CyberSecurity News
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
AI summary
The Greatness phishing-as-a-service toolkit has added device code phishing capabilities, allowing it to bypass Multi-Factor Authentication and steal user tokens. This is done by exploiting the OAuth 2.0 Device Authorization Grant, a legitimate protocol. The addition of device code phishing to Greatness makes it a more formidable crimeware solution. Greatness also supports adversary-in-the-middle credential phishing, further enhancing its capabilities. The toolkit's evolution highlights the growing threat of device code phishing attacks. Greatness is now more effective at seizing control of user accounts.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

