1 article
Device code phishing steals OAuth tokens after the victim passes MFA. Learn how the attack works and the Entra log signals that expose it.
Astrid LindqvistAug 17, 202611 min read