threat-intel Curiouser and Curiouser Cisco Talos has identified "JWR", a new phishing framework and variant of "The Outsider" as a service, used to steal payment data, 2FA codes, and device fingerprints via SMS lures impersonating regional authorities. The framework is operator-driven in real-time, allowing attackers to bypass MFA by prompting for 2FA cod… Cisco Talos · Aug 13, 2026 High phishingsmsmfa
threat-intel 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 Device code phishing, a rapidly growing threat exploiting the OAuth 2.0 device authorization grant, has evolved from a niche technique to a widespread criminal and nation-state tactic in a matter of months. Attackers are… The Hacker News · Jul 31, 2026 High device-code-phishingoath2phishing-as-a-service
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
phishing INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator INTERPOL, in collaboration with authorities across 13 MENA countries, successfully dismantled the decade-long Sniper Dz phishing-as-a-service (PhaaS) platform, resulting in the arrest of its administrator, Guedz. The ope… The Hacker News · Jun 12, 2026 High ALAEDZphishing-as-a-servicecredential theftsocial engineering