A novel phishing campaign utilizes a specialized tool named DEBULL to compromise Microsoft 365 accounts by abusing the legitimate device code authentication flow. This method bypasses traditional credential harvesting by tricking users into entering a malicious code directly into the official Microsoft login portal. Attackers distribute these threats through collaboration-themed lures that appear as legitimate document sharing or meeting invitations. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!