Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The service used device-code phishing to gain access to Microsoft accounts and then used AI-powered tools to analyze compromised mailboxes and help attackers identify opportunities for further fraud. The operation highlights how […]
Microsoft 365 OAuth attack incidents have surged in recent years, making the platform one of the major targets for cybercriminals. Microsoft’s 2024 Digital Defense Report states that over 600 million cyberattacks occur daily, covering threats such as ransomware, phishing, and identity-based attacks. Between July 2023 and June 2024, human-operated ransomware incidents increased by 275%, showing […]
The Microsoft device code phishing attack is a sophisticated cyber threat that manipulates the OAuth device authorization flow to bypass multi-factor authentication (MFA) and gain unauthorized access to Microsoft 365 accounts. According to recent cybersecurity reports, over 55% of phishing attacks in 2024 have targeted Microsoft 365 users, emphasizing the growing vulnerability of cloud-based authentication […]