More

    State actors are abusing OAuth device codes to get full M365 account access – here’s what we know



    • Proofpoint reports phishing surge abusing Microsoft OAuth 2.0 device code flow
    • Victims enter codes on real Microsoft domains, granting attackers access tokens
    • Proofpoint advises blocking device code flows

    Cybercriminals, including state-sponsored threat actors, are increasingly abusing Microsoft’s OAuth 2.0 device code authentication flow to take over Microsoft 365 accounts.

    This is according to a new report by cybersecurity researchers Proofpoint. In a new paper published on December 18, researchers confirm that have seen a sharp escalation of social engineering attacks since September 2025, in which victims are tricked into granting access to their accounts.


    https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img