// Alert

Microsoft 365 threat report

Kali365, a phishing-as-a-service platform, is conducting a sustained campaign targeting US companies with device code phishing attacks against Microsoft 365 accounts. The attack abuses Microsoft's legitimate OAuth authentication flow to obtain access and refresh tokens without directly stealing passwords, enabling attackers to compromise corporate email, documents, and cloud services. Threat intelligence shows over 80 phishing sessions per week targeting US organizations across manufacturing, technology, healthcare, government, consulting, and managed service provider sectors.

// Get alerts for Microsoft 365