Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
0 results for “device code phishing”
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness PhaaS toolkit added device code phishing capabilities to exploit OAuth 2.0’s Device Authorization Grant and bypass MFA, enabling credential theft and account takeover.
Aug 4, 2026
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Phishing attacks using device code delivery surged 1,500% in 2026, and vishing doubled, driven by evolving social engineering tactics that bypass traditional security controls and reduce forensic traceability.
Aug 4, 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing, an OAuth 2.0 device authorization grant abuse technique, has rapidly scaled from red-team tooling to industrialized threat in under six months due to widespread, unintended adoption of the flow beyond its original input-constrained device use case.
Jul 31, 2026
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new PhaaS operation named Forg365 is selling AI-enhanced phishing tooling via Telegram to attackers targeting Microsoft 365 accounts using device code and AitM session theft.
Jul 13, 2026
New Helix vishing group emerges in SharePoint data theft attacks
A newly identified threat actor named Helix is conducting targeted data theft operations against SharePoint environments using identity-based attack vectors including vishing, device code phishing, and MFA bypass techniques.
Jul 10, 2026
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A phishing campaign exploited Microsoft's legitimate device-code authentication flow using collaboration-themed lures to compromise M365 accounts, observed between late June and early July 2026.
Jul 9, 2026