Hackers target Microsoft Entra accounts in device code vishing attacks
Hackers target Microsoft Entra accounts in device code vishing attacks
#Microsoftentra
https://opr.news/240b1b51260219en_us?link=1&client=ex_global
Download Now
https://opr.as/share

Hackers target Microsoft Entra accounts in device code vishing attacks
Threat actors are targeting technology, manufacturing, and financial organizations in campaigns that combine device code phishing and voice phishing (vishing) to abuse the OAuth 2.0 Device Authorization flow and compromise Microsoft Entra accounts. Unlike previous attacks that utilized malicious OAuth applications to compromise accounts, these campaigns instead leverage legitimate Microsoft OAuth client IDs and the device authorization flow to trick victims into authenticating.