HackerFeeds

CyberSecurity News

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

The Hacker News
· August 5, 2026

AI summary

Kali365 is exploiting a legitimate Microsoft login process to gain access to corporate data of US companies. The phishing kit uses attacker-controlled device codes that are approved by victims on Microsoft's actual authentication page. This allows attackers to obtain access and refresh tokens, which can be used to access email, documents, and cloud resources. As a result, attackers may be able to retain access to sensitive data, potentially leading to data exposure and financial fraud. The attack creates a direct pathway for attackers to compromise corporate systems and data.

Read the full article at The Hacker Newsthehackernews.com/2026/08/kali365-weaponizes-microsoft.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.