[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Device-Code Phishing

newsHIGH 8.0

GhostCode Phishing Kit Abuses Microsoft OAuth Device Authorization Flow

A new phishing kit, GhostCode, is being used to trick Microsoft 365 users into handing over access to their accounts by exploiting a weakness in Microsoft's OAuth 2.0 device authorization grant flow. This campaign, identified in late August 2026, uses social-engineering tactics to convince victims to enter a device code on Microsoft's authentication page, allowing attackers to obtain authentication tokens and establish persistence in the victim's Microsoft environment. Security professionals should be aware of this threat and take steps to mitigate it.

Sep 19, 20261 source