
Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts
Hackers are increasingly abusing Microsoft’s legitimate device code flow to bypass multi-factor authentication (MFA) and hijack Microsoft 365 accounts, turning trusted identity controls into a covert account takeover vector. This article explains how the attack works, why it reliably bypasses MFA, and what defenders can do to detect and block it. The OAuth 2.0 Device […]
The post Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts appeared first on Cyber Security News.