Phishing is still one of the most concerning widespread cyber threats that organizations face today. In spite of the ongoing global investment in anti-phishing solutions, attacks still manage to bypass security systems and have a huge impact on individuals, SMBs and large enterprises alike. Furthermore, phishing is no longer limited to email, but is now being delivered via a variety of additional channels, including instant messaging and all kinds of SaaS apps, which are continuing to be widely adopted amidst the rise of hybrid work.This presentation will unveil some of the latest creative tactics and evasion techniques used by threat actors to set up phishing websites that fly under the radar of most conventional anti-phishing security solutions. We will present concrete examples that our incident response team has caught in the wild and try to generalize them into practical tips and lessons that can help security practitioners.Some examples include novel abuse of Microsoft, Google, and modern SaaS services to masquerade phishing content, new Javascript obfuscation and encryption techniques, requiring users to prove their identity before delivery, etc. We'll show how these methods easily bypass well-known defenses applied by enterprises to protect against phishing. We'll also cover new anti-evasion methodologies and approaches that put security in the browser and are able to detect cutting-edge phishing campaigns. By providing a comprehensive overview of modern evasion and anti-evasion tactics, attendees will gain a deeper understanding of how phishing attacks are evolving and how to stay ahead of attackers, which is especially relevant for security professionals, penetration testers, and anyone else responsible for detecting and preventing phishing attacks.