leadership1 publisher
Revoking the stolen tokens left GhostCode's Intune device inside the tenant
eSentire says a phishing kit called GhostCode used Microsoft's device-code flow to register three devices within 77 seconds of a victim completing MFA, and one of them stayed enrolled in Intune until it was explicitly removed.
Publishers:csoonline.com
Reality
- Evidence58
- Adoption30
- Hype gap+12
- Incentives60
- Confidence55