<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Identity Security on Juan Carlos Munera</title><link>https://cybersecpro.me/tags/identity-security/</link><description>Recent content in Identity Security on Juan Carlos Munera</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Juan Carlos Munera</copyright><lastBuildDate>Mon, 06 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybersecpro.me/tags/identity-security/index.xml" rel="self" type="application/rss+xml"/><item><title>MFA Won't Save You: How Device Code Phishing Bypasses Your Strongest Authentication</title><link>https://cybersecpro.me/posts/device-code-phishing-mfa-bypass/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/device-code-phishing-mfa-bypass/</guid><description>Device code phishing has gone from a niche state-sponsored technique to a commoditized attack with at least 11 phishing kits and a 37x surge in 2026. The attack abuses the legitimate OAuth 2.0 Device Authorization Grant flow, routes victims through real Microsoft login pages, and bypasses MFA entirely. What practitioners need to understand.</description></item></channel></rss>