← Front PageThreat Intel Desk
Threat Intel
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
Kali365 phishing service exploits OAuth token persistence to maintain Microsoft 365 access despite password changes and MFA implementations.
Summary written by editorial AI · Source link below
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.
Continue at the source
Read the full report at The RecordExternal link — opens at The Record in a new tab.
§
Continue with
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d