Kali365 Phishing Kit Bypasses MFA to Target Microsoft 365 Accounts

TL;DR Summary
The FBI warns of Kali365, a phishing-as-a-service kit that bypasses multi-factor authentication by tricking victims into approving a device-code sign-in, enabling attackers to harvest OAuth tokens and access Outlook, Teams, and OneDrive; security guidance includes never entering unsolicited device codes, navigating directly to Microsoft rather than using links, monitoring sign-ins and devices, revoking suspicious sessions, keeping MFA enabled, and reporting incidents.
- FBI warns Microsoft users about passwordless scam Fox News
- Why phishing attacks are suddenly getting much harder to spot Axios
- EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps CyberSecurityNews
- 'Organised crime operating like a tech startup': EvilToken PHaaS group ramp up AI-enabled attacks by 1,380% in 2026 TechRadar
- AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete IT Security Guru
Reading Insights
Total Reads
1
Unique Readers
25
Time Saved
13 min
vs 13 min read
Condensed
98%
2,580 → 61 words
Want the full story? Read the original article
Read on Fox News