DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
TWINLOOT authenticates to an attacker's Azure tenant and uses the Graph API to interact with SharePoint drives for command and control.