Sunday , September 27 2026
Kali365

FBI alerts on Kali365 phishing targeting Microsoft 365 accounts

The FBI warns about the Kali365 phishing platform (PhaaS). It is used to take over Microsoft 365 accounts by misusing OAuth device code authentication to steal session tokens and get around multi-factor authentication (MFA).

Kali365 appeared in April 2026, as per the FBI PSA. It is shared through Telegram channels aimed at cybercriminals looking for a simpler method to access Microsoft 365 accounts without taking passwords or capturing MFA codes.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

The platform uses device code phishing. This is a method that misuses Microsoft’s real OAuth 2.0 Device Authorization process to get into Microsoft Entra and Microsoft 365 accounts.

This login method lets devices that can’t type much, like smart TVs, conference systems, streaming boxes, printers, and IoT devices, log in using a short code from another device at Microsoft’s login page, http://microsoft.com/devicelogin.

In these attacks, bad actors start the device authorization process to make a code and then fool targets into putting it on Microsoft’s login page using phishing and trickery.

Once the victim inputs the code and finishes MFA, Microsoft gives an OAuth access token. This token allows the threat actor full access to the account without needing to solve any MFA challenges.

The bad actors now can access all the apps the user usually can through their single-sign-on account. This includes Microsoft 365, Salesforce, and other cloud services, which they use to steal data.

The FBI says that Kali365 lets even inexperienced hackers use powerful phishing tools. These include fake messages created by AI, ready-made campaign plans, dashboards to track victims in real time, and ways to capture tokens.

Security experts at Arctic Wolf talked about Kali365 actions in April. They noticed a large campaign that was hitting groups all over the world.

The researchers said that the campaigns mainly focused on Microsoft 365 using phishing emails. These emails led victims to a Microsoft login page, where they unknowingly let attackers into their accounts.

The researchers said the resulting attacks gave the hackers access to their mailboxes, where they created malicious inbox rules designed to hide their activity.

Tips to Protect:

Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack.
Create a conditional access policy to block device code flow for all users, with limited exceptions for required business processes.
Audit existing device code flow usage to identify legitimate dependencies before creating a conditional access policy.
Block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices.

Check Also

Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known …