Phishing
Phishing the Protocol: How 2026 Attackers Made MFA Irrelevant
Device code grants, app passwords, OAuth consent screens, and WhatsApp device linking all share one property: they're real login flows, not bugs. 2026's biggest identity attacks stopped stealing passwords and started collecting the tokens MFA can't protect.
GTIG Tracks Three Russian Clusters Weaponizing App Passwords, OAuth Consent, and WhatsApp Linking
Google's Threat Intelligence Group details three Russia-nexus clusters — UNC6293, UNC7005, UNC5976 — abusing app-password generation, OAuth consent flows, and WhatsApp device linking to hijack accounts of diplomats, academics, and defense researchers without tripping MFA.
AssuranceAmerica Breach Exposes 7 Million Driver's Licenses After a Single Phished Employee Account
A single compromised employee credential at auto insurer AssuranceAmerica led to the theft of driver's license numbers, SSNs, and policy data for nearly 7 million people — one of the largest driver's-license breaches disclosed in the US this year.