Saturday 08 August 2026 12:41:40 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Kali365


When a Real Microsoft Login Becomes the Trap Door

Published: 05 August 2026 17:41Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit tied to Kali365 is abusing Microsoft’s device-code sign-in path, showing how legitimate authentication can be twisted into a cloud access problem.

When a Legitimate Microsoft Login Becomes the Attack

Published: 05 August 2026 10:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A reported campaign tied to Kali365 shows how Microsoft device login can be twisted into an OAuth token grab, turning an ordinary sign-in step into a cloud security problem for targeted U.S. firms.

Phishing Kits Are Learning to Borrow Trust, Not Just Brands

Published: 04 June 2026 13:39Category: Cloud, SaaS & Identity SecurityAuthor: SHADOWFIREWALL

Kali365 appears to be expanding a phishing playbook built around identity workflows, showing how token theft and login abuse can travel across very different services.

Phishing Kits Are Learning to Live on Stolen Sessions, Not Just Stolen Passwords

Published: 04 June 2026 10:22Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Kali365 is reported to have widened its targeting from Microsoft 365 token theft to Okta SSO and MAX Messenger, a sign that commoditized phishing is shifting toward reusable session abuse.

When a Real Microsoft Login Becomes the Trap

Published: 25 May 2026 18:36Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing service built around OAuth device code flow shows how attackers can turn a legitimate sign-in path into token theft, session hijacking, and MFA bypass.

When the Login Code Becomes the Weapon: Kali365 and the New Cloud Phish

Published: 25 May 2026 18:31Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing-as-a-service platform is turning Microsoft’s device-code sign-in into a turnkey path for token theft, session hijacking, and quieter cloud compromise.

When the Password Is Not the Prize: The Microsoft 365 Token Grab Hidden Inside Kali365

Published: 22 May 2026 12:29Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing kit linked to Telegram distribution is pushing attackers toward session theft, turning a successful sign-in into a longer-lived foothold inside cloud accounts.

When Login Flows Become the Payload: The New Microsoft 365 Phishing Trap

Published: 22 May 2026 10:08Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A reported phishing service named Kali365 points to a harder problem than stolen passwords: cloud identity abuse that can ride on legitimate OAuth and device-code sign-in paths.