Kali365 è passato da una nicchia di furto di token di Microsoft 365 a un servizio più ampio di compromissione degli account. Il cambiamento è importante perché lo stesso flusso di phishing con device-code che ruba una sessione M365 ora può essere usato contro identità cloud e IdP, quindi un problema di mailbox inizia ad assomigliare a un problema di cloud-admin.
CVSS 9.8 CRITICAL: a supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions… EPSS 15% (95º percentile).
Data di correzione federale CISA 30 mag · data superata
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.