Corti.com

Welcome to corti.com, home of a collection of thoughts by Sascha Corti.

EvilTokens: An AI-Driven Device Code Attack Compromising Microsoft Businesses

EvilTokens: An AI-Driven Device Code Attack Compromising Microsoft Businesses

A new class of identity attacks is rapidly scaling across enterprises: AI-augmented device code phishing, operationalized through phishing-as-a-service (PhaaS) platforms like EvilTokens. Microsoft and multiple security vendors have confirmed that these attacks are now widespread and highly effective, compromising organizations daily by abusing legitimate authentication flows rather than exploiting vulnerabilities.
3 min read