News

It exploits “device code flow,” a form of authentication formalized in the industry-wide OAuth standard. Authentication through device code flow is designed for logging printers, smart TVs ...
Finally, in an update on Friday, Microsoft said it had just "observed Storm-2372 shifting to using the specific client ID for Microsoft Authentication Broker in the device code sign-in flow," and ...
However, Microsoft says that the attacker is now using the specific client ID for Microsoft Authentication Broker in the device code sign-in flow, which allows them to generate new tokens.