Tag · 15 articles
Phishing
Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA
Learn about the rising threat of OAuth Device Code Phishing used by Tycoon 2FA operators to bypass MFA. Discover how to protect your systems and users.
Jameson Lopp Warns Crypto Holders to Adopt Zero Trust Approach After Phishing Scheme
Jameson Lopp's warning about phishing schemes emphasizes the need for a zero trust approach in crypto security. Learn how to protect your assets effectively.
The New Phishing Click: How OAuth Consent Bypasses MFA
Learn how attackers are using OAuth consent screens to bypass MFA and gain unauthorized access. Discover best practices to protect your applications and users.
FBI Warns Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens
FBI warns of Kali365 phishing kit targeting Microsoft 365 OAuth tokens. Learn how to protect your organization from this threat.
Fake Party Invitation Phishing Scam Spoofs Google and Microsoft OAuth Logins: FTC Warns
Learn about the latest OAuth phishing scam targeting Google and Microsoft logins. Discover how to protect your applications and users from this threat.
OAuth Device Code Flow Security: How to Detect and Prevent Device Code Phishing
OAuth device code phishing (RFC 8628 abuse) bypasses MFA and steals M365 refresh tokens without a password. Learn how to disable device authorization grant in Entra ID, Keycloak, Auth0, and detect attacks with SIEM rules.
AI-enabled Device Code Phishing Campaign Exploits OAuth Flow for Account Takeover
Learn how AI-enabled device code phishing attacks exploit OAuth flows for account takeover. Protect your systems with best practices and updates.
Bogus LinkedIn Message Alerts Enable Credential Siphoning
Recent LinkedIn phishing attacks exploit message alerts to steal credentials. Learn how to protect your accounts and users from these threats.
Device Code Phishing Campaign Targets 340+ Microsoft 365 Organizations Using OAuth Abuse
Learn about the recent device code phishing campaign targeting Microsoft 365 organizations and how to protect your systems from OAuth abuse.
AitM Phishing in 2026: How Starkiller and Tycoon 2FA Bypass MFA — and How to Defend
AitM phishing attacks bypass TOTP, push, and SMS MFA by proxying real login pages. Starkiller and Tycoon 2FA show how. Only FIDO2 passkeys stop it — here's why and how to deploy.
OAuth Redirection Abuse Enables Phishing and Malware Delivery - Microsoft
Learn about OAuth redirection abuse and how it enables phishing and malware delivery. Protect your applications with best practices.
Phishing and OAuth Token Vulnerabilities Lead to Full Microsoft 365 Breach
Learn how phishing and OAuth token vulnerabilities led to a full Microsoft 365 breach. Discover best practices to protect your applications and data.
AI-Powered Phishing Kit Targets Microsoft Users for Credential Theft
Learn about the latest AI-powered phishing kit targeting Microsoft users and how to protect your credentials. Stay ahead of cyber threats with these actionable tips.
Surge of OAuth Device Code Phishing Attacks Targets M365 Accounts
Learn about the surge in OAuth Device Code Phishing attacks targeting M365 accounts and how to protect your systems immediately.