Device Code Phishing: The Fastest-Growing Threat of 2026 and How to Defend Against It
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to…
SneakyLog is the name used by Microsoft Threat Intelligence for the Kratos phishing kit. It has been active since early 2025, targeting…
An INTERPOL-led operation codenamed Operation Ramz has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform, resulting in 201 arrests across 13…
Google has filed a lawsuit against a Chinese cybercrime network accused of using its Gemini AI agent to power a phishing-as-a-service (PhaaS)…