logo

Intelligence Insights: June 2026

ID: c4066837-584c-5c6c-8451-64e23aed5f0d

STIX ID: report--c4066837-584c-5c6c-8451-64e23aed5f0d

Feed Name: Red Canary

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: The Red Canary Team

...
...

In April–May 2026 there was a notable rise in OAuth device code phishing against Microsoft Entra ID tenants driven by the subscription-based platform Kali365; attackers send branded phishing links to generate user_codes, trick users into authorizing devices, capture access/refresh tokens, and perform follow-on account takeover and BEC activity. Entra ID sign-in logs show deviceCode authentication events and refresh token redemptions from different IPs, providing detection opportunities via Conditional Access and mailbox rule monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.