You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
token theft
About this tag
Token theft is a growing cybersecurity threat that targets authentication tokens rather than passwords, often bypassing multifactor authentication (MFA). On WindowsForum, discussions cover attacks like Kali365, which abuses Microsoft's device-code authentication flow to capture OAuth tokens, and the FlagLeft bug in Microsoft 365 Android apps that allowed token theft from trusted apps. Other threads detail Russian state-sponsored campaigns using token theft via Outlook vulnerabilities, cloud attack techniques stealing Microsoft Entra refresh tokens, and the Storm-237 device-code phishing campaign. Microsoft's introduction of Administrator Protection in Windows 11 aims to defend against token-theft attacks. These posts emphasize that token theft exploits legitimate authentication workflows, making it a critical concern for IT professionals and enterprise security.
The FBI’s Internet Crime Complaint Center warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords...
Microsoft patched a production coding error in several Microsoft 365 Android apps after Enclave researchers said malicious apps on the same device could silently obtain account tokens and impersonate signed-in users. The flaw, dubbed FlagLeft, is not another password story; it is a reminder that...
The FBI issued a May 21, 2026 public warning that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 accounts by abusing device-code authentication to capture OAuth tokens and bypass multi-factor authentication. That makes this less a story about one new phishing kit than...
Russian state-sponsored hacking campaigns have once again made international headlines, following the UK’s public attribution of a newly discovered malware strain—nicknamed “Authentic Antics”—to the infamous APT28 group, also known as Fancy Bear or Forest Blizzard. This revelation not only draws...
A new development in the realm of cloud security threats has emerged, offering threat actors a novel way to obtain Microsoft Entra (formerly Azure Active Directory) refresh tokens from compromised endpoints, potentially bypassing even robust multi-factor authentication (MFA) mechanisms. This...
In a twist that plays on the duality of trust and technology, threat actors are now leveraging a legitimate Microsoft feature to infiltrate Microsoft 365 (M365) accounts. This isn't your everyday phishing scam—with no suspicious attachments or shady links—but a sophisticated manipulation of the...
In a twist straight out of a cyber espionage thriller, threat actors—potentially linked to Russian interests—have been abusing Microsoft’s device code authentication flow to hijack Microsoft 365 accounts. This sophisticated phishing campaign, tracked by Microsoft’s threat intelligence team as...
Microsoft has announced a crucial advancement in systems security for Windows 11, introducing the "Administrator Protection" feature that promises to tighten defenses against unauthorized system changes and token-theft attacks. With this announcement, Microsoft has doubled down on implementing a...
In an era where cybersecurity threats evolve at an unprecedented pace, organizations must remain vigilant in safeguarding their digital assets. Recognizing this critical need, Microsoft has introduced a groundbreaking security feature within its Entra suite: Token Theft Protection. Announced on...