Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Read full story on The Hacker News
Share
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
AI disclosure

Summary

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.