Monday 13 July 2026 01:39:12 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#device code phishing


Forg365 Turns Microsoft 365 Phishing Into a Bought-and-Sold Access Business

Published: 10 July 2026 18:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A Telegram-linked phishing service shows how identity theft now borrows the mechanics of SaaS, combining device-code abuse, token persistence, and AI-written lures.

When the Login Box Becomes the Breach: Device-Code Phishing and MFA Persistence

Published: 09 July 2026 08:05Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.

Microsoft’s Device Code Flow Is Becoming a Rental Service for Account Takeovers

Published: 08 July 2026 18:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A late-June phishing run against Microsoft 365 shows how attackers are industrializing a legitimate sign-in method, turning trusted authentication into a reusable identity-abuse chain.

When the Login Page Is Real: The Device-Code Phishing Playbook Targeting Microsoft Accounts

Published: 06 July 2026 19:14Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A legitimate Microsoft sign-in path built for low-input devices is being repurposed as a phishing lure, shifting the attack from password theft to trusted-session abuse.

Real Microsoft Sign-Ins, Fake Trust: How PDF Lures Are Steering Victims Into Device Code Phishing

Published: 06 July 2026 14:32Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing campaign is blending password-protected PDFs with Microsoft’s legitimate device-code login flow, a reminder that attackers do not always need fake pages when they can abuse the real ones.

When Microsoft Sign-In Becomes the Trap: ARToken and the New Token-Theft Playbook

Published: 02 July 2026 14:48Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit tied to Microsoft 365 targeting shows how attackers can lean on legitimate cloud login flows, trusted collaboration branding, and edge-hosted delivery to turn identity into the attack surface.

The ARToken Panel Shows How Phishing Became a Token Factory

Published: 02 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.

The Quiet MFA Bypass Hiding Inside a Legitimate Login Flow

Published: 19 June 2026 16:30Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A webinar on MFA bypass underscores a harder truth for defenders: the sharpest phishing campaigns now abuse valid authentication paths, then rely on behavioral detection to catch the fallout.

When the Login Page Is Real: The Quiet Power of Device Code Phishing

Published: 16 June 2026 12:48Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing campaign aimed at Microsoft 365 users shows how attackers can abuse a legitimate OAuth flow instead of building a fake login page.

The Real Login Trap: How Device Code Prompts Can Turn Microsoft 365 Into a Token Prize

Published: 16 June 2026 12:20Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A legitimate Microsoft sign-in path can be twisted into an authorization relay, letting an attacker win access after the victim approves the wrong device.

When a Real Microsoft Login Becomes the Trap

Published: 25 May 2026 18:36Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing service built around OAuth device code flow shows how attackers can turn a legitimate sign-in path into token theft, session hijacking, and MFA bypass.

When the Password Is Not the Prize: The Microsoft 365 Token Grab Hidden Inside Kali365

Published: 22 May 2026 12:29Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing kit linked to Telegram distribution is pushing attackers toward session theft, turning a successful sign-in into a longer-lived foothold inside cloud accounts.

Code on the Screen, Control in the Attacker’s Hands

Published: 21 May 2026 06:14Category: Security Awareness & Social EngineeringGeo: Oceania / AustraliaAuthor: PATCHKNIGHT

A legitimate Microsoft sign-in flow is being repurposed as a phishing lure, and Australian guidance now treats that abuse as a real identity risk rather than a curiosity.

When a Legitimate Login Becomes the Trap: Device-Code Phishing Targets Microsoft 365

Published: 15 May 2026 19:47Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Attackers are abusing a real OAuth sign-in path to turn user cooperation into token theft, shifting the fight from passwords to the identity layer itself.

The Login That Looked Legit: How Device Code Phishing Turns Microsoft 365 Into a Token Trap

Published: 15 May 2026 12:38Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

Attackers are abusing a standard cross-device sign-in path to steal Microsoft 365 tokens, sidestep ordinary MFA expectations, and turn a trusted identity workflow into a foothold for mailbox abuse.