#365


FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

May 25, 2026 // 19:17

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to […]

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

May 18, 2026 // 10:17

The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. Despite an international law enforcement operation […]

Authorities halt router attacks redirecting DNS to capture Microsoft 365 credentials.

Apr 7, 2026 // 18:57

An international effort involving law enforcement and private companies has stopped FrostArmada, an APT28 operation that hijacked local traffic from MikroTik and TP-Link routers to […]

OAuth abuse enables device code phishing attacks, impacting over 340 Microsoft 365 organizations across five countries.

Mar 25, 2026 // 14:43

Cybersecurity experts are raising awareness about an ongoing phishing scheme using device codes to compromise Microsoft 365 accounts in over 340 organizations across the U.S., […]