⤷ Title: Cryptographic Paradigm Shift: Google Officially Launches Device Bound Session Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
⌗ Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:26:03 +0000
════════════════════════
⌗ Tags: #Google #browser session hijacking defense #cookie refresh token rotation #Device Bound Session Credentials #Google Chrome DBSC protocol #hardware bound authentication security #infostealer malware protection #macOS Secure Enclave key pairs #session cookie theft mitigation #W3C web security standards #Windows TPM cryptographic binding
Information Security News
Device Bound Session Credentials: Google Neutralizes Cookie Theft
Google debuts Device Bound Session Credentials (DBSC). Learn how this hardware-anchored TPM protocol stops session hijacking and cookie theft.
⤷ Title: Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
Daily CyberSecurity
Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
CISA warns of 7 Naxclow IoT vulnerabilities, including a hard-coded key (CVE-2026-28742) enabling device takeover of doorbells and cameras.
⤷ Title: Device Code Phishing Using Graph Runner
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
Medium
Device Code Phishing Using Graph Runner
1. Introduction
⤷ Title: Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
Daily CyberSecurity
Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
A new device code phishing campaign abuses Microsoft's OAuth flow to hijack Microsoft 365 accounts, no password stealing needed. How to spot it.
⤷ Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Daily CyberSecurity
ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type Phishing-as-a-service (PhaaS) with device code phishing and token theft Targets Micros…
⤷ Title: Default Security Becomes a Backdoor: Assessing the Smart Wi-Fi Camera
════════════════════════
𐀪 Author: Veereshgadige
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 12:35:31 GMT
════════════════════════
⌗ Tags: #device_security #iot_security #penetration_testing
════════════════════════
𐀪 Author: Veereshgadige
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 12:35:31 GMT
════════════════════════
⌗ Tags: #device_security #iot_security #penetration_testing
Medium
Default Security Becomes a Backdoor: Assessing the Smart Wi-Fi Camera
Disclaimer: This research was performed on a device that I personally own and in a controlled environment. The purpose of this article is…
⤷ Title: Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
Daily CyberSecurity
Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
At a glance Actor / group Helix (suspected ties to BlackFile and ShinyHunters) Activity type Data extortion through identity-based intrusion Targets / victims Enterprises; high-visibility staff an…
⤷ Title: Misconfigured Server Exposes Three AiTM Phishing Operators
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
Daily CyberSecurity
Misconfigured Server Exposes Three AiTM Phishing Operators
At a glance Actor / group codemado, mail-argenta, saroula01 (online aliases) Activity AiTM phishing and OAuth Device Code Flow abuse Targets / victims Corporate Microsoft 365 accounts, plus crypto…
⤷ Title: LG Monitors Auto-Install Adware Through Windows Device Metadata
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 02:03:32 +0000
════════════════════════
⌗ Tags: #Malware #adware #Device Metadata #Group Policy #LG #Microsoft Store #windows
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 02:03:32 +0000
════════════════════════
⌗ Tags: #Malware #adware #Device Metadata #Group Policy #LG #Microsoft Store #windows
Daily CyberSecurity
LG Monitors Auto-Install Adware Through Windows Device Metadata
Owners of LG monitors recently discovered something unwelcome on their desktops. Their displays had silently triggered the download of companion software, and that software began serving pop-up ad…
⤷ Title: Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
Daily CyberSecurity
Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
At a glance Actor Unnamed operator; ReliaQuest notes tradecraft similar to APT28 (Fancy Bear, Forest Blizzard) but does not attribute the campaign Activity type Gateway compromise, DNS poisoning, …
⤷ Title: Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
Daily CyberSecurity
Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
At a glance Actor or group Operators of the Greatness kit, also tracked as HoneyStorm Activity type Phishing-as-a-Service with AiTM token theft and device code phishing Targets or victims Microsof…