Device code phishing attacks surge 37x as new kits spread online
2026-04-04T19:23:30Z•283ffdd4c118e364c2a2e22f6785d7d92a5b2b8ddd3a15df824b14524232465c
BrowserGateCERT-EUClaude-CodeEuropean-Commission-breachExchange-Online-outageLinkedInProgress-ShareFileQilinStrykerTeamPCPVidarZendeskbrowser-scanningchrome-extensionsdata-breachdata-wipingdevice-code-phishinginfostealeroauth2-device-flowphishing-kitspre-auth-rceproxy-evasionransomwareresidential-proxiessupport-ticket-leak
What happened
Multiple high-impact cyber incidents and attacker trends reported: device-code phishing abusing the OAuth2 Device Authorization Grant has surged ~37x as new phishing kits spread; LinkedIn reportedly runs hidden scripts to scan visitors for 6,000+ Chrome extensions and collect device data ("BrowserGate"); Hims & Hers warns of a data breach after Zendesk support tickets were stolen; Qilin ransomware claims data theft from German party Die Linke; CERT-EU attributes a European Commission cloud hack exposing data of ~30 EU entities to TeamPCP; new Progress ShareFile flaws can be chained for pre‑aut
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 283ffdd4c118e364c2a2e22f6785d7d92a5b2b8ddd3a15df824b14524232465c
- Enrichment time
- 2026-04-04T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.