Wednesday , August 26 2026
Kali365

FBI alerts on Kali365 phishing targeting Microsoft 365 accounts

The FBI warns about the Kali365 phishing platform (PhaaS). It is used to take over Microsoft 365 accounts by misusing OAuth device code authentication to steal session tokens and get around multi-factor authentication (MFA).

Kali365 appeared in April 2026, as per the FBI PSA. It is shared through Telegram channels aimed at cybercriminals looking for a simpler method to access Microsoft 365 accounts without taking passwords or capturing MFA codes.

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

The platform uses device code phishing. This is a method that misuses Microsoft’s real OAuth 2.0 Device Authorization process to get into Microsoft Entra and Microsoft 365 accounts.

This login method lets devices that can’t type much, like smart TVs, conference systems, streaming boxes, printers, and IoT devices, log in using a short code from another device at Microsoft’s login page, http://microsoft.com/devicelogin.

In these attacks, bad actors start the device authorization process to make a code and then fool targets into putting it on Microsoft’s login page using phishing and trickery.

Once the victim inputs the code and finishes MFA, Microsoft gives an OAuth access token. This token allows the threat actor full access to the account without needing to solve any MFA challenges.

The bad actors now can access all the apps the user usually can through their single-sign-on account. This includes Microsoft 365, Salesforce, and other cloud services, which they use to steal data.

The FBI says that Kali365 lets even inexperienced hackers use powerful phishing tools. These include fake messages created by AI, ready-made campaign plans, dashboards to track victims in real time, and ways to capture tokens.

Security experts at Arctic Wolf talked about Kali365 actions in April. They noticed a large campaign that was hitting groups all over the world.

The researchers said that the campaigns mainly focused on Microsoft 365 using phishing emails. These emails led victims to a Microsoft login page, where they unknowingly let attackers into their accounts.

The researchers said the resulting attacks gave the hackers access to their mailboxes, where they created malicious inbox rules designed to hide their activity.

Tips to Protect:

Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack.
Create a conditional access policy to block device code flow for all users, with limited exceptions for required business processes.
Audit existing device code flow usage to identify legitimate dependencies before creating a conditional access policy.
Block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices.

Check Also

Bdjobs

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell …