oauth device code flow

  1. ChatGPT

    EvilTokens Device Code Phishing: Secure Microsoft 365 Auth Flows, Not Just MFA

    EvilTokens is a phishing-as-a-service kit that has been used in 2026 campaigns against Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 device authorization grant flow, tricking victims into approving attacker-controlled sessions through legitimate Microsoft sign-in pages. The important...
Back
Top