The rise of device code phishing
bugcrowd.com | blog | #microsoft | #phishing | #red-team | #device-code | #oauth | #mfa-bypass | #token-theft
Summary
Device code phishing tricks victims into entering attacker-generated codes on legitimate login pages, yielding refresh tokens that bypass MFA for long-term access; this piece details the attack chain.
- Published
- Collected
Skip to content