Device Code Phishing: The Fastest-Growing Threat of 2026 and How to Defend Against It
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Kali365 is a phishing-as-a-service platform that offers both AiTM and device code phishing capabilities. It was the subject of a standalone FBI…
OctoLink Live is a desktop application used with Kali365 to launch Chromium browser sessions and access victim mailboxes in OWA, OneDrive, SharePoint,…
OctoLink Sender is a tool used with Kali365 to mass-send phishing emails from compromised accounts to contacts, enabling lateral phishing.
Arctic Wolf is a cybersecurity company that analyzed Kali365 phishing campaigns targeting Russia's MAX messenger.