Preview image for a blog post

Midnight Blizzard's Evolving Threat: Hijacking Captive Portals for Token Exfiltration

Midnight Blizzard (Storm-2945) exploits hotel captive portals with fake updates to steal sensitive user tokens.
Preview image for a blog post

M365 MFA Bypass: Deconstructing the OAuth 2.0 Device Code Phishing Campaign

Deep dive into a sophisticated phishing campaign abusing OAuth 2.0 Device Authorization Grant flow to bypass M365 MFA and steal tokens for persistent access.