FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
2026-05-25T13:23:33Z•81cf0cedaffe430e64dcfbe6c727d5c88dab007d32942a3a386b777f4251a5eb
Apex OneCINEMAGOALClickFixComposerDDoSDrupalGhost CMSKali365KimWolfLaravel LangMFA bypassMicrosoft 365OAuth device codeSQL injectionTrend MicroUbiquiti UniFi OSbotnetcredential stealerhosting abuselaw enforcement takedownphishing-as-a-servicepiracyserver seizuresupply chainzero-day
What happened
Multiple active and high-impact security incidents reported: the FBI warns of Kali365 phishing-as-a-service abusing OAuth device code flow to steal Microsoft 365 session tokens and bypass MFA; Ghost CMS is being exploited via a critical SQL injection (CVE-2026-26980) to deliver ClickFix attack chains; Laravel Lang Composer packages were hijacked to distribute credential-stealing malware; Trend Micro disclosed an Apex One zero-day being exploited in the wild and Drupal is seeing active targeting of a critical SQL injection. Other notable items include Ubiquiti patches for maximum-severity UniFi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 81cf0cedaffe430e64dcfbe6c727d5c88dab007d32942a3a386b777f4251a5eb
- Enrichment time
- 2026-05-25T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.