๐ฅ TRENDING
๐ข Kali365-Phishing-Kit: Angreifer umgehen MFA seit April 2026 - Bรถrse Express
#Kali365-phishing-kit #Angreifer #April #Bรถrse #GlobalFeed #News #DE
*Automatisch gepostet von Global Feed Bot*
๐ฅ TRENDING
๐ข Kali365-Phishing-Kit: Angreifer umgehen MFA seit April 2026 - Bรถrse Express
#Kali365-phishing-kit #Angreifer #April #Bรถrse #GlobalFeed #News #DE
*Automatisch gepostet von Global Feed Bot*
This Week in Security: Ubiquiti Fixes, and FreeBSD Joins the Club you Donโt Want to Join
๐จ #๐๐ฎ๐น๐ถ๐ฏ๐ฒ๐ฑ ๐๐ฐ๐๐ถ๐๐ถ๐๐ ๐ฆ๐๐ฟ๐ด๐ฒ๐: ๐๐ฒ๐๐ถ๐ฐ๐ฒ ๐๐ผ๐ฑ๐ฒ ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐๐ ๐ฆ๐ฐ๐ฎ๐น๐ถ๐ป๐ด ๐๐ฎ๐๐
Weโre seeing a growing Device Code #phishing activity, with Kali365 emerging as one of the most active PhaaS. In the last 24 hours alone, #ANYRUN recorded 100+ related analysis sessions.
โ ๏ธ The attack abuses legitimate Microsoft device authentication flows. Victims are shown a user code and instructed to enter it into a real Microsoft device auth page, allowing attackers to capture OAuth access tokens instead of passwords. The risk shifts from credential theft to token abuse, while significantly reducing the number of traditional phishing indicators typically used for detection and triage.
โ๏ธ Deobfuscated Kali365 JavaScript revealed that after a verification gate, the lure deploys a phishing page, launches a legitimate Microsoft device authentication flow, and then polls /api/status/<session_id> for session states such as captured, expired, and declined.
๐ The code also contains lure-template generators for OneDrive, SharePoint, Teams, Outlook, and Voicemail, and a separate Google device-code authentication flow.
โก๏ธ #ANYRUN lets analysts safely reconstruct the flow, validate suspicious OAuth activity faster, and identify related phishing infrastructure before campaigns scale further, helping SOC teams reduce investigation time, improve detection accuracy, and lower MTTR.
๐จโ๐ป See the full phishing flow, validate detection logic, and collect #IOCs: https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoservice&utm_term=270526
๐ Track Kali365 activity using this TI Lookup search query: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktotilookup&utm_term=270526#%7B%2522query%2522:%2522threatName:%255C%2522kali365%255C%2522%2522,%2522dateRange%2522:7%7D%20
๐ Scale your SOCโs triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=kali365_activity_surges&utm_content=linktoplans&utm_term=270526
FBI warns of #Kali365 #phishing service targeting #Microsoft365 accounts

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
The whole industry has been screaming at you to enable MFA. Microsoft turned it into a mandate. So you complied. And now there's a subscription service selling access to exactly those "protected" accounts, using a legitimate Microsoft authentication flow they never bothered to retire.
https://blog.ppb1701.com/the-failsafe-that-isnt-microsofts-mfa-problem
#microsoft #microsoft365 #phishing #cybersecurity #mfa #kali365 #bigtechwaronusers #security #infosec #privacy #blog
๐ข Kali365 : une plateforme PhaaS vole les tokens OAuth Microsoft 365 et contourne le MFA
๐ ## ๐๏ธ Contexte
Le **21 mai 2026**, le FBI (Internet Crime Complaint Center) a publiรฉ une alerte publique (PSA nยฐ I-052126-PSA) concernant une nouvelle pl...
๐ cyberveille : https://cyberveille.ch/posts/2026-05-25-kali365-une-plateforme-phaas-vole-les-tokens-oauth-microsoft-365-et-contourne-le-mfa/
๐ source : https://www.ic3.gov/PSA/2026/PSA260521
#Device_Code_Flow #Kali365 #Cyberveille