AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
ID: b3241154-0199-5db0-83eb-f8f7af1ae48a
STIX ID: report--b3241154-0199-5db0-83eb-f8f7af1ae48a
Feed Name: securityonline.info
Proofpoint and industry reporting describe a rising wave of device code phishing that tricks users into entering attacker-provided alphanumeric codes at the legitimate microsoft.com/devicelogin portal so adversaries can capture authentication tokens. Criminals have improved the technique by generating on-demand device codes at click time—removing the previous time-expiry constraint—and by commercializing tooling via Phishing-as-a-Service offerings (EvilTokens, Tycoon 2FA, ODx) that leverage AI "vibe coding" for rapid scale; organizations are advised to go beyond user training and enforce Conditional Access policies to block or restrict the device code authentication flow.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
