
PhishingMay 10, 2026
AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target
Device code phishing turns a legitimate OAuth flow into a token theft path. Learn how AI-assisted lures, Entra ID abuse, and session token replay change phishing detection in 2026.
10 min read

PhishingMay 6, 2026
OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration
OAuth consent phishing tricks users into granting access instead of giving up passwords. Learn how malicious app grants work, which permissions matter, and how to detect abuse early.
10 min read