phishing
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required
High
Summary
The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow, exploiting a legitimate Microsoft feature to gain unauthorized access. The attacks have been observed across North America and Europe, highlighting the vulnerability of organizations relying on MFA alone.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data