[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7AWHrX1HA-B5wZF2zxRtJBTPx6r7dw1aP9HJQsUVVa4":3},{"article":4,"iocs":27,"watch_terms":28},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"5f5e123d-724c-4fe6-bee0-3a7acd806f28","A phishing campaign is abusing an official device code OAuth flow. Instead of stealing passwords,...","a-phishing-campaign-is-abusing-an-official-device-code-oauth-flow-instead-of-ste","A phishing campaign is abusing an official device code OAuth flow. Instead of stealing passwords, attackers trick you into entering a verification code on the real login page to hijack OAuth tokens. This grants long-term access to email and files. Details: https:\u002F\u002Ft.co\u002FbnR9kg4cSy https:\u002F\u002Ft.co\u002F1LcGIuiiVK","A sophisticated phishing campaign is leveraging the legitimate device code OAuth flow to trick users into entering verification codes on real login pages, allowing attackers to obtain long-term OAuth tokens for email and file access. Rather than attempting traditional password theft, the attackers exploit the trust users place in official authentication mechanisms to gain persistent access to victim accounts.","Phishing campaign abuses device code OAuth flow to hijack tokens without stealing passwords.",null,"https:\u002F\u002Fx.com\u002FUnit42_Intel\u002Fstatus\u002F2036157630230528413","2026-03-23T19:06:23+00:00","2026-03-23T20:00:14.845487+00:00",8,[],"2c8f44d4-b56e-47cf-9677-04f22c9ee78d",{"id":17,"icon":11,"name":19,"slug":20},"Identity & Access","identity-access",[22],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]