The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

The commercial phishing-as-a-service (PhaaS) toolkit named Greatness has reportedly integrated support for device code phishing. This new capability allows the crimeware solution to leverage the OAuth 2.0 Device Authorization Grant flow, a legitimate mechanism, for malicious purposes. The primary goal of this addition is to bypass Multi-Factor Authentication (MFA) and facilitate the theft of user tokens, ultimately leading to account compromise.
Device code phishing exploits the OAuth 2.0 Device Authorization Grant, which is designed for input-constrained devices like smart TVs or IoT devices to authenticate with services. In a legitimate scenario, a user would visit a URL on a separate device (like a computer or smartphone) and enter a short code displayed on the constrained device to complete the authentication. Attackers weaponize this by tricking victims into entering a malicious code on a phishing page, which then grants the attacker access to the victim's account or tokens.
This method is particularly effective against MFA because the authentication process often occurs outside the immediate context of the phishing site. The user is prompted to approve a legitimate-looking request, often on a trusted device, making it difficult to discern the underlying malicious intent. Once the victim approves the device code, the attacker gains access to an OAuth token, which can be used to impersonate the user and access their resources without needing their password or directly bypassing MFA.
Greatness, as a commercial PhaaS offering, provides an accessible platform for a wider range of threat actors to deploy sophisticated phishing campaigns. The integration of device code phishing into such a toolkit lowers the technical barrier for attackers, enabling them to execute attacks that might otherwise require more specialized knowledge or custom tooling. This trend reflects a broader commoditization of advanced attack techniques within the cybercriminal ecosystem.
Mitigation strategies for this class of attack typically involve robust user education to recognize the signs of phishing, even when MFA prompts appear legitimate. Organizations are also advised to implement conditional access policies that restrict access from untrusted devices or locations. Monitoring for unusual login patterns and token usage can help detect compromised accounts. Furthermore, security teams should review and understand the legitimate use cases for OAuth 2.0 Device Authorization Grant within their environment and consider disabling it where it is not strictly necessary.
The emergence of device code phishing in commercial PhaaS toolkits like Greatness underscores the ongoing arms race between defenders and attackers. As security measures like MFA become more prevalent, threat actors continuously adapt their tactics to circumvent them. This evolution highlights the need for organizations to stay informed about emerging attack vectors and to continuously update their security postures and user awareness training to counter these increasingly sophisticated threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.