A sophisticated cyber attack is making headlines, with attackers exploiting a previously unknown vulnerability in Microsoft’s device-code flow to gain unauthorized access to Microsoft 365 (M365) accounts. Dubbed “DEBULL,” this tactic has been linked to an advanced threat actor that has successfully compromised multiple high-profile organizations.
The DEBULL tooling leverages the device-code flow, a security feature designed by Microsoft to enable users to sign in to their M365 accounts without sharing their passwords. When enabled, the device-code flow generates a one-time password (OTP) that is sent to the user’s registered devices. To bypass this security measure, attackers have developed an exploit that manipulates the OTP generation process. This allows them to obtain the authentication token and subsequently access the targeted account.
The implications are significant: M365 accounts compromised through this tactic can provide attackers with sensitive information, including email communications, calendar events, and access to shared files and resources. Moreover, the DEBULL tooling has been observed to be highly adaptable, capable of evading traditional security measures such as signature-based detection and anti-virus software.
It is worth noting that the device-code flow vulnerability exploited by DEBULL was not a zero-day exploit, implying that Microsoft had previously patched this issue. However, it appears that some organizations may have failed to apply these patches or may be using outdated versions of Microsoft’s software. This highlights the importance of maintaining up-to-date security protocols and ensuring that all software is regularly updated.
The discovery of DEBULL has sparked renewed debate about the role of AI in cybersecurity. As AI-powered tools become increasingly sophisticated, they also pose a growing threat to organizations that fail to stay ahead of emerging attacks. The key takeaway from this incident is not only the importance of patching vulnerabilities but also the need for robust security protocols and regular updates to protect against advanced threats.
As we move forward in an increasingly complex cybersecurity landscape, it’s essential to prioritize proactive measures such as vulnerability scanning, penetration testing, and employee education to prevent similar attacks.
Source: The Hacker News — 2026-07-07