CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3887

As cited

Copy frozen at (site build).

threat intel

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is a phishing kit that tricks US organizations into approving attacker-controlled device codes through legitimate Microsoft authentication pages. Once victims authorize the code, attackers obtain access and refresh tokens that grant persistent access to email, documents, and cloud resources. The attack exploits the trust users place in Microsoft's real authentication interface to compromise corporate data and systems.

Why it matters: US companies face direct credential compromise and persistent cloud access loss; security teams should monitor for unusual device code approvals and educate users on suspicious authentication requests.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is a phishing kit that tricks US organizations into approving attacker-controlled device codes through legitimate Microsoft authentication pages. Once victims authorize the code, attackers obtain access and refresh tokens that grant persistent access to email, documents, and cloud resources. The attack exploits the trust users place in Microsoft's real authentication interface to compromise corporate data and systems.

Why it matters: US companies face direct credential compromise and persistent cloud access loss; security teams should monitor for unusual device code approvals and educate users on suspicious authentication requests.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary