A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
Extortion gangs are using passkey and SSO phishing to hijack Microsoft accounts, steal tokens, and exfiltrate Microsoft 365 ...
BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and ...
A new phishing-as-a-service (PhaaS) campaign is abusing Microsoft’s device code authentication flow to gain unauthorized access to user accounts. Sekoia researchers first spotted the toolkit ...
In February 2025, the Microsoft Threat Intelligence Center warned that Russian hackers were targeting Microsoft 365 accounts using device code phishing. In December, ProofPoint reported similar ...