Token Bingo: Don't Let Your Code be the Winner

Reported 25 Apr 2026 by otx · Severity: medium

In early April 2026, a large-scale device code phishing campaign targeted organizations across multiple sectors and regions, exploiting OAuth 2.0 Device Authorization Grant. Threat actors leveraged the Kali365 phishing-as-a-service platform, originating primarily from IP address