HUGE AI-powered Microsoft Account phishing campaign

HUGE AI-powered Microsoft Account phishing campaign

Source: YouTube · John Hammond · published Apr 9, 2026 · 15:02

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Device code phishing is a technique cybercriminals use to compromise Azure and Microsoft 365 accounts by exploiting Microsoft's legitimate device code authentication process 0:00-0:10.

Key Takeaways:
• Device code authentication works similarly to TV sign-ins where users enter a code to authenticate a device 0:17-0:28
• Microsoft's implementation of this feature is described as extremely over permissive, creating security risks 0:37-0:42
• This method bypasses certain security measures, making it particularly dangerous for organizations 0:44-0:46

Understanding this attack vector is crucial for securing Microsoft cloud environments against sophisticated phishing attempts.

Sources:

  • 0:00-0:10 Explanation of device code phishing technique
  • 0:17-0:28 Device authentication process explained
  • 0:37-0:42 Microsoft's over permissive implementation
  • 0:44-0:46 Security bypass concerns

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

One of the ways that cyber-criminals steal your Azure Microsoft 365 accounts or take over and compromise your Entra ID identities is with the technique called device code fishing. And this technique takes advantage of a genuine legitimate sign-in process, device code authentication. You can think of it like you're trying to sign in to Netflix on your TV. All you have is your remote, so they give you some random string of letters and numbers, a code, to authenticate that device. And for some reason, Microsoft has support for this, not that you'd ever log in to Outlook or Teams or SharePoint on your TV, but it allows a full sign-in and it is extremely over permissive. And we've covered the device code fish plenty of times on this channel. The most sinister part is that it basically bypasses,…