Device Code Phishing After EvilToken: The 15-Minute Window Is Gone
Recent device code phishing campaigns turned a niche device-authorization abuse path into a practical MFA-bypass workflow. The real change is not just better lures. It is that attackers now generate device codes in real time, which makes the attack far easier to scale.