Skip Navigation
Get a Demo
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

SecOps Weekly: Episode 78 – How platform-chaining abuse leads to phishing

SecOps Weekly | 08.25.26

How platform-chaining abuse leads to phishing

Staff Threat Researcher Mitchel Parish discusses how his team has detected an uptick in identity attacks this summer, many which leverage phishing-as-a-service (PhaaS) kits that rely on legitimate services to trick users.

SHOW NOTES

In this episode of SecOps Weekly, Staff Threat Researcher Mitchel Parish breaks down the growing threat of device code phishing: a technique that abuses legitimate authentication flows to silently harvest access and refresh tokens from unsuspecting users.

Mitchel also walks through a real attack chain that uses Calendly routing forms and Cloudflare Workers to host convincing lures and examines how AI-powered phishing kits have dramatically lowered the bar for pulling off these attacks.

TIMESTAMPS

  • 00:00: Welcome to SecOps Weekly!
  • 02:35: PhaaS kits & identity attacks
  • 07:01: Abuse of trusted services
  • 13:08: The lure
  • 17:00: The foothold
  • 22:27 : Mitigation opportunities

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top