Device code phishing has emerged as a particularly sophisticated attack vector, with threat actors using tools like TokenTactics to intercept Microsoft 365 tokens and gain unauthorized access to ...
Crucially, this account “did not have multifactor authentication (MFA) enabled,” Microsoft said in the post. While stopping short of acknowledging that the hack was enabled by an oversight ...