<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Token-Theft on CuraSec</title><link>https://curasec.metacog.co.kr/tags/token-theft/</link><description>Recent content in Token-Theft on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/token-theft/index.xml" rel="self" type="application/rss+xml"/><item><title>Kali365 Abuses Microsoft Device Code Flow to Steal OAuth Tokens</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-kali365-weaponizes-microsoft-authentication-against-us-compa/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-kali365-weaponizes-microsoft-authentication-against-us-compa/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code flow phishing is a real and growing vector for M365/Azure tenants; audit Conditional Access policies to block or restrict device code flow for user accounts that don&amp;rsquo;t require it, and enforce compliant-device requirements where the flow must remain enabled.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections on Entra ID sign-in logs for device code authorization events originating from unexpected locations or apps; also hunt for refresh token reuse anomalies that may indicate post-phishing lateral movement within M365.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A named actor targeting US M365 tenants via Microsoft&amp;rsquo;s own authentication UI is useful context for the risk register and customer security questionnaire responses, but no confirmed breaches or near-term regulatory deadlines make this a monitor-and-track item rather than an executive action.&lt;/li>
&lt;/ul></description></item></channel></rss>