DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

July 7, 2026 1 Min Read 0

Threat Intelligence Brief

Threat Risk: High

Victim: Microsoft 365 users

Incident: Phishing campaign leveraging DEBULL tooling to abuse Microsoft's device-code authentication flow.

Impact: Full account takeover and MFA bypass, potentially leading to BEC or ransomware.

Attacker: Storm-2372

Analysis: The key concern for Microsoft 365 users is the potential follow-on impact — Full account takeover and MFA bypass, potentially leading to BEC or ransomware. Treat this as a high-priority item and validate the source details, exposure scope, and required defensive actions. Reported attribution to Storm-2372 increases the need to validate exposure and related indicators.

Recommendations:

  • Apply vendor patches Review exposed systems Monitor for exploitation indicators

Source: thehackernews.com

View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *