Security · 2h ago
Device Code Phishing Emerges as Fast-Growing Threat
Device code phishing, which abuses OAuth 2.0's device authorization grant, has become an industrial-scale threat in under six months. The attack targets input-constrained devices like smart TVs and printers, exploiting a flow designed for them. This technique steals access tokens, posing significant risks to users and organizations.
Meridian48 take
The rapid adoption of device authorization flows has created a new attack surface that many security teams may not yet fully grasp.
Read the full reporting
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 →
The Hacker News
device-code-phishingoauth-abuse