Skip to main content

Share story

Security

Device code phishing attacks surge 3,700% as criminal kits proliferate

Device code phishing attacks surge 3,700% as criminal kits proliferate Image: Primary
Attacks exploiting the OAuth 2.0 Device Authorization Grant flow have increased more than 37 times this year as automated phishing kits lower barriers to entry for cybercriminals, security researchers report. The technique bypasses traditional phishing defenses by targeting the device code authentication process used for smart TVs, printers, and other input-constrained devices. Once attackers obtain a device code through social engineering, they can hijack accounts without capturing passwords or bypassing multi-factor authentication. The surge reflects a broader pattern of attackers migrating to authentication protocol weaknesses as direct credential theft becomes more difficult. Security teams are being advised to monitor for anomalous device code requests and implement additional verification steps for device-based authentication workflows.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...