Cybersecurity News

Filters
Tag
Reset

Filtered by tag: device code authentication × Clear

Device Code Phishing Keeps Evolving. Here’s What to Watch For

Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.