Security Feed
  1. Archives

May 25 2026 FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

Source

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]

Posted by Lawrence Abrams on Mon 25 May 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Microsoft
  • Security Blog
  • Biz & IT
  • AI
  • Security & Identity
  • CryptoCurrency
  • google
  • Announcements
  • Artificial Intelligence
  • Foundational (100)
  • Legal
  • A Little Sunshine
  • Privacy
  • Apple
  • squid
  • Mobile
  • Hacking
  • Intermediate (200)
  • Advanced (300)
  • LLM
  • Technical How-to
  • vulnerabilities

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.