SECURITY

https://cdn.mos.cms.futurecdn.net/CT482eMSRL8PagRtuBVYNd-2000-80.jpeg

TECH NEWS

FBI warns of Kali phishing scam hitting Microsoft OAuth tokens — warns 'Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures'

* FBI flags Kali365, a phishing kit sold on Telegram which steals Microsoft 365 OAuth tokens and bypasses MFA * Victims are tricked into entering device codes on legitimate Microsoft pages, unknowingly authorizing attacker access to Outlook, Teams, and OneDrive * Mitigation steps include restricting device code flow, enforcing conditional access policies, auditing