Tuesday , August 4 2026
Kali365

FBI alerts on Kali365 phishing targeting Microsoft 365 accounts

The FBI warns about the Kali365 phishing platform (PhaaS). It is used to take over Microsoft 365 accounts by misusing OAuth device code authentication to steal session tokens and get around multi-factor authentication (MFA).

Kali365 appeared in April 2026, as per the FBI PSA. It is shared through Telegram channels aimed at cybercriminals looking for a simpler method to access Microsoft 365 accounts without taking passwords or capturing MFA codes.

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

The platform uses device code phishing. This is a method that misuses Microsoft’s real OAuth 2.0 Device Authorization process to get into Microsoft Entra and Microsoft 365 accounts.

This login method lets devices that can’t type much, like smart TVs, conference systems, streaming boxes, printers, and IoT devices, log in using a short code from another device at Microsoft’s login page, http://microsoft.com/devicelogin.

In these attacks, bad actors start the device authorization process to make a code and then fool targets into putting it on Microsoft’s login page using phishing and trickery.

Once the victim inputs the code and finishes MFA, Microsoft gives an OAuth access token. This token allows the threat actor full access to the account without needing to solve any MFA challenges.

The bad actors now can access all the apps the user usually can through their single-sign-on account. This includes Microsoft 365, Salesforce, and other cloud services, which they use to steal data.

The FBI says that Kali365 lets even inexperienced hackers use powerful phishing tools. These include fake messages created by AI, ready-made campaign plans, dashboards to track victims in real time, and ways to capture tokens.

Security experts at Arctic Wolf talked about Kali365 actions in April. They noticed a large campaign that was hitting groups all over the world.

The researchers said that the campaigns mainly focused on Microsoft 365 using phishing emails. These emails led victims to a Microsoft login page, where they unknowingly let attackers into their accounts.

The researchers said the resulting attacks gave the hackers access to their mailboxes, where they created malicious inbox rules designed to hide their activity.

Tips to Protect:

Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack.
Create a conditional access policy to block device code flow for all users, with limited exceptions for required business processes.
Audit existing device code flow usage to identify legitimate dependencies before creating a conditional access policy.
Block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices.

Check Also

water

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks …