DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A sophisticated cyber attack is making headlines, with attackers exploiting a previously unknown vulnerability in Microsoft’s device-code flow to gain unauthorized access to Microsoft 365 (M365) accounts. Dubbed “DEBULL,” this tactic has been linked to an advanced threat actor that has successfully compromised multiple high-profile organizations. The DEBULL tooling leverages the device-code flow, a security … Read more