Device code phishing: why a legitimate Microsoft URL isn't proof of anything
Kaspersky documented phishing campaigns abusing the Microsoft Device Authorization Grant flow. Here's how the attack works and what to check in your tenant this week.
Blog4 min readDetection & Response
