<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web Security | He (Shawn) Shuang's Personal Site</title><link>https://8759s.github.io/tags/web-security/</link><atom:link href="https://8759s.github.io/tags/web-security/index.xml" rel="self" type="application/rss+xml"/><description>Web Security</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 00:00:00 +0000</lastBuildDate><image><url>https://8759s.github.io/media/icon_hu_1035bcf07d2ae8d9.png</url><title>Web Security</title><link>https://8759s.github.io/tags/web-security/</link></image><item><title>Device Code Phishing Evasion Techniques</title><link>https://8759s.github.io/news/device-code-phishing-evasion-techniques/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>https://8759s.github.io/news/device-code-phishing-evasion-techniques/</guid><description>&lt;p>We observed device-code phishing campaigns using four complementary evasion techniques. CAPTCHA gates block basic URL scanners while mimicking legitimate Microsoft security checks, and multi-step flows route victims through trusted SaaS platforms before revealing the phishing page.&lt;/p>
&lt;p>Other campaigns decrypt phishing HTML inside the browser and deliver it through a session-unique blob URL that blocklists cannot retrieve. The pages also disrupt content detection with Cyrillic lookalike characters, zero-width spaces and randomized strings embedded in &lt;code>&amp;lt;bdi&amp;gt;&lt;/code> elements, while remaining visually convincing to victims.&lt;/p>
&lt;p>
&lt;/p></description></item><item><title>Device Code-based OAuth Phishing</title><link>https://8759s.github.io/news/device-code-based-oauth-phishing/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://8759s.github.io/news/device-code-based-oauth-phishing/</guid><description>&lt;p>This active campaign abuses Microsoft&amp;rsquo;s legitimate device-code OAuth flow to capture application tokens instead of passwords. Victims interact with a real Microsoft sign-in page while the attacker&amp;rsquo;s infrastructure obtains the resulting token in the background.&lt;/p>
&lt;p>The phishing pages combine trusted authentication flows with obfuscated payloads, developer-tool detection and debugger traps. A captured OAuth token can provide application-level access to email, files and identity data without exposing the victim&amp;rsquo;s password.&lt;/p>
&lt;p>
&lt;/p></description></item><item><title>IOCs for phishing pages using blob URLs</title><link>https://8759s.github.io/news/iocs-for-phishing-pages-using-blob-urls/</link><pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate><guid>https://8759s.github.io/news/iocs-for-phishing-pages-using-blob-urls/</guid><description>&lt;p>Several active phishing campaigns use blob URLs to deliver their final pages. Rather than loading all malicious content over the network, the pages construct it dynamically in browser memory at runtime.&lt;/p>
&lt;p>This delivery method can reduce the visibility available to network-based analyzers and complicate conventional URL inspection.&lt;/p>
&lt;p>
&lt;/p></description></item></channel></rss>