CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 534

As cited

Copy frozen at (site build).

threat intel

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A phishing campaign targeting Microsoft 365 accounts has exploited the Microsoft device-code authentication flow using collaboration-themed lures. Rather than employing fake login pages, the attackers directed victims to the legitimate Microsoft device login process, potentially making the attack more credible to users.

Why it matters: M365 users and administrators need to recognize device-code phishing techniques as a threat vector, since these attacks bypass traditional password page detection and can lead to account compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A phishing campaign targeting Microsoft 365 accounts has exploited the Microsoft device-code authentication flow using collaboration-themed lures. Rather than employing fake login pages, the attackers directed victims to the legitimate Microsoft device login process, potentially making the attack more credible to users.

Why it matters: M365 users and administrators need to recognize device-code phishing techniques as a threat vector, since these attacks bypass traditional password page detection and can lead to account compromise.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary