discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing, the abuse of the OAuth 2.0 device authorization grant to steal access tokens, has evolved from a niche red-team technique to an industrial-scale threat in under six months. It defeats every form of MFA, including passkeys, and is now a standard featu…

By The Hacker News·Jul 31·thehackernews.com·2 min read

Intelligence analysis by Llama

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Image: thehackernews.com

Device code phishing is a growing threat that bypasses all MFA, including passkeys, and is now a standard feature in the phishing-as-a-service catalog. It's not just a Microsoft problem, as any application that implements the OAuth 2.0 device authorization grant is a potential target.

Why it matters

Device code phishing is a significant threat to security, as it can bypass all forms of MFA and is now being used by nation-state actors and criminal groups. It's essential for security teams to be aware of this threat and take steps to protect themselves.

Device code phishing is a type of attack that tricks people into giving away secret codes that let attackers access their accounts. It's like a fake login page that looks real, but it's actually a trick to get the code. This type of attack is hard to stop because it looks like a real login page and can bypass all kinds of security measures.

Analysis

A $60B Vote of Confidence

Device code phishing has evolved from a niche red-team technique to an industrial-scale threat in under six months. This rapid growth reflects the maturity of the existing phishing-as-a-service market and the speed at which AI-assisted development lets new capabilities get built and distributed. The technique has been adopted by a wide range of apps and use-cases that it wasn't originally intended for, most commonly CLI logins.

Why Cursor?

Attackers are moving away from the authentication layer because that's where defenders have concentrated their control. Device code phishing is less universally applicable than AiTM - not every app implements the device authorization grant - but it has the advantages of bypassing all MFA, not requiring cloning a login page, and the user interacting with legitimate provider URLs. Apps like GitHub, AWS, and others all support device code flows, and for GitHub it's a core part of how developers authenticate CLI tools and VS Code tunnels.

The Road Ahead

The commercialization pattern mirrors what happened with AiTM phishing: a technique moves from a research curiosity to nation-state espionage to a criminal commodity, each stage accelerating faster than the last. But device code phishing completed that entire journey in a matter of months - a compression that reflects both the maturity of the existing PhaaS market and the speed at which AI-assisted development lets new capabilities get built and distributed. As kit developers look beyond Microsoft, these are the targets that open up.

Key points

  • Device code phishing is a growing threat that bypasses all MFA, including passkeys.
  • It's not just a Microsoft problem, as any application that implements the OAuth 2.0 device authorization grant is a potential target.
  • Attackers are moving away from the authentication layer because that's where defenders have concentrated their control.
  • Device code phishing is less universally applicable than AiTM - not every app implements the device authorization grant - but it has the advantages of bypassing all MFA, not requiring cloning a login page, and the user interacting with legitimate provider URLs.
The Upside

If security teams can stay ahead of the pace of new device code phishing kits emerging, they may be able to mitigate the threat. This could involve developing new security controls that can detect and prevent device code phishing attacks, as well as educating users about the risks of this type of attack.

The Downside

The rapid growth of device code phishing kits and the ease with which new kits can be built and distributed make it a difficult threat to combat. If security teams are not able to stay ahead of the pace of new kits emerging, the threat of device code phishing may continue to grow.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentsbrowser-securityphishingsecurityoauth-20

Author

The Hacker News

Intelligence analysis by

Llama

Published

Jul 31, 2026

Source

thehackernews.com

Share

Topics

ai-agentsbrowser-securityphishingsecurityoauth-20

Related

More from this desk

Jul 31·bleepingcomputer.com

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical company Amgen suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.

Jul 31·bleepingcomputer.com

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.

Jul 31·schneier.com

Friday Squid Blogging: Squid Helps Discover New Marine Species

A scientific expedition using a new machine called the Squid discovered thirty-one new marine species in two weeks. The Squid uses lasers to scan microscopic details of how organisms are put together.

Jul 31·bleepingcomputer.com

OpenAI says its new GPT 5.6 models are becoming more cost-efficient

OpenAI has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20%. The new prices affect how it counts usage in Codex and ChatGPT Work.