Find notable cyber news and cases, enriched with sources, timelines, and signals.

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targeting cloud accounts. The service now combines AiTM credential theft, OAuth consent abuse, and multiple target platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace. That shift lowers the barrier to entry for affiliates and increases the scale and persistence of account compromise.

Related Happenings

Tycoon2FA-Kali365-ARToken alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score89 First: 31.07.2026 14:24 Last: 31.07.2026 14:24 Sources 1

About this happening: Phishing-as-a-service kits have turned device code phishing into a commoditized feature, expanding token theft across multiple criminal platforms and accelerating oper...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Timeline

  1. 04.08.2026 20:27 2 articles · 3h ago

    Greatness adds device code phishing to its operator panel

    Initial Disclosure

    Greatness added device code phishing to its phishing-as-a-service toolkit, pairing the OAuth 2.0 Device Authorization Grant with existing AiTM token theft and OAuth consent abuse capabilities to bypass MFA and steal session tokens. The service is marketed through a public Telegram channel and bot-based registration flow, and recent campaigns used spoofed RingCentral voicemail lures plus post-compromise token replay against Microsoft 365 resources such as Outlook, Teams, SharePoint, Exchange, and OneDrive.

    Show sources