LIVE · cybersecurity feed
Live wire
Bypassing AI guardrails is so easy a script kiddie can do itCVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
phishing

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

zeroday.news · 2h ago

The commercial phishing-as-a-service (PhaaS) toolkit named Greatness has reportedly integrated support for device code phishing. This new capability allows the crimeware solution to leverage the OAuth 2.0 Device Authorization Grant flow, a legitimate mechanism, for malicious purposes. The primary goal of this addition is to bypass Multi-Factor Authentication (MFA) and facilitate the theft of user tokens, ultimately leading to account compromise.

Device code phishing exploits the OAuth 2.0 Device Authorization Grant, which is designed for input-constrained devices like smart TVs or IoT devices to authenticate with services. In a legitimate scenario, a user would visit a URL on a separate device (like a computer or smartphone) and enter a short code displayed on the constrained device to complete the authentication. Attackers weaponize this by tricking victims into entering a malicious code on a phishing page, which then grants the attacker access to the victim's account or tokens.

This method is particularly effective against MFA because the authentication process often occurs outside the immediate context of the phishing site. The user is prompted to approve a legitimate-looking request, often on a trusted device, making it difficult to discern the underlying malicious intent. Once the victim approves the device code, the attacker gains access to an OAuth token, which can be used to impersonate the user and access their resources without needing their password or directly bypassing MFA.

Greatness, as a commercial PhaaS offering, provides an accessible platform for a wider range of threat actors to deploy sophisticated phishing campaigns. The integration of device code phishing into such a toolkit lowers the technical barrier for attackers, enabling them to execute attacks that might otherwise require more specialized knowledge or custom tooling. This trend reflects a broader commoditization of advanced attack techniques within the cybercriminal ecosystem.

Mitigation strategies for this class of attack typically involve robust user education to recognize the signs of phishing, even when MFA prompts appear legitimate. Organizations are also advised to implement conditional access policies that restrict access from untrusted devices or locations. Monitoring for unusual login patterns and token usage can help detect compromised accounts. Furthermore, security teams should review and understand the legitimate use cases for OAuth 2.0 Device Authorization Grant within their environment and consider disabling it where it is not strictly necessary.

The emergence of device code phishing in commercial PhaaS toolkits like Greatness underscores the ongoing arms race between defenders and attackers. As security measures like MFA become more prevalent, threat actors continuously adapt their tactics to circumvent them. This evolution highlights the need for organizations to stay informed about emerging attack vectors and to continuously update their security postures and user awareness training to counter these increasingly sophisticated threats.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Dem senators criticize Trump administration decisionmaking on AI security risks

The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

aihigh

Bypassing AI guardrails is so easy a script kiddie can do it

Researchers from Cisco Talos have found that current AI model guardrails are easily bypassed by threat actors. Simple claims of ownership or participation in security exercises are often enough to make AI models assist with potentially malicious activities. While AI can be a force multiplier for sophisticated attackers, less skilled individuals may struggle to achieve significant results due to a lack of expertise.

security

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal

Facing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.

malware

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]

ransomware

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

security

Tennessee congressional hopeful accused of shooting license plate cameras

Cops arrest budding politician for allegedly dealing with Flock's expansion the American way