Tag · 15 articles

Phishing

Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA

Learn about the rising threat of OAuth Device Code Phishing used by Tycoon 2FA operators to bypass MFA. Discover how to protect your systems and users.

Jameson Lopp Warns Crypto Holders to Adopt Zero Trust Approach After Phishing Scheme

Jameson Lopp's warning about phishing schemes emphasizes the need for a zero trust approach in crypto security. Learn how to protect your assets effectively.

The New Phishing Click: How OAuth Consent Bypasses MFA

Learn how attackers are using OAuth consent screens to bypass MFA and gain unauthorized access. Discover best practices to protect your applications and users.

FBI Warns Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens

FBI warns of Kali365 phishing kit targeting Microsoft 365 OAuth tokens. Learn how to protect your organization from this threat.

Fake Party Invitation Phishing Scam Spoofs Google and Microsoft OAuth Logins: FTC Warns

Learn about the latest OAuth phishing scam targeting Google and Microsoft logins. Discover how to protect your applications and users from this threat.

OAuth Device Code Flow Security: How to Detect and Prevent Device Code Phishing

OAuth device code phishing (RFC 8628 abuse) bypasses MFA and steals M365 refresh tokens without a password. Learn how to disable device authorization grant in Entra ID, Keycloak, Auth0, and detect attacks with SIEM rules.

AI-enabled Device Code Phishing Campaign Exploits OAuth Flow for Account Takeover

Learn how AI-enabled device code phishing attacks exploit OAuth flows for account takeover. Protect your systems with best practices and updates.

Bogus LinkedIn Message Alerts Enable Credential Siphoning

Recent LinkedIn phishing attacks exploit message alerts to steal credentials. Learn how to protect your accounts and users from these threats.

Device Code Phishing Campaign Targets 340+ Microsoft 365 Organizations Using OAuth Abuse

Learn about the recent device code phishing campaign targeting Microsoft 365 organizations and how to protect your systems from OAuth abuse.

AitM Phishing in 2026: How Starkiller and Tycoon 2FA Bypass MFA — and How to Defend

AitM phishing attacks bypass TOTP, push, and SMS MFA by proxying real login pages. Starkiller and Tycoon 2FA show how. Only FIDO2 passkeys stop it — here's why and how to deploy.

OAuth Redirection Abuse Enables Phishing and Malware Delivery - Microsoft

Learn about OAuth redirection abuse and how it enables phishing and malware delivery. Protect your applications with best practices.

Phishing and OAuth Token Vulnerabilities Lead to Full Microsoft 365 Breach

Learn how phishing and OAuth token vulnerabilities led to a full Microsoft 365 breach. Discover best practices to protect your applications and data.

AI-Powered Phishing Kit Targets Microsoft Users for Credential Theft

Learn about the latest AI-powered phishing kit targeting Microsoft users and how to protect your credentials. Stay ahead of cyber threats with these actionable tips.

Surge of OAuth Device Code Phishing Attacks Targets M365 Accounts

Learn about the surge in OAuth Device Code Phishing attacks targeting M365 accounts and how to protect your systems immediately.

Understanding and Defending Against Bank Impersonation Attacks

Learn to identify and defend against bank impersonation attacks using IAM and DevOps strategies. Protect your financial data with expert tips.