
TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2
authenticationcloud-securityidentity-access-management+3
453

A fork of the great TokenTactics with support for CAE and token endpoint v2

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…