Kali365 targets US organizations with attacker-controlled device codes, potentially exposing Microsoft 365 email, files, and ...
Greatness attackers spoof RingCentral alerts to steal Microsoft 365 tokens through AiTM and device-code phishing attacks.
Hackers are compromising hotel Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages that can ...
The Telegram-distributed service combines AI-assisted lures with device-code phishing and attacker-side session refresh, complicating containment after an account is breached.
New Jalisco and OmegaLord phishing kits target Microsoft 365 accounts by abusing device code flows, OAuth tokens, and MFA prompts to maintain access.
A new phishing-as-a-service (PhaaS) campaign is abusing Microsoft’s device code authentication flow to gain unauthorized access to user accounts. Sekoia researchers first spotted the toolkit ...
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.