A novel phishing campaign utilizes a specialized tool named DEBULL to compromise Microsoft 365 accounts by abusing the legitimate device code authentication flow. This method bypasses traditional credential harvesting by tricking users into entering a malicious code directly into the official Microsoft login portal. Attackers distribute these threats through collaboration-themed lures that appear as legitimate document sharing or meeting invitations. Source
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!