A newly observed device-code phishing operation, tracked as GhostCode, abuses Microsoft Entra device enrollment to preserve attacker access even after compromised tokens are revoked. The campaign begins with business-focused social engineering rather than a conventional credential-harvesting page. Attackers reportedly posed as procurement representatives from legitimate organizations, including BJ’s Wholesale Club, and initiated seemingly legitimate inquiries through Salesforce contact forms. After establishing communication, they introduced an NDA-signing workflow and delivered a password-protected HTML attachment through WeTransfer. The attachment impersonates a FlipBook document portal and incorporates multiple evasion mechanisms, including large volumes of junk data, HTML comments inserted between visible characters, and AES-256-GCM encryption that conceals the phishing destination until the victim supplies the required password. Once opened, the attachment decrypts and redirects the victim through several anti-analysis controls, including JavaScript filtering, Cloudflare Turnstile, GeoIP validation, and user-agent checks. The final page directs the victim to Microsoft’s genuine device-code authentication service, where they enter an attacker-provided code and complete their normal sign-in process, including MFA. GhostCode abuses the OAuth 2.0 device authorization flow, meaning the resulting authentication is legitimate from Microsoft’s perspective. Following successful authorization, the attackers reportedly retained the device-code session and polled for completion before redirecting the victim to a convincing NDA document. The observed activity also involved Microsoft Authentication Broker application identifiers, Microsoft Graph permissions, and offline_access. The most significant risk occurs after authentication. According to eSentire’s Threat Response Unit, attackers began interacting with Intune Enrollment, Device Registration Service, Windows Azure Active Directory, and Microsoft Graph within seconds of successful authorization. In one observed case, three Entra devices were registered within 78 seconds, followed by acquisition of a Primary Refresh Token (PRT). Because rogue device-enrollment records can remain after session or refresh-token revocation, simply invalidating tokens may not eliminate the attacker’s persistence. Organizations responding to suspected device-code phishing should therefore investigate and remove unauthorized device registrations, review Entra and Intune audit activity, and examine unusual deviceCode authentication and Graph activity. Where device-code authentication is not required, Microsoft recommends restricting the flow through Conditional Access, using report-only testing before enforcing tightly controlled exceptions.
A critical pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited against unpatched deployments. The flaw affec...
cPanel has addressed CVE-2026-68490, a permissions-related security weakness in its CalDAV and CardDAV services. The issue can expose calendar entries and contact information belon...
RemControl is a newly identified Android malware threat targeting users of more than 30 banking and financial applications. The malware is distributed through deceptive websites an...