VMTech
Discuss a project

DEBULL: A new tool for attacks on Microsoft 365 via device-code flow

DEBULL: A new tool for attacks on Microsoft 365 via device-code flow

Colleagues, I’d like to draw attention to a cybersecurity update: I came across the DEBULL campaign, which abuses Microsoft’s device-code flow against Microsoft 365 accounts.

What matters:
- attackers do not spoof a password page; instead, they direct the victim to Microsoft’s legitimate sign-in screen;
- they then obtain tokens and can take over the account;
- the technique resembles campaigns such as Storm-2372 and is already being packaged into PhaaS models;
- these tools make attacks, BEC and data theft easier.

Why it matters: even a legitimate authentication flow can become an entry point for an attack if a user enters a code based on someone else’s prompt.

How do you assess the risk of such attacks for M365 in your company?

#cybersecurity #Microsoft365 #phishing #identitysecurity

Open analytics
On the site 1 views
min read 1 07.07.2026
On Instagram 5 views
On Instagram 1 reach
Instagram

DEBULL: A new tool for attacks on Microsoft 365 via device-code flow

Open the post on Instagram ↗