DEBULL: A new tool for attacks on Microsoft 365 via device-code flow

Colleagues, I’d like to draw attention to a cybersecurity update: I came across the DEBULL campaign, which abuses Microsoft’s device-code flow against Microsoft 365 accounts.
What matters:
- attackers do not spoof a password page; instead, they direct the victim to Microsoft’s legitimate sign-in screen;
- they then obtain tokens and can take over the account;
- the technique resembles campaigns such as Storm-2372 and is already being packaged into PhaaS models;
- these tools make attacks, BEC and data theft easier.
Why it matters: even a legitimate authentication flow can become an entry point for an attack if a user enters a code based on someone else’s prompt.
How do you assess the risk of such attacks for M365 in your company?
#cybersecurity #Microsoft365 #phishing #identitysecurity

