Device Code Phishing
ID: 839b142a-aee4-5c45-ad73-d619588358d3
STIX ID: report--839b142a-aee4-5c45-ad73-d619588358d3
Feed Name: Schneier on Security
The report describes the rising use of device code phishing, where attackers abuse the OAuth device code flow—intended for browserless devices like TVs and printers—to obtain tokens and access accounts. By prompting victims to enter a displayed code at a legitimate URL on another device, attackers leverage the dual-path authorization process to complete login on the constrained device, effectively bypassing standard authentication workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
