[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnIGsWYN2bwfhXJ9fhVXRa6FWkdHDmre8uTmh0Kt02Zw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"f4d56e87-47fd-4e99-831f-8f61bdfaa8b9","device-code-phishing-exploits-legitimate-authentication-flows","c998512b-e6ad-4398-9fd2-2f29786b5283","Device Code Phishing Exploits Legitimate Authentication Flows","The Tycoon 2FA phishing group has shifted tactics to exploit device code authentication, a legitimate Microsoft feature that allows users to sign in on devices without keyboards by entering a code on another device. Attackers trick victims into visiting malicious websites that display fake device authorization prompts, convincing users to enter the displayed code on their legitimate Microsoft accounts. This bypasses traditional 2FA protections because the authentication flow appears legitimate to both the user and Microsoft's systems. Organizations must educate users about this emerging threat and implement additional safeguards around device authorization processes.","**Immediate actions:**\n- Train employees to recognize and report suspicious device authorization requests\n- Review and audit recent device registrations across organizational accounts\n- Implement conditional access policies that restrict device registration to trusted locations\n\n**Long-term improvements:**\n- Deploy advanced email security solutions that detect device code phishing campaigns\n- Establish policies requiring IT approval for new device registrations\n- Implement zero-trust architecture that validates device integrity before granting access\n\n**Detection measures:**\n- Monitor authentication logs for unusual device registration patterns\n- Set up alerts for device code authentication attempts from unfamiliar locations\n- Implement user behavior analytics to detect anomalous account access patterns",[12,13,14,15,16],"CIS Control 6","CIS Control 14","NIST AC-2","NIST AC-19","NIST AT-2","published","2026-04-17T22:08:22.892481+00:00","2026-04-17T22:08:22.706+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Ftycoon-2fa-hackers-device-code-phishing","tycoon-2fa-phishers-scatter-adopt-device-code-phishing-3458ed","Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"cd36c298-054c-4a13-bc0e-75a419f703d7","2026-04-18","morning","ThreatNoir Weekend Brief — April 18","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-18\u002Fthreatnoir-morning-brief-2026-04-18.mp3"]