Device Code Phishing is an Evolution in Identity Takeover (opens in new tab)
Key Findings Device code phishing is exploding across the threat landscape, with new device code phishing tools emerging every week. The spike in device code phishing coincides with publicly released criminal toolkits, and the emergence of multiple phishing-as-a-service (PhaaS) offerings. Most of the identified activity is using “vibe coded” techniques. It is unclear whether most are copying and modifying publicly known tools or using similar prompts to generate nearly identical attack flows ...
Read the original article