Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The Greatness PhaaS toolkit now offers device-code phishing to bypass MFA via OAuth 2.0 device authorisation flows, commoditising an attack that previously required bespoke adversary infrastructure.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

"Greatness supports AiTM [adversary-in-the-middle] credential and

Editorial Analysis

Why it matters

Commoditised device-code phishing dramatically lowers the barrier for MFA bypass attacks; enterprises relying solely on push-based MFA face escalating token-theft risk.

What to do

Restrict device-code OAuth flows in conditional access policies and accelerate migration to phishing-resistant authentication methods like FIDO2 passkeys.

Board brief

A commercial phishing toolkit now automates MFA bypass via OAuth device-code flows, threatening enterprises that rely on standard multi-factor authentication.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk