Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
UNC7005, also known as Storm-2945, is a suspected Russian threat actor identified in February 2026. It targets academia, diplomatic, and nonprofit personnel…
Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft's legitimate authentication flow. According to ANY.RUN telemetry, the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…