6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved...
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved...
Swati KhandelwalJul 29, 2026Vulnerability / DevOps Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A...
Swati KhandelwalJul 29, 2026Mobile Security / Threat Intelligence Source code for the Flying Eagle Android remote access trojan (RAT) framework...
Opening a Git repository in a vulnerable version of Cursor could be enough to give attackers code execution on a...
The biggest privacy risk on smartphones may not be the apps themselves, but the third-party code quietly running inside them....
Swati KhandelwalJul 17, 2026Vulnerability / Web Security An anonymous HTTP request can run code on a WordPress site. The bug...
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion,...
In September 2025, Anthropic detected suspicious activity in its Claude Code tool, which turned out to be a state-sponsored espionage...
China is telling organizations to remove certain versions of Anthropic’s Claude Code. The warning claims the AI coding assistant has...
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on...
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of...
TL;DR: Use code SECURE to get a NordVPN 1-year subscription (MSRP $69.99) for $29.99. Public Wi-Fi at airports, hotels, and coffee shops...
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between...
AI coding agents (Claude Code, Cursor, Codex, and others built on skill packs such as GStack) are showing up in customer environments. They...
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living....