Why device code phishing became an industrial threat
🔒 Device code phishing — the abuse of the OAuth 2.0 device authorization grant — has rapidly evolved from a niche red-team tactic into a widespread criminalized attack. Exploiting the authorization step after authentication, it defeats all forms of MFA and has been commercialized in phishing-as-a-service kits. Push Security researchers outline the attack mechanics, ecosystem growth, cross-platform risk, and detection challenges for defenders.
