Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike@social.raytec.co.
Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts:
-cyberhunter_nl
-tr2222200
-tr1sa111
-bluenumberone
-dekarituraj
-feisty-swim1410
If they become overwhelming or repetitive I will gladly accept suggestions to remove any.
A little bot maintained by @mike@social.raytec.co to post the latest pulses from Open Threat Exchange.
Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted.
Unaffiliated with OTX or AlienVault
WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it.
Posts
Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault
Abusing OAuth Device Code Flow
In early 2026, phishing attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's OAuth 2.0 Device Authorization Grant (Device Code Flow) to compromise user accounts. Attackers use phishing emails containing Mailchimp's Mandrill service links to bypass security controls, leading victims to fake Adobe-themed websites. The sites abuse legitimate Microsoft authentication mechanisms to obtain access and refresh tokens, granting persistent delegated access to critical resources like Graph API, Teams, Outlook, and SharePoint. The technique leverages shared client IDs across tenants and family of client IDs (FOCI) for lateral movement. Two variants exist: one using external phishing infrastructure with dynamic code generation, and another relying solely on fake meeting invitations containing pre-generated device codes. The attack is particularly effective as it uses legitimate Microsoft services, making detection challenging.
Pulse ID: 69e68ccac96ab3f866763f12
Pulse Link: https://otx.alienvault.com/pulse/69e68ccac96ab3f866763f12
Pulse Author: AlienVault
Created: 2026-04-20 20:30:02
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #CyberSecurity #Email #InfoSec #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #RCE #SMS #bot #AlienVault