Hackers Abuse OAuth Device Authorization Flow to Steal Microsoft 365 Tokens
ID: 3fbea925-a8b7-5e7f-a8e0-01d5d29513ad
STIX ID: report--3fbea925-a8b7-5e7f-a8e0-01d5d29513ad
Feed Name: cybersecurityNews.com
Threat Score
Device code phishing campaigns exploit the OAuth 2.0 device authorization flow by inducing users to enter attacker-provided device codes on legitimate Microsoft login pages, granting threat actors persistent access to Microsoft 365 accounts; the report documents a surge in campaigns since late 2024, lists observed actors and toolkits, provides numerous domain IoCs, and recommends mitigations such as conditional access policies and enhanced user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
