Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The service used device-code phishing to gain access to Microsoft accounts and then used AI-powered tools to analyze compromised mailboxes and help attackers identify opportunities for further fraud. The operation highlights how […]
The Microsoft device code phishing attack is a sophisticated cyber threat that manipulates the OAuth device authorization flow to bypass multi-factor authentication (MFA) and gain unauthorized access to Microsoft 365 accounts. According to recent cybersecurity reports, over 55% of phishing attacks in 2024 have targeted Microsoft 365 users, emphasizing the growing vulnerability of cloud-based authentication […]