Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft 365 device-code phishing defenses for OAuth token abuse

Defensive Guidance
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

Defenders are tightening Microsoft 365 protections against device code phishing and vishing, a technique that can hand attackers valid OAuth tokens for Microsoft Entra accounts. The guidance focuses on blocking malicious infrastructure, revoking suspicious app consents, and watching for device code authentication events before token reuse can spread across connected services.

Related Happenings

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Microsoft Azure CLI password-spray campaign using ROPC

Campaign
H score24 First: 01.07.2026 08:46 Last: 01.07.2026 08:46 Sources 1

About this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...

Microsoft AiTM payroll pirate attack mitigation

Advisory/Mitigation
H score34 First: 10.04.2026 14:56 Last: 10.04.2026 14:56 Sources 1

About this happening: Microsoft is urging defenders to harden Microsoft 365 and related HR workflows against AiTM-driven payroll theft by requiring phishing-resistant MFA, blocking...

Timeline

  1. 19.02.2026 14:30 2 articles · 4mo ago

    Microsoft 365 defenses against device code phishing

    Mitigation Patch Update

    KnowBe4 Threat Labs guidance focuses on hardening Microsoft 365 against device code phishing and vishing that abuse the OAuth 2.0 Device Authorization flow to obtain valid authentication tokens for Microsoft Entra accounts. Recommended controls include blocking malicious domains and sender addresses, auditing and revoking suspicious OAuth app consents, reviewing Azure AD sign-in logs for device code authentication events, turning off the device code flow option when it is not required, and enforcing conditional access policies; the same reporting context notes a campaign first spotted in December 2025 and a Microsoft Threat Intelligence Center warning from February 2025 about device code phishing.

    Show sources