[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFBm231RaCHkPP9tRD-Ufvx6M-vtqQ-ZZCxHmifYAA8I":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"6169d4e2-dee9-4604-a95e-86fc4a675cdb","phaas-toolkit-bypasses-mfa-via-device-code-phishing-and-token-theft","817b4a9c-36d5-4ca3-b077-fc5786d18c0f","PhaaS Toolkit Bypasses MFA via Device Code Phishing and Token Theft","The Greatness PhaaS platform has evolved to exploit the OAuth 2.0 Device Authorization Grant flow, allowing attackers to bypass multi-factor authentication entirely by stealing session tokens rather than credentials. This matters because traditional MFA — often considered a gold-standard defense — provides no protection when the authentication flow itself is hijacked through device code phishing. Victims are tricked into authorizing attacker-controlled devices, granting persistent access without ever surrendering a password. The consolidation of AiTM, device code phishing, and OAuth abuse into a single commoditized toolkit dramatically lowers the barrier for cybercriminals to launch sophisticated identity attacks at scale.","**Immediate actions:**\n- Restrict or disable the OAuth 2.0 Device Authorization Grant flow for users who do not require device-based authentication workflows.\n- Enforce Conditional Access policies that block token issuance from unmanaged or unrecognized devices.\n- Audit existing OAuth application consents and revoke any suspicious or unknown third-party app authorizations immediately.\n\n**Long-term improvements:**\n- Migrate to phishing-resistant MFA methods such as FIDO2\u002FWebAuthn hardware security keys that are immune to token-theft and AiTM attacks.\n- Implement a Zero Trust architecture requiring continuous verification of device health, user identity, and session context before granting resource access.\n- Establish a formal OAuth application allowlist so only pre-approved apps can request user consent within your environment.\n\n**Detection measures:**\n- Monitor identity provider logs for anomalous device code authentication attempts, especially from unfamiliar IP addresses or geographies.\n- Alert on unusual OAuth consent grants or new application registrations outside of approved change windows.\n- Deploy User and Entity Behavior Analytics (UEBA) to detect impossible travel, token replay, or session anomalies indicative of stolen tokens.",[12,13,14,15,16,17,18,19,20,21,22,23],"NIST SP 800-63B (Phishing-Resistant AAL3 Authenticators)","NIST AC-17 (Remote Access)","NIST AC-20 (Use of External Systems)","NIST SI-4 (System Monitoring)","CIS Control 4 (Secure Configuration of Enterprise Assets)","CIS Control 6 (Access Control Management)","CIS Control 12 (Network Infrastructure Management)","CIS Control 16 (Application Software Security)","MITRE ATT&CK T1528 (Steal Application Access Token)","MITRE ATT&CK T1566 (Phishing)","GDPR Article 32 (Security of Processing)","NIST Zero Trust Architecture SP 800-207","published","2026-08-04T18:20:23.645442+00:00","2026-08-04T18:20:23.556+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fgreatness-phaas-adds-device-code.html","greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens-bc208a","Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]