news.mlab.sh
Back to the feed
phishing

FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required

High
Summary

The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow, exploiting a legitimate Microsoft feature to gain unauthorized access. The attacks have been observed across North America and Europe, highlighting the vulnerability of organizations relying on MFA alone.

Read the full article at Graham Cluley

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.