Intelligence Insights: June 2026
ID: c4066837-584c-5c6c-8451-64e23aed5f0d
STIX ID: report--c4066837-584c-5c6c-8451-64e23aed5f0d
Feed Name: Red Canary
In April–May 2026 there was a notable rise in OAuth device code phishing against Microsoft Entra ID tenants driven by the subscription-based platform Kali365; attackers send branded phishing links to generate user_codes, trick users into authorizing devices, capture access/refresh tokens, and perform follow-on account takeover and BEC activity. Entra ID sign-in logs show deviceCode authentication events and refresh token redemptions from different IPs, providing detection opportunities via Conditional Access and mailbox rule monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
