security1 publisher
eSentire finds GhostCode phishing Microsoft device codes through web contact forms
eSentire's Threat Response Unit says the GhostCode kit abuses Microsoft's OAuth 2.0 device authorization grant, and the lure reached targets in late August 2026 as a procurement inquiry filed through a company's own web form.
Publishers:esentire.com
Reality
- Evidence48
- Adoption32
- Hype gap+20
- Incentives78
- Confidence45