DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
Cybersecurity researchers have uncovered a sophisticated threat actor exploiting a previously unknown vulnerability in Microsoft’s device-code flow, which allows attackers to gain unauthorized access to Microsoft 365 (M365) accounts. The technique, dubbed “DEBULL Tooling,” has been used to target high-profile organizations and individuals worldwide. At its core, the attack relies on manipulating the device-code flow, … Read more