The Sign-In Page Was Genuinely Microsoft's Own. DMARC Had Nothing Left to Check.
Researchers at Check Point have documented a phishing campaign that skips the part security teams spend the most time training people to spot. Running from late June through the second week of July, the campaign sent …