Cybersecurity researchers have uncovered a sophisticated threat actor exploiting a previously unknown vulnerability in Microsoft’s device-code flow, which allows attackers to gain unauthorized access to Microsoft 365 (M365) accounts. The technique, dubbed “DEBULL Tooling,” has been used to target high-profile organizations and individuals worldwide.
At its core, the attack relies on manipulating the device-code flow, a security feature designed to prevent phishing attacks by sending unique codes to users’ devices via SMS or email. Normally, when a user attempts to sign in to their M365 account from an unfamiliar device, Microsoft sends a code to their registered phone number or email address. If the correct code is entered within a certain timeframe, access is granted.
However, the DEBULL Tooling exploit has found a way to bypass this security measure by sending multiple fake codes to a victim’s device in rapid succession. The attacker uses AI-powered tools to analyze the device-code flow and determine the exact timing required to intercept the correct code before it can be entered by the intended user.
This technique allows attackers to gain unauthorized access to M365 accounts, potentially leading to data breaches, identity theft, or even lateral movement within an organization’s network. The researchers warn that the threat actor behind DEBULL Tooling has been actively targeting high-profile organizations and individuals in various industries, including finance, healthcare, and government.
The sophistication of this attack is a stark reminder of the evolving nature of cyber threats. As AI-powered tools become increasingly prevalent in cybersecurity, attackers are adapting their tactics to stay ahead of the curve. The DEBULL Tooling exploit highlights the need for organizations to remain vigilant and adapt their security measures accordingly.
In particular, M365 administrators should be aware of this vulnerability and take immediate action to mitigate its effects. This may involve implementing additional security controls, such as multi-factor authentication or device-based access policies. It is also essential that users are educated on the risks associated with phishing attacks and the importance of being cautious when receiving unsolicited SMS or email codes.
Ultimately, the DEBULL Tooling exploit serves as a warning to organizations and individuals alike: as AI-powered threats continue to evolve, so too must our defenses. By staying informed about emerging threats and adapting our security measures accordingly, we can better protect ourselves against the ever-changing landscape of cyber attacks.
Source: The Hacker News — 2026-07-07