← Front PageThreat Intel Desk
Threat Intel
FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks
Kali365 phishing service exploits OAuth token persistence to maintain Microsoft 365 access despite password changes and MFA implementations.
Summary written by editorial AI · Source link below
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.
Continue at the source
Read the full report at The RecordExternal link — opens at The Record in a new tab.
§
Continue with
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul