Microsoft Device Code Phishing Attacks Target Organizations
Threat actors are targeting technology, manufacturing, and financial organizations using device code phishing and voice phishing (vishing) attacks to compromise Microsoft Entra accounts. Unlike previous attacks that used malicious OAuth applications, these campaigns leverage legitimate Microsoft OAuth client IDs and the device authorization flow to trick victims into authenticating. This allows attackers to access victim’s … Read more