As cited
Copy frozen at (site build).
threat intel
We Need to Talk About Device Code Phishing
Huntress researchers presented analysis of device code phishing attacks during a June Tradecraft Tuesday session, examining variations of the technique and its appeal to threat actors. Device code phishing leverages the device authorization flow to trick users into granting attackers access to cloud accounts and data.
Why it matters: Security teams need to understand device code phishing because threat actors are increasingly using this method to bypass traditional defenses and gain initial access to cloud environments; practitioners should implement controls to detect and block suspicious device code authentication attempts.
- Source published
- First seen by Cybersecurity Tracker