Skip to content
The Nexus
DossierENTITY

phishing-as-a-service (PhaaS)

Coverage of phishing-as-a-service (PhaaS) in the Nexus archive.

Earliest in view: May 25 · 12:45 UTCMost recent: Aug 4 · 17:27 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 4 · 17:27 UTCTHE HACKER NEWS
    Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, which exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. This method allows attackers to seize control of accounts by leveraging a legitimate authentication protocol.

  • SECURITYMay 25 · 12:45 UTCBLEEPING COMPUTER
    FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

    The FBI has issued a warning about the Kali365 phishing-as-a-service platform, which exploits OAuth device code authentication to hijack Microsoft 365 accounts. The service steals session tokens and bypasses multi-factor authentication (MFA), posing a significant cybersecurity threat.