threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal user accounts. This evolution reflects a broader trend in PhaaS platforms expanding beyond simple c… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 Device code phishing, a rapidly growing threat exploiting the OAuth 2.0 device authorization grant, has evolved from a niche technique to a widespread criminal and nation-state tactic in a matter of months. Attackers are… The Hacker News · Jul 31, 2026 High device-code-phishingoath2phishing-as-a-service
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft