Topic: conditional access policies

  • FBI warns of Kali365 phishing threat to Microsoft 365 accounts

    FBI warns of Kali365 phishing threat to Microsoft 365 accounts

    The FBI warns about Kali365, a phishing-as-a-service platform that targets Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). Kali365 enables low-skilled attackers with AI-generated phishing lures, automated cam...

    Read More »
  • Device Code Phishing Attacks Jump 37x with New Kits

    Device Code Phishing Attacks Jump 37x with New Kits

    A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for hardware to hijack accounts and bypass multi-factor authentication. The primary driver is the EvilTokens phishing-as-a-service kit, with at least 11 distinct kits now a...

    Read More »
  • Microsoft 365 Users Targeted by EvilTokens Device Code Phishing

    Microsoft 365 Users Targeted by EvilTokens Device Code Phishing

    A new phishing-as-a-service toolkit called EvilTokens is enabling a surge in sophisticated device code phishing attacks against Microsoft 365 accounts, bypassing traditional security like multi-factor authentication. The attack exploits a legitimate Microsoft device authentication feature, tricki...

    Read More »
  • Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Attackers are exploiting Microsoft's device code authorization flow to bypass multi-factor authentication, tricking users into granting account access via fraudulent login portals. The campaigns are scaled using readily available red team tools like Squarephish and Graphish, which automate phishi...

    Read More »