Abusing OAuth Device Code Flow

Reported 20 Apr 2026 by otx · Severity: medium

In early 2026, phishing attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's OAuth 2.0 Device Authorization Grant (Device Code Flow) to compromise user accounts. Attackers use phishing emails containing Mailc