Technology ❯ Cybersecurity ❯ Phishing ❯ Scams
The kit lures victims to enter a device code on a genuine Microsoft sign‑in page, which gives attackers reusable OAuth tokens that grant ongoing access to email and files.