A legitimate Microsoft sign-in path is being treated as an attack surface, where user approval can hand an adversary a valid session without breaking the protocol itself.
A subscription-style phishing kit called Forg365 shows how device-code abuse, session theft, and mailbox persistence are being packaged into a ready-made identity attack against Microsoft 365 users.
A long-running device-code campaign shows how attackers can abuse a legitimate Microsoft authentication flow to harvest access without breaking in the usual way.
A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.
Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.
A late-June phishing run against Microsoft 365 shows how attackers are industrializing a legitimate sign-in method, turning trusted authentication into a reusable identity-abuse chain.
A legitimate Microsoft sign-in path built for low-input devices is being repurposed as a phishing lure, shifting the attack from password theft to trusted-session abuse.
A phishing campaign is blending password-protected PDFs with Microsoft’s legitimate device-code login flow, a reminder that attackers do not always need fake pages when they can abuse the real ones.
A phishing kit tied to Microsoft 365 targeting shows how attackers can lean on legitimate cloud login flows, trusted collaboration branding, and edge-hosted delivery to turn identity into the attack surface.
A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.
A webinar on MFA bypass underscores a harder truth for defenders: the sharpest phishing campaigns now abuse valid authentication paths, then rely on behavioral detection to catch the fallout.
A phishing campaign aimed at Microsoft 365 users shows how attackers can abuse a legitimate OAuth flow instead of building a fake login page.
A legitimate Microsoft sign-in path can be twisted into an authorization relay, letting an attacker win access after the victim approves the wrong device.
A phishing service built around OAuth device code flow shows how attackers can turn a legitimate sign-in path into token theft, session hijacking, and MFA bypass.
A phishing kit linked to Telegram distribution is pushing attackers toward session theft, turning a successful sign-in into a longer-lived foothold inside cloud accounts.
A legitimate Microsoft sign-in flow is being repurposed as a phishing lure, and Australian guidance now treats that abuse as a real identity risk rather than a curiosity.
Attackers are abusing a real OAuth sign-in path to turn user cooperation into token theft, shifting the fight from passwords to the identity layer itself.
Attackers are abusing a standard cross-device sign-in path to steal Microsoft 365 tokens, sidestep ordinary MFA expectations, and turn a trusted identity workflow into a foothold for mailbox abuse.