OAuth Consent and Device Code Phishing for Red Teams

Due to the increasing trend of OAuth abuse in phishing and most users’ lack of understanding between Device Code and OAuth App Consent phishing, I just added them to the PhishU Framework. Now with a quick, two-step process red teams and internal orgs can leverage the templates to train users for this very real-world attack.

Check out the blog for details at https://phishu.net/blogs/blog-microsoft-entra-device-code-phishing-phishu-framework.html if interested!

submitted by /u/IndySecMan
[link] [comments]

March 29, 2026
Read More >>

Apple issues urgent lock screen warnings for unpatched iPhones and iPads

Apple is alerting users of outdated iPhones and iPads via lock screen warnings about active web-based exploits, urging immediate software updates. Apple is sending lock screen alerts to users running outdated iOS and iPadOS versions, warning of active web-based attacks targeting their devices. The notifications urge users to install critical updates to stay protected, highlighting […]

March 29, 2026
Read More >>