A phishing kit tied to Kali365 is abusing Microsoft’s device-code sign-in path, showing how legitimate authentication can be twisted into a cloud access problem.
A described campaign ties hostile Wi-Fi conditions to a Microsoft login flow that can turn ordinary user approval into cloud access, showing why identity controls now matter as much as network trust.
A reported campaign tied to public Wi-Fi gateways shows how a wireless foothold in hospitality can turn into stolen Microsoft logins and cloud exposure.
AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.
The reported kit blends a brand clone, a Turnstile checkpoint, and bare PHP endpoints into a compact phishing pipeline built to collect enterprise logins.
A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.
A fast-moving phishing kit is being watched as it shifts from early testing to live deployment, with Microsoft sign-ins in its sights and proxy-style attacks at the center of the risk.