EvilTokens: A phishing attack that doesn’t steal your password (opens in new tab)
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages.
Read the original article