Cozy Bear didn’t “hack Cloudflare.” They hacked your faith in the device-code box. After last year’s .rdp phish, they pivoted to watering holes that spoofed Microsoft auth—until the big clouds finally tag-teamed the takedown. 🔐
Two fast tells: weird spikes in device-code grants and sudden enterprise app consents from odd ASNs. If users can still one-click “Approve,” you’re basically gift-wrapping tokens. It’s 2025—why are we still debating phishing-resistant MFA?
What breaks this at your org—locking down device-code flows, FIDO2 for admins, or admin-only consent? Which one ships this sprint?
Read the breakdown (and steal the detections) 👉 https://blog.alphahunt.io/russian-apts-oauth-abuse-rdp-phish-and-takedowns
Subscribe for the full forecast—before the next lure drops.
Read, then subscribe for the full detection set and IR checklist. #AlphaHunt #CyberSecurity #ThreatIntelligence #APT29