How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

The Illicit Consent Grant Part 2: Device-Code Phishing and the AI PhaaS Wave

calendar_today July 15, 2026 person SlashID Team, Vincenzo Iozzo domain slashid

Part 1 showed the illicit consent grant done by hand. Part 2 shows its close cousin — device-code phishing — now sold as a ready-made kit, with AI writing the lures and reading the stolen mailbox. We analyze two Phishing-as-a-Service platforms, EvilTokens and the FBI-flagged Kali365, walk the device-code attack through the same three phases from Part 1, and share what a sandboxed reconstruction taught us — then map detection and mitigation to the SlashID identity layer.

open_in_new Read original post