Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service (PhaaS) platform has integrated device code phishing capabilities, exploiting OAuth 2.0 Device Authorization Grant protocols to circumvent multi-factor authentication protections. This enhancement allows threat actors to conduct adversary-in-the-middle attacks that steal credentials and session tokens, representing an escalation in commercially available cybercr
AIHackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Pro-Iranian hackers exploited Meta's AI customer support bot to hijack high-profile Instagram accounts, including those of the Obama White House and a U.S. Space Force official. The attack involved tricking the AI assistant into adding unauthorized email addresses during password reset flows, highlighting critical vulnerabilities in AI-powered customer support systems. Meta has reportedly deployed
