I Found an MFA-Bypassing Phishing Attack on Microsoft 365

MediaVideo

https://jh.live/flare-kali365 || Manage threat intelligence and your exposed attack surface with Flare! Try a free trial and see what info is out there: https://jh.live/flare-kali365

Kali365 is a phishing-as-a-service kit that targets Microsoft 365 sessions and OAuth device authorization, letting criminals steal access tokens even when MFA succeeds. I trace the kit across public reporting and underground sources, unpack how the token theft works, and explain why defenders need session revocation and device-code controls, not MFA alone.

https://www.ic3.gov/PSA/2026/PSA260521?pubDate=20260525
https://www.huntress.com/blog/kali365-device-code-phishing-kit
https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/

Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training
See what else I’m up to with: https://jh.live/newsletter

ℹ️ Resources:
See what cybersecurity events are happening: https://jh.live/infosecmap
Learn how to code with CodeCrafters: https://jh.live/codecrafters
Host your own VPN with OpenVPN: https://jh.live/openvpn
Get Blue Team Training and SOC Analyst Certifications with CyberDefenders: https://jh.live/cyberdefense

#Cybersecurity #Phishing #Microsoft365John HammondRead More