ended6월 2일· 1 sources

OAuth's Overlooked Weakness: Device Code Flow Emerging as Phishing Weapon of Choice

OAuth의 간과된 약점: Device Code Flow가 피싱 공격의 주요 무기로 부상

Why it matters

Device code flow, originally designed for IoT and CLI tools lacking browser interfaces, has become a critical phishing vector—particularly through commercial platforms like Kali365 that enable even unskilled attackers to scale credential-less attacks. Many organizations unknowingly leave this authentication path enabled, unnecessarily expanding their attack surface and OAuth security risks. Restricting device code flow via Conditional Access policies is now essential to protect Microsoft 365 and other OAuth-dependent environments from this growing threat.

1
Sources
+0
24h
Growth
102d
Active
Device Code FlowOAuthPhishingKali365Conditional Access

Sources

Related Issues