← Back to feed
research Kaspersky Securelist

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

Kaspersky Securelist Microsoft

The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers.

T1566
Read the full story Kaspersky Securelist →

Related Coverage

research SAML: A fractal of bad design Trail of Bits · Sep 21 research Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO Kaspersky Securelist · Sep 21 research From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies Unit 42 · Sep 21