Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow

A new phishing campaign targeting Microsoft 365 users has been uncovered, and it takes a different approach than most attacks seen in the wild. Instead of trying to steal a victim’s password directly, this campaign tricks users into completing a real Microsoft authentication process that quietly hands over control of their account to an attacker. […]

The post Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: