Device Code Phishing: 37x Spike, Every PhaaS Platform Shipping It — The MFA Bypass That Survives Password Resets Is Now a Criminal Commodity
18 months ago: Russian espionage only. Today: 18 kits in circulation, 37.5x detection spike, every major AiTM PhaaS platform ships it. It bypasses TOTP, push notifications, and SMS MFA. The stolen OAuth token survives password resets. EvilTokens is AI-built and Telegram-distributed. Your Conditional Access policy doesn’t block it by default. FBI advisory issued on Kali365.
Read Full Brief →Threats & Attacks
18 months ago: Russian espionage. Today: criminal commodity. Bypasses TOTP, push, SMS. Token survives password resets. Conditional Access doesn’t block it by default. EvilTokens is AI-built. FBI advisory on Kali365.
The exploit never touches disk. FIM, Tripwire, AIDE — all report clean. Poisons the kernel page cache copy of /bin/su. Public PoC in 24 hours. Ubuntu patches pending.
No org membership. No special privileges. Owner-level Google Cloud access. Non-expiring Microsoft Sentinel keys. Python Black token for 130M monthly installs. AI agents reproducing the pattern.
C’s strchr, a 1997 FTP parser, heap overread leaking other users’ passwords. Found by Claude Mythos in under an hour. Coming in 7.7. Disable FTP now.
+181% in 48 hours. Five CISA-mandated actions. 35% generic admin accounts. Hudson Rock free lookup tool. FortiSandbox also exploited.
REDCap exploitation, INFINITERED malware, domain admin, weaponized Google Workspace compliance rule. Defense, AI, and medical research data exfiltrated.
Intelligence & Deep Dive
Further Coverage
Scan, stuff, sniff, feed. Turkish NATO defense contractor confirmed. Source still unconfirmed.
No credentials. No interaction. AWS out of the box. watchTowr exploit chain published.
Largest Patch Tuesday ever. Wormable HTTP.sys. MiniPlasma patched. RoguePlanet now CVE-2026-50656.
Unauthenticated attackers forge GlobalProtect cookies, bypass MFA. CVSS 9.1. June 19 CISA deadline passed.
Now confirmed exploited for months prior to disclosure. No patch. Chains after CVSS 10.0 auth bypass.
Nx Console breach + Megalodon GitHub Actions campaign. TeamPCP open-sourced framework. Earlier chapter of the Cordyceps supply chain arc.
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise. Trusted by enterprise and government security leaders.
