[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:microsoft-takes-down-eviltokens-device-code-phishing-service-tied-to-12-000-inbo-muf2jny1":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"22e46142-509f-43ac-aa0c-fc6a5d75146d","Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises","microsoft-takes-down-eviltokens-device-code-phishing-service-tied-to-12-000-inbo-muf2jny1","Microsoft dismantled EvilTokens, an AI-powered device-code phishing service that compromised over 12,000 mailboxes by using chatbots to analyze inboxes and craft targeted impersonation attacks. Threat actors leveraged AI to identify trusted relationships within victim organizations and automate social engineering at scale. This represents a significant shift in phishing sophistication and inbox compromise methodology.","critical","advisory",[],[13,14,15,16],"OAuth 2.0 device authorization flow","Microsoft","Cloudflare","OpenAI","Hunt for device-code authentication flows in your environment. Review Azure AD sign-in logs for unusual device code grants, anomalous forwarding rules, and inbox delegation changes. Prioritize accounts showing inbox access from unexpected locations or devices in the past 90 days.",[19],"46001668-4e40-4f52-98d0-3fb8480bf015",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmicrosoft-takes-down-eviltokens-device.html","active","2026-09-26T05:05:46.859+00:00","2026-09-24T05:05:49.627956+00:00","2026-09-24T05:06:35.212509+00:00",[28],{"id":19,"title":6,"url":22}]