All News
5 August 2026IT News

Greatness PhaaS Evolves to Bypass MFA with Device Code Phishing

The Greatness phishing-as-a-service toolkit has added device code phishing capabilities, posing a significant threat to Australian businesses and individuals by bypassing Multi-Factor Authentication, a critical security measure that many organisations in Australia rely on to protect their networks and data.

A recent development in the cyber threat landscape has seen the commercial phishing-as-a-service toolkit known as Greatness incorporate device code phishing into its arsenal, enabling it to bypass Multi-Factor Authentication and seize control of user accounts, which is particularly concerning for Australian IT professionals and students who are tasked with protecting sensitive information and maintaining the security of their organisations' networks.

The Greatness toolkit supports adversary-in-the-middle credential theft, further complicating the task of securing user accounts and highlighting the need for ongoing training and certification in the field of cybersecurity, such as the Security+ course offered by Wepro Technology, to stay ahead of emerging threats and ensure that IT professionals have the skills and knowledge necessary to effectively counter these types of attacks.

Device code phishing, which abuses the legitimate OAuth 2.0 Device Authorization Grant, is a rapidly growing cyber threat that has the potential to compromise even the most secure systems, making it essential for Australian businesses and individuals to be aware of this threat and take steps to protect themselves, including implementing additional security measures and ensuring that all users are educated about the risks associated with phishing and other types of cyber attacks.

The addition of device code phishing to the Greatness toolkit is a significant development, as it allows attackers to bypass Multi-Factor Authentication, which is widely regarded as a critical security measure for protecting user accounts and preventing unauthorised access to sensitive information, and it is likely that this new capability will be used in a variety of different contexts, including targeted attacks against specific organisations or individuals in Australia.

As the threat landscape continues to evolve, it is essential for Australian IT professionals and students to stay up-to-date with the latest developments and to be aware of the potential risks and threats that are associated with emerging technologies and techniques, such as device code phishing, and to take steps to protect themselves and their organisations from these types of attacks, including investing in ongoing training and education and implementing robust security measures to prevent and detect cyber threats.

The growing threat of device code phishing and other types of cyber attacks highlights the need for Australian businesses and individuals to be proactive in their approach to cybersecurity, and to take a comprehensive and multi-layered approach to protecting themselves and their organisations from these types of threats, including implementing robust security measures, providing ongoing training and education to IT professionals and users, and staying informed about the latest developments and trends in the field of cybersecurity.

Source
The Hacker NewsView original
Newsletter

Stay ahead in IT

Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.

  • Weekly IT news & insights
  • New course announcements
  • Free quiz updates

Your email

No spam, ever · Unsubscribe anytime

Ask anything!