Post #4370741
2026-08-04 09:01 UTC
Device-code phishing rose ~1,500% in 2026. It steals Microsoft 365 tokens after you sign in, so MFA and passkeys do not stop it.
Hits Entra ID tenants.
Fix: block the device-code flow in Conditional Access, alert on every use.
https://suriq.io/blog/device-code-phishing-microsoft-365-token-theft
#Detection #Phishing #infosec #cybersecurity
Replies (0)
No replies.