sends emails to whom, which header patterns and frequency are common, and how identities interact with authentication applications and flows. That is the central proposal of platforms that apply behavioral IA to distinguish real noise anomalies and reduce false positive.
Behavior-based detection offers clear advantages: automates the prioritization of incidents, accelerates research and allows contextual remedies (post reversion, tokens revocation, session blocking) not dependent on humans for every step. However, it is not a panacea. These solutions require good quality telemetry, integration with identity systems and governance policies to avoid dangerous automated decisions.
On the operational level, the combination of tools is critical: combining abnormal detection with orchestration playbooks (SOAR), conditional access controls and an account segmentation strategy reduces the attacker's persistence window. At the same time, it is essential to maintain well-designed awareness programmes and simulations that include modern vectors - for example, attacks that exploit OAuth consent or device flow abuses - so as not to be anchored to obsolete phishing exercises.
Organizations that want to prioritize efforts should assess three fronts: integrity and centralization of login to feed behavioral models; automated response capacity for low-risk mitigation actions; and specific technical controls against OAuth and Device Code abuse. Review applications with high privilege permits, limit third-party consent and implement risk-based conditional access policies are concrete and effective measures.

The discussion that Abnormal AI will propose in the webinar is not only technological, but operational: how to move from receiving isolated alerts to managing automated workflows that close the detection-mediation cycle. To better understand these capabilities and compare approaches, it may also be useful to consult the documentation and resources of providers specialized in mail security and authentication, such as Abnormal Security ( abnormalsecurity.com), which combines behavior analysis with automated mediation.
If your team suffers from warning fatigue, long research tails or excessive reliance on manual analysis, booking a space in this type of event can offer short-term applicable tactics and a road map to integrate behavioral models into the security architecture. Take the opportunity to ask the rapporteurs for implementation cases, false positive reduction metrics and integration requirements.
Finally, remember that the defense against these attacks is collective: sharing indicators between teams, auditing permits and maintaining dynamic access controls are practices that reduce systemic risk. To deepen authentication flows and their technical risks, Microsoft's documentation on Device Code flow is a useful technical starting point ( learn), and to follow the impact and analysis of mail campaigns, the specialized coverage of BleepingComputer It is often a practical and up-to-date resource.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...