Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code

Threat actors are now targeting Microsoft 365 accounts using a growing attack method known as OAuth device code phishing. This technique takes advantage of the OAuth 2.0 device authorization flow, a legitimate Microsoft feature designed for devices with limited input options. Attackers trick users into entering codes on authentic Microsoft login pages, which grants them […]

The post Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: