An active campaign in which attackers are abusing Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow to take over Microsoft 365 accounts. Rather than capturing credentials with a fake login page, the threat actors persuade victims to complete a genuine Microsoft authentication process that, unbeknownst to them, authorizes an attacker-controlled “device.” The result: fully […]
The post Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior
State-linked influence operations from Russia and China have entered a new and more dangerous phase. Rather than overwhelming social media with floods of low-quality posts,


