OAuth Device Code Phishing Research and Findings
A short report on OAuth device code phishing, an attack technique that has grown rapidly in 2026. It covers how attackers use real login pages to steal access tokens and bypass MFA.
A short report on OAuth device code phishing, an attack technique that has grown rapidly in 2026. It covers how attackers use real login pages to steal access tokens and bypass MFA.
Learn the foundations of malware analysis and Windows forensics, then follow a RAT from static and dynamic analysis to Prefetch, Amcache and Registry evidence
A walkthrough of a real EtherHiding campaign, tracing how attackers use Polygon smart contracts as a dead drop to serve a ClickFix/FakeCAPTCHA and deliver information stealers.
A breakdown of fake CAPTCHA malvertising campaigns used to deliver malware and information stealers like LummaStealer and StealC with a look at attack flows, findings, detection ideas to put in place, and response actions.