Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
…contains 230 vendor names and is constantly updated. eSentire recommends disabling the OAuth device code flow when not needed, restricting OAuth consent permissions, requiring admin approval for third-party apps, enabling Continuous…
