The briefing
The FBI has flagged a phishing-as-a-service operation, dubbed Kali365, that uses AI-generated emails and legitimate-looking Microsoft verification pages to steal OAuth tokens. With token access, attackers can pivot into Outlook, Teams, and OneDrive without traditional login hurdles, enabling persistent access to corporate environments.
Original headline
The FBI warns Microsoft 365 services are being bombarded with new phishing emails — here are 3 steps you can take to stay safe