Observed Signal · May 28, 2026 · Security Advisory · Source: t3n · Impact: 3/5 · Sentiment: Negative
FBI warns Microsoft 365 users about Kali365 phishing
The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.
A government security advisory highlights a new PhaaS that captures OAuth tokens and can bypass MFA for Microsoft 365 — a meaningful identity/security risk for many organizations and SaaS platforms.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- FBI issued a public advisory warning about the Kali365 phishing platform targeting Microsoft 365 users.
- Kali365 was first observed by the FBI in April and is circulated notably via Telegram.
- The platform facilitates Phishing-as-a-Service (PhaaS) that harvests OAuth access and refresh tokens through a device-code flow.
- Attackers using stolen tokens can access Microsoft 365 services (Outlook, Teams, OneDrive) without passwords or MFA checks.
- The FBI recommends restricting the OAuth device-code flow and blocking unnecessary device-code token issuance.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions
Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.
Microsoft warns against SMS-based 2FA over AI phishing
Microsoft has warned IT administrators that SMS- and voice-based two-factor authentication (2FA) are increasingly vulnerable due to AI-assisted phishing and easier SIM-swapping. In an internal email, the company recommended migrating to phishing-resistant methods such as passkeys. Microsoft said it has observed a strong rise in AI-driven attacks with higher click-through rates that aim to capture passwords and MFA codes. As a consequence, Microsoft will disable SMS- and voice-based authentication for Entra ID accounts starting February 1, 2027; a timeline for personal Microsoft accounts has not yet been announced.
LinkedIn Malware Warning: Security Advice for Employers and Jobseekers
The article warns LinkedIn users—both employers and jobseekers—to treat messages with caution, even from known contacts that may be compromised. It recommends verifying job opportunities outside LinkedIn, avoiding any job offers that require downloading or executing files, and recognising that familiar services (e.g., Google, Dropbox) or trusted domains do not guarantee safety. Users should regularly review and terminate unfamiliar active sessions in LinkedIn settings and treat distant or anomalous logins as signs of account compromise. The piece advises enabling multi-factor authentication (ideally using hardware security keys) and notes LinkedIn supports software passkeys. If compromise is suspected, users should reset passwords and revoke all sessions.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
