discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI says Kali365 uses device-code phishing to hijack Microsoft 365 accounts and bypass MFA.

By Lawrence Abrams·May 25·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
Image: bleepingcomputer.com

Kali365 sells low-skill attackers a ready-made way to break into Microsoft 365 and Entra accounts by abusing OAuth device-code logins. The FBI says it can capture tokens, hide activity, and extend access through inbox rules and new device registrations.

Why it matters

This is a scalable phishing service aimed at widely used business accounts, so the risk is not limited to one campaign or one victim. It also shows that MFA alone does not stop attacks when the login flow itself is abused.

Kali365 is like a crime kit sold to people who want to break into email accounts. Instead of stealing a key, it tricks a person into opening the door for them.

The trick uses a real Microsoft login page and a short code. If the person enters the code and finishes the extra safety check, the attacker gets a pass that works like a copied wristband at an event.

The FBI says companies should block this kind of login when possible and watch for strange sign-ins or new devices. That can help stop the thief even after the trick has started.

Analysis

What the FBI says

The FBI warns that Kali365 is a phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing OAuth device-code authentication. According to the FBI PSA, the service first appeared in April 2026 and is promoted through Telegram channels to criminals who want an easier path into Microsoft accounts without needing passwords or MFA codes.

How the attack works

The core trick is device-code phishing. Attackers start the Microsoft device authorization flow themselves, generate a code, and then send the victim to the legitimate Microsoft login page to enter it. If the victim completes the login and MFA prompt, Microsoft issues an OAuth token that gives the attacker access to the account session. That means the attacker can reach the same cloud apps the user can, including Microsoft 365 and other connected SaaS services.

Why Kali365 stands out

The FBI says Kali365 packages this into a service with features aimed at lower-skill operators, including AI-generated phishing lures, campaign templates, victim-tracking dashboards, and token capture. Arctic Wolf reported similar activity in April after seeing campaigns that targeted Microsoft 365 users with emails leading them to the device-code login portal. In those cases, attackers gained mailbox access, created inbox rules to hide their activity, and sometimes registered new devices for longer-term access.

Broader trend and response

Arctic Wolf described Kali365 as an organized business with admins, resellers, and affiliates. The platform also offers an adversary-in-the-middle mode called Cookie Link, which proxies victims through attacker-controlled infrastructure to capture authenticated sessions, cookies, and tokens. The FBI recommends restricting or blocking device-code authentication with Conditional Access where possible, auditing device-code usage, and blocking authentication transfer policies. It also urges reporting incidents to the IC3 and preserving phishing emails, suspicious logins, and unauthorized device registrations.

Key points

  • The FBI says Kali365 is a phishing-as-a-service platform aimed at Microsoft 365 and Entra accounts.
  • It abuses OAuth device-code authentication to steal session tokens and bypass MFA.
  • The service is distributed through Telegram and appears designed for low-skill attackers.
  • Arctic Wolf reported campaigns that used the method to access mailboxes, hide activity, and add devices.
  • The FBI recommends restricting device-code authentication, auditing its use, and reporting incidents to the IC3.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechpolicyglobal-news

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

May 25, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechpolicyglobal-news

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…