Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Kali365 Exploits Microsoft Login to Threaten US Firms

Kali365 Exploits Microsoft Login to Threaten US Firms

Posted on August 5, 2026 By CWS

Kali365 is exploiting Microsoft authentication mechanisms, turning legitimate logins into a significant cyber threat for US enterprises. This phishing kit uses device codes controlled by attackers that victims inadvertently approve, allowing unauthorized access to sensitive corporate data, emails, and cloud services. This breach leads to potential financial fraud, data exposure, and operational challenges.

How Kali365 Operates

Designed to manipulate Microsoft authentication processes, Kali365 uses device code phishing to compromise US organizations. ANY.RUN’s telemetry indicates over 80 public sessions linked to these phishing campaigns weekly, with the US as a primary target. Typically, victims are lured with a SharePoint-themed page, leading them into the authentication process.

The attack unfolds in three phases: First, victims are presented with a page mimicking services like SharePoint or OneDrive. Then, they are redirected to Microsoft’s legitimate login page, where they enter a code provided by the attacker. Finally, upon successful authentication, attackers gain access and refresh tokens, allowing continued access to Microsoft 365 resources.

Implications for US Businesses

Once a device-code request is approved, it can lead to a broader compromise of Microsoft 365 accounts. For US companies, this risk can result in financial fraud through invoice manipulation, exposure of sensitive data, disruption of operations, and increased incident response costs. Additionally, companies face compliance and reputational risks if customer or regulated data is exposed.

Since the authentication occurs on a legitimate Microsoft page, the activity might initially seem routine, affording attackers more time to exploit access before detection.

Strategies to Mitigate Kali365 Risks

Addressing Kali365 requires more than email filtering; it necessitates updated threat intelligence, swift validation of suspicious activity, and strategic preparation for evolving threats. Security leaders should focus on expanding detection capabilities with fresh phishing intelligence, which can inform SIEM, SOAR, and other security measures.

ANY.RUN’s Interactive Sandbox provides detailed insights into the attack chain, offering AI summaries and evidence reports to aid in faster threat identification and response. Additionally, ongoing threat research allows organizations to stay ahead by monitoring campaign data and related infrastructure through ANY.RUN’s Threat Intelligence services.

Kali365 challenges the assumption that cloud authentication is inherently secure. Organizations must equip their SOCs to detect when legitimate login processes are manipulated, trace these activities, and contain threats before they impact critical business systems.

Using ANY.RUN, organizations have achieved faster threat triage, reduced mean time to resolution (MTTR), and lessened Tier 1 workloads, enhancing their capacity to respond to and contain identity-based threats effectively.

The Hacker News Tags:attack vectors, cloud security, cyber threat intelligence, Cybersecurity, data breach, incident response, Kali365, Microsoft, Phishing, US companies

Post navigation

Previous Post: Cyber Operations’ Expanding Influence in Global Conflicts
Next Post: Malware Exploits Passkey Systems in New Attack Methods

Related Posts

U.S. Sanctions 10 North Korean Entities for Laundering .7M in Crypto and IT Fraud U.S. Sanctions 10 North Korean Entities for Laundering $12.7M in Crypto and IT Fraud The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
FCC Restricts New Import of Foreign Routers Over Security Risks FCC Restricts New Import of Foreign Routers Over Security Risks The Hacker News
U.S. Dismantles DanaBot Malware Network, Charges 16 in M Global Cybercrime Operation U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation The Hacker News
Critical Security Updates Released for Major Software Critical Security Updates Released for Major Software The Hacker News
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark