Before you continue

This Week in Security: Ubiquiti Fixes, and FreeBSD Joins the Club you Donโ€™t Want to Join

https://fed.brid.gy/r/https://hackaday.com/2026/05/29/this-week-in-security-ubiquiti-fixes-and-freebsd-joins-the-club-you-dont-want-to-join/

This Week In Security: Ubiquiti Fixes, And FreeBSD Joins The Club You Donโ€™t Want To Join

Ubiquiti released a new security bulletin detailing fixes for six security issues, including one rated 9.1 (critical) and one scoring a perfect 10.0 on the CVE risk scale. The vulnerabilities rangeโ€ฆ

Hackaday
Before you continue

๐Ÿšจ #๐—ž๐—ฎ๐—น๐—ถ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ถ๐˜๐˜† ๐—ฆ๐˜‚๐—ฟ๐—ด๐—ฒ๐˜€: ๐——๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—œ๐˜€ ๐—ฆ๐—ฐ๐—ฎ๐—น๐—ถ๐—ป๐—ด ๐—™๐—ฎ๐˜€๐˜
Weโ€™re seeing a growing Device Code #phishing activity, with Kali365 emerging as one of the most active PhaaS. In the last 24 hours alone, #ANYRUN recorded 100+ related analysis sessions.

โš ๏ธ The attack abuses legitimate Microsoft device authentication flows. Victims are shown a user code and instructed to enter it into a real Microsoft device auth page, allowing attackers to capture OAuth access tokens instead of passwords. The risk shifts from credential theft to token abuse, while significantly reducing the number of traditional phishing indicators typically used for detection and triage.

โ—๏ธ Deobfuscated Kali365 JavaScript revealed that after a verification gate, the lure deploys a phishing page, launches a legitimate Microsoft device authentication flow, and then polls /api/status/<session_id> for session states such as captured, expired, and declined.

๐Ÿ“Œ The code also contains lure-template generators for OneDrive, SharePoint, Teams, Outlook, and Voicemail, and a separate Google device-code authentication flow.

โšก๏ธ #ANYRUN lets analysts safely reconstruct the flow, validate suspicious OAuth activity faster, and identify related phishing infrastructure before campaigns scale further, helping SOC teams reduce investigation time, improve detection accuracy, and lower MTTR.

๐Ÿ‘จโ€๐Ÿ’ป See the full phishing flow, validate detection logic, and collect #IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoservice&utm_term=270526

๐Ÿ” Track Kali365 activity using this TI Lookup search query: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktotilookup&utm_term=270526#%7B%2522query%2522:%2522threatName:%255C%2522kali365%255C%2522%2522,%2522dateRange%2522:7%7D%20

๐Ÿš€ Scale your SOCโ€™s triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoplans&utm_term=270526

#cybersecurity #infosec

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).

BleepingComputer

The whole industry has been screaming at you to enable MFA. Microsoft turned it into a mandate. So you complied. And now there's a subscription service selling access to exactly those "protected" accounts, using a legitimate Microsoft authentication flow they never bothered to retire.

https://blog.ppb1701.com/the-failsafe-that-isnt-microsofts-mfa-problem

#microsoft #microsoft365 #phishing #cybersecurity #mfa #kali365 #bigtechwaronusers #security #infosec #privacy #blog

The Failsafe That Isn't: Microsoft's MFA Problem - ByteHaven - Where I ramble about bytes

Part of the ongoing Big Tech's War on Users series. The FBI issued a warning last week about a phishing-as-a-service platform called Kali365 that can...

โš ๏ธ Kali365 turns M365 phishing into a service The #FBI warns #Kali365 targets Microsoft 365 accounts, packaging credential theft for operators attacking cloud identity at scale. ๐Ÿ”— read more: www.infosecurity-magazine.com/news/fbi-kal... #ransomNews #cybersecurity
Kali365-Phishing-Dienst kompromittiert Microsoft 365-Konten durch Umgehung von MFA
Mehr: https://maniabel.work/archiv/1660
#Kali365, #Phishing #MFA #Microsoft365 #OAuth-Token #phishing-as-a-service #PhaaS
#up2date #BeDiS

๐Ÿ“ข Kali365 : une plateforme PhaaS vole les tokens OAuth Microsoft 365 et contourne le MFA
๐Ÿ“ ## ๐Ÿ›๏ธ Contexte

Le **21 mai 2026**, le FBI (Internet Crime Complaint Center) a publiรฉ une alerte publique (PSA nยฐ I-052126-PSA) concernant une nouvelle pl...
๐Ÿ“– cyberveille : https://cyberveille.ch/posts/2026-05-25-kali365-une-plateforme-phaas-vole-les-tokens-oauth-microsoft-365-et-contourne-le-mfa/
๐ŸŒ source : https://www.ic3.gov/PSA/2026/PSA260521
#Device_Code_Flow #Kali365 #Cyberveille