惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Security

Exclusive: New Zealand’s Alpha Group Holdings allegedly hacked Trump Mobile confirms reports of customer data exposure, unsure whether to notify those impacted Op-Ed: Why CISOs are drowning in alerts but missing the real threat Exclusive: Marketing & merchandise firm Branded Products listed by Qilin ransomware Bank on it: AI-driven cyber crime is reshaping financial sector threats Alert! National Anti-Scam Centre and ASIC warns Aussies of fake crypto trading platforms Report: AI-driven exploitation beats phishing as most popular initial access strategy Exclusive: Victorian regional newspaper alleged hacked ransomware group Exclusive: Victorian regional newspaper allegedly hacked by ransomware group State Library of NSW responding to April cyber intrusion Over 50% of API banking attacks happen in Asia-Pacific, report finds Microsoft patches pair of Microsoft Defender zero-days following active exploitation EU wins global cybersecurity competition following digital partnership with Australia Report: Rapid7 warns AI-driven attacks are accelerating vulnerability exploitation Warning! Hackers spotted exploiting poorly patched SonicWall SSL VPN appliances 7-Eleven confirms cyber attack following ShinyHunters claims Busted! Vulnerability remediation is broken, a new report says Exclusive: US fintech firm OpenAI is using for linking bank accounts to ChatGPT discloses years-long cyber incident Thales and Google Cloud launch sovereign cloud operation in Germany Cyber fraud attacks up 17%, new findings reveal Australian Signals Directorate warns of device code phishing activity targeting Microsoft 365 users US banking regulators pause cyber exams for banks to allow Mythos patching Barracuda partners with CyberCert to simplify SMB1001 compliance for Australian SMEs Op-Ed: The reality of data-centric security and Attribute-based Access Control (ABAC) Exclusive: INC Ransom claims cyber attack on Australian engineering service company Op-Ed: To pay, or not to pay… That is the existential ransomware question Cyber Insurance for Small Business: When Getting Hacked Stops Everything Operation Ramz: INTERPOL arrests 201 in MENA region cybercrime operation Exclusive: Australian College of Business Intelligence investigating Qilin ransomware claims Exclusive: Major cleaning and facility services firm confirms third-party cyber incident Sentenced: 35-year-old Melbourne man jailed over phone porting scam Exclusive: Bluize confirms cyber incident, launches investigation US cyber agency warns of active exploitation of Microsoft Exchange Server spoofing vulnerability Three scammers charged following gold bullion purchase using scam profits Exclusive: Qilin ransomware group claims responsibility for Generation Life hack Exclusive: Hospitality IT provider allegedly breached by Qilin Exclusive: Tassie hospitality group confirms CMD Organization ransomware attack 80% of Aussies organisations face identity attacks, survey finds British Airways allegedly breached as hackers claim to have stolen pilot data Q&A with Adam Meyers: “It's going to be an absolute bloodbath.” Act now! Cisco patches ‘perfect 10’ Cisco Catalyst SD-WAN Controller vulnerability AI revolution? CVE disclosures jump by up to 500% for some vendors Report: Business email compromise attacks surged dangerously in April Kick-off! 2026 FIFA World Cup to be a prime target for scammers, cyber criminals Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian Federal Budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July Exclusive: Major Australian jewellery brand confirms cyber incident Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Exclusive: Prime Properties listed as breach victim by M3rx ransomware DigiCert launches AI Trust architecture to secure agents, models, and content Winners of the 2026 Australian Cyber Awards unveiled Op-Ed: Redefining performance in the AI-powered SOC NZ council cyber attack leads to ID and financial data being exposed Alert! Wave of fake toll, parking scams impacting countries worldwide, including Australia and New Zealand Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims Aussie ice-cream franchise Gelatissimo suffers alleged hack by DragonForce Anthropic Mythos: The model, the myth and the mundane​ Report: Aussie small businesses doing it tough as job scams double, losses rise Cyber attacks on medical devices pose ‘significant’ impact on real-life patient care Twisted Firestarter! Aussie, US, and UK cyber agencies warn of Cisco malware campaign Generation Life informs customers of “cyber incident” as owner shares incident with ASX CBA launches new scam-finding AI agent
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365 access tokens
david.hollin · 2026-05-27 · via Security

Law enforcement and experts express concern over a phishing service marketed via Telegram that “lowers the barrier to entry and enables rapid affiliate recruitment”.

The United States FBI has released a public service announcement (PSA) warning of a newly emerged phishing-as-a-service (PhaaS) platform: Kali365.

First observed in April 2026, the platform is marketed and distributed via the Telegram messaging service.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“Through the Kali365 platform subscription, cyber threat actors can capture ‘OAuth’ tokens and gain persistent access to targeted individuals/entities’ Microsoft 365 environments,” the FBI said in a 21 May PSA.

“Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.”

The scam works in four steps: an initial phishing email that appears to be from a “trusted cloud productivity and document-sharing service” that contains a device code and link to a legitimate Microsoft verification page, which in turn leads to the victim authorising the attacker’s device.

The attacker can then capture OAuth tokens, which grant them access to the victim’s Microsoft 365 services without needing a password or bypassing multifactor authentication challenges.

And while it is early days for the phishing platform, its popularity is steadily increasing.

“We’re observing gradual growth in activity alongside a clear expansion of underlying infrastructure. The threat actors are deploying new servers and access panels, which suggests the operation is maturing and scaling,” Steven Campbell, staff threat intelligence researcher at Arctic Wolf, told Cyber Daily.

“What’s particularly notable is the distribution model – Kali365 is being marketed through Telegram channels, which lowers the barrier to entry and enables rapid affiliate recruitment. This isn’t a single sophisticated group; it’s a commoditised capability that’s now accessible to less technical actors.”

Kali365, according to Campbell, is particularly dangerous because it can enable “advanced phishing operations” that lead to attacker-in-the-middle attacks, in which session tokens and credentials alike can be stolen. And because Kali365 uses legitimate Microsoft infrastructure, any activity appears normal to the victim.

“In practical terms, this means an attacker doesn’t need to build sophisticated tooling themselves,” Campbell said.

“They can stand up a campaign quickly and at scale. The platform provides AI-generated lures, automated campaign templates, and real-time dashboards for tracking compromised accounts.”

The FBI suggested several steps to defend against the toolkit:

  • Create a conditional access policy to block device code flow, with limited exceptions for essential processes.
  • Audit existing device code usage to identify legitimate dependencies.
  • Block authentication transfer policies to prevent users from transferring authentication to mobile devices.
  • If device code flow usage cannot be restricted, exclude emergency access accounts to prevent lockouts.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.