Find a story

Search Spins

Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.

0 results for “device code phishing”

SPIN Processed News Frame: The Fog

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness PhaaS toolkit added device code phishing capabilities to exploit OAuth 2.0’s Device Authorization Grant and bypass MFA, enabling credential theft and account takeover.

Spin 40% Claim Present in Source AI Risk Moderate
The Hacker News

Aug 4, 2026

SPIN Processed News Frame: The Stampede

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Phishing attacks using device code delivery surged 1,500% in 2026, and vishing doubled, driven by evolving social engineering tactics that bypass traditional security controls and reduce forensic traceability.

Spin 65% Needs Evidence AI Risk High
Dark Reading

Aug 4, 2026

SPIN Processed News Frame: The Stampede

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing, an OAuth 2.0 device authorization grant abuse technique, has rapidly scaled from red-team tooling to industrialized threat in under six months due to widespread, unintended adoption of the flow beyond its original input-constrained device use case.

Spin 70% Claim Present in Source AI Risk Moderate
The Hacker News

Jul 31, 2026

SPIN Processed News Frame: The Shield

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new PhaaS operation named Forg365 is selling AI-enhanced phishing tooling via Telegram to attackers targeting Microsoft 365 accounts using device code and AitM session theft.

Spin 30% Source-Supported AI Risk Moderate Needs Evidence
The Hacker News

Jul 13, 2026

SPIN Processed News Frame: The Shield

New Helix vishing group emerges in SharePoint data theft attacks

A newly identified threat actor named Helix is conducting targeted data theft operations against SharePoint environments using identity-based attack vectors including vishing, device code phishing, and MFA bypass techniques.

Spin 40% Claim Present in Source AI Risk Moderate
BleepingComputer

Jul 10, 2026

SPIN Processed News Frame: The Shield

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A phishing campaign exploited Microsoft's legitimate device-code authentication flow using collaboration-themed lures to compromise M365 accounts, observed between late June and early July 2026.

Spin 55% Claim Present in Source AI Risk Moderate
The Hacker News

Jul 9, 2026