The FBI has put out a warning about Kali365 and the spike in device code phishing attacks earlier this week:
Through the Kali365 platform subscription, cyber threat actors can capture “OAuth” tokens and gain persistent access to targeted individuals/entities’ Microsoft 365 environments. Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.
But the deeper story is why this class of attack is so hard to catch. There’s no malicious link, no spoofed login page — just a legitimate OAuth flow handing attackers a valid token, bypassing everything traditional security is trained to flag.
Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment:
“The FBI’s warning is well-placed, and the recommended mitigations — conditional access policies, blocking device code flows — are the right first response. But they address the front door.
The harder question is what happens once an attacker is already inside a legitimate session. When a token is stolen, the attacker isn’t a stranger to the system anymore. They’re operating with valid credentials through authorized pathways. Traditional controls see a clean session. They don’t see intent.
That gap gets wider as AI enters the picture. Copilots and agents connected to M365 mean a compromised session isn’t just access to stored data — it’s a potential entry point into ongoing AI workflows, retrieval pipelines, and generated outputs that can surface sensitive information in ways that are much harder to detect.
The industry conversation tends to stop at authentication. It needs to extend to the data layer — what’s actually moving through these systems, what it contains, who it’s about, and whether that movement aligns with policy intent. Because by the time data is in motion, the authentication question has already been answered. Correctly or not.”
As mentioned, this technique is particularly dangerous because it exploits legitimate authentication workflows, making detection more difficult. Thus the mitigations that are recommended are vital to keeping your organization safe.
FBI, Google And Black Lotus Labs Take Down Chinese Based Phishing As A Service Operation
Posted in Commentary with tags Black Lotus, FBI, Google on June 15, 2026 by itnerdIt has been reported that in a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
You can find the full story here: https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“Outsider Enterprise was dismantled, but no one was arrested, and only a hundred thousand dollars was recovered out of the billions it stole. What’s notable here is that there was no involvement with Chinese authorities. Until we have stronger international cooperation and enforcement, nothing is stopping these scammers from rebuilding and committing more crimes. This is especially true for adversarial countries like China and Russia, from which we cannot extradite criminals. Scammers and other cybercriminals can operate from those countries with impunity, so long as they don’t attack domestic targets.”
While this is positive, there needs to be much more of this sort of thing. This has to be unprofitable for threat actors, which will make them stop what they’re doing.
Leave a comment »