Category: SpyCloud Labs

Illustration of device code phishing attack bypassing multi-factor authentication.

Device Code Phishing: The AiTM Attack That Bypasses MFA

Device code phishing is a fast-growing adversary-in-the-middle (AiTM) attack that exploits OAuth 2.0 device flow to harvest access and refresh tokens — bypassing MFA. SpyCloud Labs researchers break down how it works, what attackers do with stolen tokens, and how to detect and shut down compromised sessions.

Read More »

Going passwordless changes your attack surface. Explore session hijacking prevention

X