importantSYS.SOURCE: The Hacker News• 2026-07-31T16:54:59+05:30
Device Code Phishing: A Rising Threat in 2026 Exploiting OAuth 2.0 Authorization Flaws
Device code phishing exploits OAuth 2.0 authorization flows to bypass MFA, including passkeys, and has rapidly evolved into a widespread threat through PhaaS ecosystems. The attack's growth is accelerated by AI-assisted kit development and a shift toward targeting authorization layers rather than authentication.
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months.
Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally
*** END OF TRANSMISSION ***