OAuth Device Flow Abuse: 37x Surge in Account Hijacking via Weaponised Phishing Kits
Device code phishing attacks exploiting OAuth 2.0's Device Authorization Grant flow have increased 37-fold this year, with automated kits now widely available. Attackers bypass traditional MFA by tricking users into authorising malicious device registrations, gaining account access without credentials.