The Telegram-distributed service combines AI-assisted lures with device-code phishing and attacker-side session refresh, complicating containment after an account is breached.
Windows Report on MSN
Hackers hijack hotel Wi-Fi to steal Microsoft 365 accounts
Hackers are changing hotel Wi-Fi DNS settings to redirect travelers to fake Microsoft 365 login pages and steal account ...
New Jalisco and OmegaLord phishing kits target Microsoft 365 accounts by abusing device code flows, OAuth tokens, and MFA prompts to maintain access.
The FBI warned that Kali365 can hijack Microsoft 365 accounts by abusing device code authentication and capturing OAuth tokens. A new phishing service is turning a legitimate Microsoft login process ...
Hotel Wi-Fi hack targeting Microsoft 365 accounts has turned captive portal gateways at hotels and conference centers in the ...
A new phishing-as-a-service (PhaaS) campaign is abusing Microsoft’s device code authentication flow to gain unauthorized access to user accounts. Sekoia researchers first spotted the toolkit ...
In February 2025, the Microsoft Threat Intelligence Center warned that Russian hackers were targeting Microsoft 365 accounts using device code phishing. In December, ProofPoint reported similar ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results