Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
thehackernews.com Aug 5, 2026

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

AI-summarised brief · reviewed before publication

Kali365 exploits Microsoft’s device‑code authentication to turn legitimate login pages into phishing gateways for U.S. companies. The kit lures victims with spoofed SharePoint, OneDrive, or DocuSign pages, then redirects them to Microsoft’s real login portal where an attacker‑supplied code is entered. Successful authentication grants attackers access and refresh tokens for Microsoft 365 email, documents, and cloud resources, enabling prolonged data exposure and fraud. Over 80 public sessions are recorded weekly, with U.S. organizations as the primary target.

💡 Why It Matters

  • · The attack bypasses traditional email filters, turning routine authentication into a covert breach that can spread quickly across an organization’s cloud assets.
  • · Rapid detection and contextual threat intelligence are essential to prevent a single compromised account from escalating into a widespread incident.