Microsoft Accounts Hijacked via Device Code Phishing Surge
A large-scale phishing-as-a-service operation abuses Microsoft’s device code flow to trick users into authorising attacker-controlled sessions that hand over full mailbox access without stealing passwords. The campaign leverages Kali365 infrastructure to capture OAuth tokens, persist inside accounts, and manipulate inbox rules to hide security alerts.
Source: Arctic Wolf
Read more: CyberSecBrief












