Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNK_AcademicFlare Microsoft 365 device code phishing campaign

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The UNK_AcademicFlare phishing campaign is actively stealing Microsoft 365 credentials through device code authentication abuse, creating account takeover risk for organizations across government, think tanks, higher education, and transportation in the U.S. and Europe. The operation has been active since September 2025 and uses trust-building outreach from compromised email accounts. It matters because the same login flow can yield valid access tokens that let operators take over accounts without needing a password reset. The campaign shows how a low-friction phishing method can be reused at scale against sensitive organizations.

Related Happenings

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Pink new extortion brand within The Com

Threat Actor Meta
H score31 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...

UNK_MassTraction Roundcube university exploitation campaign

Campaign
H score41 First: 07.07.2026 12:10 Last: 07.07.2026 12:10 Sources 1

About this happening: The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...

Microsoft Azure CLI password-spray campaign using ROPC

Campaign
H score24 First: 01.07.2026 08:46 Last: 01.07.2026 08:46 Sources 1

About this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...

Timeline

  1. 19.12.2025 19:54 2 articles · 6mo ago

    UNK_AcademicFlare device code phishing disclosure

    Initial Disclosure

    Proofpoint attributed the UNK_AcademicFlare phishing campaign to a suspected Russia-aligned group using device code authentication workflows to steal Microsoft 365 credentials and take over accounts at government, think tank, higher education, and transportation targets in the U.S. and Europe. The campaign used compromised email addresses to build rapport, sent victims to a Cloudflare Worker page that mimicked Microsoft OneDrive, and redirected them to the legitimate Microsoft device code login URL so entered codes could generate access tokens for account takeover. Defenders were advised to block device code flow with a Conditional Access policy using the Authentication Flows condition, or restrict the flow to approved users, operating systems, or IP ranges.

    Show sources