In a twist straight out of a cyber espionage thriller, threat actors—potentially linked to Russian interests—have been abusing Microsoft’s device code authentication flow to hijack Microsoft 365 accounts. This sophisticated phishing campaign, tracked by Microsoft’s threat intelligence team as "Storm-237," targets individuals working in high-stakes sectors like government, defense, telecommunications, health, energy, and beyond across Europe, North America, Africa, and the Middle East. Today...