Dangerous Invitations: @volexity has published our #threatintel team’s findings on two new campaigns abusing Device Code & OAuth authentication workflows. Throughout 2025, Volexity has identified dozens of campaigns from state-sponsored threat actors abusing these workflows, showing no signs of slowing.
This blog post, details the creative social engineering tactics used by Russian threat actor UTA0355 in recent campaigns to impersonate European security events. Read the full blog post here: https://www.volexity.com/blog/2025/12/04/dangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks/






