Detecting Identity Attacks at Scale with Herd Immunity
ID: d7400129-c217-5b00-91a9-29c40ccaabe0
STIX ID: report--d7400129-c217-5b00-91a9-29c40ccaabe0
Feed Name: Arctic Wolf Blog
Arctic Wolf outlines the rapid mainstream adoption of device code phishing via PhaaS platforms (Kali365, EvilTokens), the limitations of single-tenant anomaly detection, and the value of cross-tenant correlation ('herd immunity') to raise confidence in malicious sign‑in events. The report cites an April 2026 campaign in which one IP performed device code authentication against roughly 150 unique identities across more than 110 customer tenants in a week, with investigators confirming the infrastructure as the Kali365 PhaaS that supports device code abuse and adversary-in-the-middle session capture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
