惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
博客园 - 司徒正美
博客园 - 【当耐特】
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
宝玉的分享
宝玉的分享
V
V2EX
S
SegmentFault 最新的问题
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
L
LangChain Blog
D
Docker
腾讯CDC

New York Post

Federal officials order flight cuts at Chicago O’Hare to reduce airport delays Minnesota dad who shoved Turning Point USA journalist at anti-ICE protest says family is 'absolutely not violent' Former adult film star Asia Carrera makes career turn after passing Texas bar exam to become attorney Boy, 13, stabbed with large knife during suspected dispute near NYC park Over 200 swarm Atlanta intersection in illegal street takeover roaring with cars racing and doing donuts Yankees' Aaron Boone blasts 'overly sensitive' umpires after first ejection of season Stream It Or Skip It: 'Fake Profile' Season 3 On Netflix, Another Crazy Season Of The Steamy Colombian Thriller Eastbound 105 Freeway reopens hours after man shot as mystery deepens around what happened Tony Bradley believes Hawks need to hit Knicks 'in the mouth first' A quiet change at a Sacramento school is raising concerns among parents Washington state teacher flashed topless pics to class full of students during PowerPoint presentation Knicks looking to push NBA-best clutch success to its limit in playoffs Stream It Or Skip It: 'Beef' Season 2 On Netflix, Where A Young Couple Take On Their Boss And His Wife When They Witness A Vicious Argument Footage shows D4vd arrested surrounded by gun-wielding cops Acting ICE Director Todd Lyons resigns after 20 years with agency -- will stay on for transition 'Proof' review: Ayo Edebiri and Don Cheadle star in underpowered Broadway revival Federal authorities issue warning after multiple drone sightings above Coors Field Ohio State dominant school at receiver with latest star set for NFL draft 'The Pitt' Season 2 Ending Explained: Does Baby Jane Doe Save Dr. Robby? SoCal man's bittersweet reunion with stolen 1969 Camaro caught on camera Dem rising star boasts about Fed experience -- but record tells different story Luka Doncic spotted in Europe at Real Madrid basketball game with tennis superstar Pregnant Aubrey Plaza flaunts her baby bump in floral minidress at NYC screening ‘The Pitt’ Season 2 Episode 15 Recap: 100 Percent F**ked Up (Season 2 Finale) ‘Shahs of Sunset’ star Mercedes ‘MJ’ Javid reveals how she found a fresh start amid divorce Deonte Banks gets Giants 'clean slate' at critical point in his NFL career Mets can't hide behind the numbers — they're feeling the pressure Tiffany & Co. Blue Book 2026 launch: Mariah Carey, Naomi Watts, Teyana Taylor and more Hannah Einbinder Couldn't Stop Bawling While Jesse McCartney Was On Set Filming 'Hacks' Episode 2: "I Cried Every Single Take" The PGA Tour reunions that must happen with LIV Golf on life support
FBI sounds alarm on phishing tool that steals Microsoft 3...
Ariel Zilber · 2026-05-28 · via New York Post

The FBI is warning that a new hacking platform is allowing cybercriminals to hijack Microsoft 365 accounts — including Outlook, Teams and OneDrive — while bypassing multi-factor authentication entirely.

The bureau posted a public service announcement last week sounding the alarm about the “Phishing-as-a-Service” toolkit known as Kali365, which is being used to steal Microsoft 365 access tokens and gain entry to victim accounts without intercepting passwords.

The feds say that Kali365 makes it easy for even amateur hackers to run advanced phishing scams that used to require serious technical skills.

The FBI is warning that cybercriminals are using a new phishing platform called Kali365 to hijack Microsoft 365 accounts and bypass multi-factor authentication.

The FBI is warning that cybercriminals are using a new phishing platform called Kali365 to hijack Microsoft 365 accounts and bypass multi-factor authentication. Shutterstock / Minerva Studio

“Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI warned.

The scheme exploits Microsoft’s legitimate OAuth 2.0 “device code” authentication system — a feature commonly used to log into smart TVs, streaming devices and other hardware with limited keyboards.

Rather than stealing passwords directly, attackers trick victims into entering a code on a real Microsoft login page, unknowingly authorizing the hacker’s device.

“The device code flow is a legitimate authentication method that is being actively exploited by cybercriminals to bypass multi-factor authentication,” the FBI said in its advisory.

“By tricking users into entering a device code on a legitimate Microsoft page, attackers can gain persistent access to accounts without ever needing the user’s credentials.”

Victims receive phishing emails impersonating services like SharePoint, OneDrive or Microsoft Teams.

Attackers using the Kali365 phishing toolkit can gain long-term access to Outlook, Teams and OneDrive accounts.

Attackers using the Kali365 phishing toolkit can gain long-term access to Outlook, Teams and OneDrive accounts. picsmart – stock.adobe.com

The emails instruct targets to visit Microsoft’s legitimate device login page and enter a short-lived authentication code.

Once the victim completes the process and passes MFA checks, Microsoft issues valid OAuth access and refresh tokens directly to the attacker.

That allows hackers to access Outlook inboxes, Teams accounts and cloud-stored files without ever needing the victim’s password again.

The FBI warned that attackers can maintain persistent access to accounts until the stolen tokens are manually revoked.

Matt Burk, chief information security officer at Bespoke Concierge MD, told The Post the attacks have become increasingly effective because Microsoft’s widespread enforcement of multi-factor authentication has forced cybercriminals to adapt.

Federal investigators warned that victims are being tricked into authorizing hackers through legitimate Microsoft device-login pages.

Federal investigators warned that victims are being tricked into authorizing hackers through legitimate Microsoft device-login pages. FellowNeko – stock.adobe.com

“Since Microsoft has globally enforced MFA, this method of cyber attack is designed to bypass MFA and the need for a password,” he said.

Asked which industries or employees are most vulnerable, Burk warned that virtually anyone using Microsoft 365 could be targeted.

“I absolutely hate to generalize, but everyone from a small mom-and-pop business to a large Fortune 500 company,” he said.

Burk added that organizations should deploy third-party Security Information and Event Management, or SIEM, systems capable of detecting suspicious authentication activity tied to token theft.

“Using these tools can detect access like the Kali365 exploit and with the correct security features can automatically shut down the connection,” he said.

Ordinary users should take the threat seriously because the attacks target cloud-based computing platforms used daily by businesses and consumers alike, according to the expert.

“Everybody should be concerned with this exploit,” Burk said.

Cybersecurity researchers say the emergence of Kali365 marks a major escalation in the growing “phishing-as-a-service” underground economy, where sophisticated attack tools are sold to low-skilled criminals via subscription services on Telegram and dark web forums.

The bureau said Kali365 was first observed last month and has rapidly spread among cybercriminal groups.

The platform automates phishing campaigns and provides dashboards that allow attackers to monitor victims in real time.

Federal authorities said the operation is part of a broader wave of attacks targeting Microsoft 365 environments globally.

Scattered Spider, also known as Octo Tempest, is a notorious English-speaking cybercrime group known for aggressive social engineering and SIM-swapping attacks targeting large corporations.

Another entity, Storm-2949, has focused on compromising IT administrators and senior executives through abuse of Microsoft password reset systems and cloud authentication tools.

The Post has sought comment from Microsoft.