chiprook
← Security
SecuritySeptember 18, 2026, 22:16

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

eSentire researchers found the GhostCode phishing kit abusing Microsoft's legitimate OAuth device authorization flow to steal Microsoft 365 access tokens. The attack registers devices in Intune and obtains a Primary Refresh Token with a 14-day lifetime, enabling persistent access.

GhostCode attackers abuse device codes to take over Microsoft 365 accounts
#Microsoft#Microsoft365#ESentire#Intune
Read next
Security

Plugin4Shell: one git trick bypassed safety locks on four AI coding agents

Security

Tetragon in AWS CodeBuild blocks npm postinstall network access

Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts