Topic: device code phishing

  • Device Code Phishing Attacks Jump 37x with New Kits

    Device Code Phishing Attacks Jump 37x with New Kits

    A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for hardware to hijack accounts and bypass multi-factor authentication. The primary driver is the EvilTokens phishing-as-a-service kit, with at least 11 distinct kits now a...

    Read More »
  • FBI warns of Kali365 phishing threat to Microsoft 365 accounts

    FBI warns of Kali365 phishing threat to Microsoft 365 accounts

    The FBI warns about Kali365, a phishing-as-a-service platform that targets Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). Kali365 enables low-skilled attackers with AI-generated phishing lures, automated cam...

    Read More »
  • Microsoft 365 Users Targeted by EvilTokens Device Code Phishing

    Microsoft 365 Users Targeted by EvilTokens Device Code Phishing

    A new phishing-as-a-service toolkit called EvilTokens is enabling a surge in sophisticated device code phishing attacks against Microsoft 365 accounts, bypassing traditional security like multi-factor authentication. The attack exploits a legitimate Microsoft device authentication feature, tricki...

    Read More »
  • Microsoft Entra Accounts Targeted in Vishing Attacks

    Microsoft Entra Accounts Targeted in Vishing Attacks

    A new wave of attacks combines device code phishing with voice phishing (vishing) to compromise Microsoft Entra accounts, exploiting the legitimate OAuth 2.0 device authorization flow to steal authentication tokens without traditional password theft. The **ShinyHunters** extortion group is believ...

    Read More »
  • Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Attackers are exploiting Microsoft's device code authorization flow to bypass multi-factor authentication, tricking users into granting account access via fraudulent login portals. The campaigns are scaled using readily available red team tools like Squarephish and Graphish, which automate phishi...

    Read More »
  • Why Your Browser Is AI Security's New Front Line

    Why Your Browser Is AI Security's New Front Line

    AI-enabled attacks are outpacing traditional defenses by using AI to rapidly create phishing kits, rotate infrastructure, and deploy multi-channel campaigns via non-email channels, making IoC-based detections like blocklists largely ineffective. The browser session is the critical convergence poi...

    Read More »
  • New Helix vishing group targets SharePoint in data theft attacks

    New Helix vishing group targets SharePoint in data theft attacks

    A new threat group called Helix uses voice phishing, device code phishing, and MFA abuse to compromise SharePoint environments for data extortion. Helix bypasses security by tricking employees through vishing calls and then exploiting device code phishing to gain persistent access without trigger...

    Read More »
  • Senior Executives Targeted by VENOM Phishing for Microsoft Logins

    Senior Executives Targeted by VENOM Phishing for Microsoft Logins

    A new, sophisticated phishing-as-a-service platform called VENOM has been targeting high-level corporate executives since at least November 2025, using a closed-access model to evade detection. The attacks use highly personalized emails with QR codes to bypass email scanners, leading to filtering...

    Read More »
  • Hijacked Hotel Wi-Fi Spreads Spyware Via Fake Updates

    Hijacked Hotel Wi-Fi Spreads Spyware Via Fake Updates

    CaptiveCrunch is a malicious campaign exploiting compromised hotel Wi-Fi captive portals to redirect travelers to fake browser update pages, delivering the CornFlake remote access trojan that can spy via webcam, microphone, keyboard, and steal credentials. The attack leverages DNS manipulation on...

    Read More »
  • Phishing-Resistant Authentication: How Hackers Still Bypass It

    Phishing-Resistant Authentication: How Hackers Still Bypass It

    Phishing-resistant authentication methods like passkeys and FIDO2-based systems (e.g., YubiKeys) improve security, but attackers exploit weaknesses such as downgrade attacks to bypass them. Emerging threats like device code phishing, consent phishing, and verification phishing target vulnerabilit...

    Read More »
  • 2025 Phishing Trends: Protect Your Security Strategy Now

    2025 Phishing Trends: Protect Your Security Strategy Now

    Phishing in 2025 became more sophisticated and identity-focused, with attacks increasingly occurring outside of email through channels like LinkedIn and manipulated search results to bypass traditional security filters. The rise of Phishing-as-a-Service kits enables real-time attacks that can byp...

    Read More »
  • Hackers compromise hotel WiFi networks, Microsoft warns

    Hackers compromise hotel WiFi networks, Microsoft warns

    Microsoft has identified a cyberthreat campaign called "CaptiveCrunch" targeting travelers through compromised hotel WiFi networks, potentially linked to Russian actors and active since May. The attack uses deceptive pop-ups or fake login screens that trick users into downloading files or alterin...

    Read More »