
NewsMicrosoft 365
DEBULL Tooling Abuses Microsoft Device-Code Flow to Hijack M365 Accounts
Researchers at ZeroBEC say a Microsoft 365 device code phishing campaign observed from late June into early July 2026 used collaboration-themed lures and a reusable tooling layer dubbed DEBULL to hijack accounts without stealing passwords or defeating MFA directly. The activity shares strong overlaps with Microsoft's Storm-2372 tradecraft.
