Topic: device authorization flow
-
Microsoft Entra Accounts Targeted in Vishing Attacks
A new wave of attacks combines device code phishing with voice phishing (vishing) to compromise Microsoft Entra accounts, exploiting the legitimate OAuth 2.0 device authorization flow to steal authentication tokens without traditional password theft. The **ShinyHunters** extortion group is believ...
Read More » -
Device Code Phishing Attacks Jump 37x with New Kits
A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for hardware to hijack accounts and bypass multi-factor authentication. The primary driver is the EvilTokens phishing-as-a-service kit, with at least 11 distinct kits now a...
Read More »