The FBI warns Microsoft 365 services are being bombarded with new phishing emails — here are 3 steps you can take…

https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-2560-80.jpg

The FBI has warned of a new Phishing-as-a-Service (PhaaS) kit that is targeting Microsoft 365 accounts in a complex but easily accessible campaign.

The Kali365 PhaaS service allows hackers to gain persistent access to Microsoft 365 environments by stealing ‘OAuth’ tokens using AI-generated phishing emails that direct users to legitimate Microsoft verification pages.

Once the attacker holds the OAuth token, they can access Outlook, Teams, and OneDrive services without having to complete any additional verification or authentication mechanisms.

Phishing campaigns such as these rely on human-error in order to breach accounts, but luckily there are multiple steps to take to keep accounts and wider Microsoft 365 environments safe. Here are 3 ways businesses can protect themselves against the Kali365 PhaaS campaign:

1. Phishing Vigilance

Phishing emails come in a range of formats. They can be interview invites, document access requests, and everything in between. Hackers are using AI tools to...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more