EvilTokens: A phishing attack that doesn’t steal your password

Wait 5 sec.

A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages