A phishing kit tied to Kali365 is abusing Microsoft’s device-code sign-in path, showing how legitimate authentication can be twisted into a cloud access problem.
A reported campaign tied to Kali365 shows how Microsoft device login can be twisted into an OAuth token grab, turning an ordinary sign-in step into a cloud security problem for targeted U.S. firms.
Kali365 appears to be expanding a phishing playbook built around identity workflows, showing how token theft and login abuse can travel across very different services.
Kali365 is reported to have widened its targeting from Microsoft 365 token theft to Okta SSO and MAX Messenger, a sign that commoditized phishing is shifting toward reusable session abuse.
A phishing service built around OAuth device code flow shows how attackers can turn a legitimate sign-in path into token theft, session hijacking, and MFA bypass.
A phishing-as-a-service platform is turning Microsoft’s device-code sign-in into a turnkey path for token theft, session hijacking, and quieter cloud compromise.
A phishing kit linked to Telegram distribution is pushing attackers toward session theft, turning a successful sign-in into a longer-lived foothold inside cloud accounts.
A reported phishing service named Kali365 points to a harder problem than stolen passwords: cloud identity abuse that can ride on legitimate OAuth and device-code sign-in paths.