The latest method causing trouble for security teams is that of device code phishing, a technique that tricks users into granting access to sensitive accounts without attackers needing to steal a ...
In order to protect against the specific attack vector used by Storm-2372, Microsoft recommends: Disabling device code flow wherever possible. Provide phishing training to all users. Revoke access ...