⤷ Title: New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
Daily CyberSecurity
New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
Microsoft uncovers EvilToken, an AI-powered PhaaS toolkit using Dynamic Device Code Generation to bypass MFA and breach high-value accounts. Patch now!
⤷ Title: Hardware-Locked: How Chrome’s New DBSC Makes Stolen Cookies Worthless
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 07:18:14 +0000
════════════════════════
⌗ Tags: #Technology #Chrome 146 #cybersecurity #DBSC #Device Bound Credentials #google chrome #infosec #InfoStealer malware #Secure Enclave #Session Hijacking #TPM #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 07:18:14 +0000
════════════════════════
⌗ Tags: #Technology #Chrome 146 #cybersecurity #DBSC #Device Bound Credentials #google chrome #infosec #InfoStealer malware #Secure Enclave #Session Hijacking #TPM #Web Security
Daily CyberSecurity
Hardware-Locked: How Chrome’s New DBSC Makes Stolen Cookies Worthless
Google launches DBSC in Chrome 146, binding session cookies to hardware like TPM. Neutralize infostealers and stop session hijacking with this new standard.
⤷ Title: Hackers Hijack Microsoft 365 Accounts via Legitimate Device Code Flows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:07:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #Device Code Flow #Graphish #M365 Hardening #Microsoft 365 #OAuth #Passwordless Security #phishing 2026 #Proofpoint #QR Code Phishing #SquarePhish2 #TA2723
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:07:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #Device Code Flow #Graphish #M365 Hardening #Microsoft 365 #OAuth #Passwordless Security #phishing 2026 #Proofpoint #QR Code Phishing #SquarePhish2 #TA2723
Penetration Testing Tools
Hackers Hijack Microsoft 365 Accounts via Legitimate Device Code Flows
Both fraudulent actors and state-sponsored syndicates have commenced the large-scale deployment of a novel stratagem to usurp Microsoft
⤷ Title: BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 02:49:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure AD #BAADTokenBroker #cloud security #Device_Bound Keys #Kerberos #Microsoft Entra ID #NT Hash #post_exploitation #PRT Cookie #red teaming #TGT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 15 May 2026 02:49:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure AD #BAADTokenBroker #cloud security #Device_Bound Keys #Kerberos #Microsoft Entra ID #NT Hash #post_exploitation #PRT Cookie #red teaming #TGT
Penetration Testing Tools
BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking
Master Microsoft Entra ID post-exploitation with BAADTokenBroker. Learn how to request PRT cookies and abuse Entra Kerberos to acquire TGTs and NT hashes.
⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!
⤷ Title: Microsoft Explains the New “SecureBoot” Folder in Windows 11 KB5089549 Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
Daily CyberSecurity
Microsoft Explains the New "SecureBoot" Folder in Windows 11 KB5089549 Update
Seeing a new SecureBoot folder under C:Windows? Microsoft confirms it is part of an essential KB5089549 update to replace expiring 2011 UEFI certificates.
⤷ Title: Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Cyber Security #Device Authorization Grant #eSentire TRU #infosec #MFA Bypass #Microsoft 365 #Multi_Factor Authentication #OAuth 2.0 #PhaaS #Phishing_as_a_Service #Tycoon 2FA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Cyber Security #Device Authorization Grant #eSentire TRU #infosec #MFA Bypass #Microsoft 365 #Multi_Factor Authentication #OAuth 2.0 #PhaaS #Phishing_as_a_Service #Tycoon 2FA
Daily CyberSecurity
Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365
Despite a global takedown, Tycoon 2FA is back. It now abuses Microsoft's device code flow to bypass MFA entirely. Disabling this flow is critical.
⤷ Title: Intel Architects High-Velocity Point-to-Point Interconnect Paradigm for Linux
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:39 +0000
════════════════════════
⌗ Tags: #Linux #/dev/tbstreamX character device #cable based host to host streaming #ConfigFS USB4 tunnel configuration #device to device file sharing #hardware peripheral virtualization #Intel thunderbolt_stream kernel patch #Linux USB4STREAM driver protocol #low dependency disaster recovery backup #Mika Westerberg Linux 7.2 merge #raw packet transfer over Thunderbolt
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:39 +0000
════════════════════════
⌗ Tags: #Linux #/dev/tbstreamX character device #cable based host to host streaming #ConfigFS USB4 tunnel configuration #device to device file sharing #hardware peripheral virtualization #Intel thunderbolt_stream kernel patch #Linux USB4STREAM driver protocol #low dependency disaster recovery backup #Mika Westerberg Linux 7.2 merge #raw packet transfer over Thunderbolt
Information Security News
Intel USB4STREAM Driver Bypasses Network Stack in Linux 7.2
Intel's new USB4STREAM driver protocol lets Linux hosts transfer raw data and share hardware peripherals via USB4/Thunderbolt without a network stack.
⤷ Title: Telemetry Interception: The Unauthorized Routing of Motorola’s Amazon Gateway
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 03:32:30 +0000
════════════════════════
⌗ Tags: #Technology #Allison Yi product management statement #Amazon affiliate code injection #Android launcher app hijacking #Device Native mobile ad monetization #disable Motorola Smart Feed #kira_abboud.com tracking domain #mobile bloatware browser detour #Motorola Razr 60 Ultra app drawer bug #Motorola Smart Feed redirect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 03:32:30 +0000
════════════════════════
⌗ Tags: #Technology #Allison Yi product management statement #Amazon affiliate code injection #Android launcher app hijacking #Device Native mobile ad monetization #disable Motorola Smart Feed #kira_abboud.com tracking domain #mobile bloatware browser detour #Motorola Razr 60 Ultra app drawer bug #Motorola Smart Feed redirect
Daily CyberSecurity
Telemetry Interception: The Unauthorized Routing of Motorola's Amazon Gateway
Users uncover a weird Motorola Smart Feed redirect that forces the Amazon app through third-party tracking links. Motorola claims it was a glitch and fixed it.
⤷ Title: Cryptographic Paradigm Shift: Google Officially Launches Device Bound Session Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
⌗ Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
⌗ Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
Information Security News
Device Bound Session Credentials: Google Neutralizes Cookie Theft
Google debuts Device Bound Session Credentials (DBSC). Learn how this hardware-anchored TPM protocol stops session hijacking and cookie theft.
⤷ Title: Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
Daily CyberSecurity
Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
CISA warns of 7 Naxclow IoT vulnerabilities, including a hard-coded key (CVE-2026-28742) enabling device takeover of doorbells and cameras.
⤷ Title: Device Code Phishing Using Graph Runner
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
Medium
Device Code Phishing Using Graph Runner
1. Introduction
⤷ Title: Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
Daily CyberSecurity
Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
A new device code phishing campaign abuses Microsoft's OAuth flow to hijack Microsoft 365 accounts, no password stealing needed. How to spot it.
⤷ Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Daily CyberSecurity
ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type Phishing-as-a-service (PhaaS) with device code phishing and token theft Targets Micros…
⤷ Title: Default Security Becomes a Backdoor: Assessing the Smart Wi-Fi Camera
════════════════════════
𐀪 Author: Veereshgadige
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 12:35:31 GMT
════════════════════════
⌗ Tags: #device_security #iot_security #penetration_testing
════════════════════════
𐀪 Author: Veereshgadige
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 12:35:31 GMT
════════════════════════
⌗ Tags: #device_security #iot_security #penetration_testing
Medium
Default Security Becomes a Backdoor: Assessing the Smart Wi-Fi Camera
Disclaimer: This research was performed on a device that I personally own and in a controlled environment. The purpose of this article is…
⤷ Title: Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
Daily CyberSecurity
Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
At a glance Actor / group Helix (suspected ties to BlackFile and ShinyHunters) Activity type Data extortion through identity-based intrusion Targets / victims Enterprises; high-visibility staff an…
⤷ Title: Misconfigured Server Exposes Three AiTM Phishing Operators
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
Daily CyberSecurity
Misconfigured Server Exposes Three AiTM Phishing Operators
At a glance Actor / group codemado, mail-argenta, saroula01 (online aliases) Activity AiTM phishing and OAuth Device Code Flow abuse Targets / victims Corporate Microsoft 365 accounts, plus crypto…
⤷ Title: LG Monitors Auto-Install Adware Through Windows Device Metadata
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 02:03:32 +0000
════════════════════════
⌗ Tags: #Malware #adware #Device Metadata #Group Policy #LG #Microsoft Store #windows
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 02:03:32 +0000
════════════════════════
⌗ Tags: #Malware #adware #Device Metadata #Group Policy #LG #Microsoft Store #windows
Daily CyberSecurity
LG Monitors Auto-Install Adware Through Windows Device Metadata
Owners of LG monitors recently discovered something unwelcome on their desktops. Their displays had silently triggered the download of companion software, and that software began serving pop-up ad…
⤷ Title: Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
Daily CyberSecurity
Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
At a glance Actor Unnamed operator; ReliaQuest notes tradecraft similar to APT28 (Fancy Bear, Forest Blizzard) but does not attribute the campaign Activity type Gateway compromise, DNS poisoning, …
⤷ Title: Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
Daily CyberSecurity
Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
At a glance Actor or group Operators of the Greatness kit, also tracked as HoneyStorm Activity type Phishing-as-a-Service with AiTM token theft and device code phishing Targets or victims Microsof…