<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #phishing</title><description>Articles tagged phishing on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Scammers turned a Microsoft notification address into a spam relay. The emails pass SPF, DKIM, and DMARC.</title><link>https://devtake.dev/article/microsoft-internal-account-spam-abuse/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-internal-account-spam-abuse/</guid><description>Spammers found a Tenant Name injection in Entra ID that pushes fraud text into Microsoft&apos;s own OTP emails. The from-line reads msonlineservicesteam@microsoftonline.com.</description><pubDate>Mon, 25 May 2026 12:00:00 GMT</pubDate><category>security</category><category>security</category><category>microsoft</category><category>entra-id</category><category>phishing</category><category>dmarc</category><category>spamhaus</category><category>email-security</category><category>credential-theft</category><author>luca-reinhardt</author></item></channel></rss>