Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Read full story on The Hacker News
Share
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
AI disclosure

Summary

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.