FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

2026-05-25T13:23:33Z81cf0cedaffe430e64dcfbe6c727d5c88dab007d32942a3a386b777f4251a5eb
Apex OneCINEMAGOALClickFixComposerDDoSDrupalGhost CMSKali365KimWolfLaravel LangMFA bypassMicrosoft 365OAuth device codeSQL injectionTrend MicroUbiquiti UniFi OSbotnetcredential stealerhosting abuselaw enforcement takedownphishing-as-a-servicepiracyserver seizuresupply chainzero-day

What happened

Multiple active and high-impact security incidents reported: the FBI warns of Kali365 phishing-as-a-service abusing OAuth device code flow to steal Microsoft 365 session tokens and bypass MFA; Ghost CMS is being exploited via a critical SQL injection (CVE-2026-26980) to deliver ClickFix attack chains; Laravel Lang Composer packages were hijacked to distribute credential-stealing malware; Trend Micro disclosed an Apex One zero-day being exploited in the wild and Drupal is seeing active targeting of a critical SQL injection. Other notable items include Ubiquiti patches for maximum-severity UniFi

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
81cf0cedaffe430e64dcfbe6c727d5c88dab007d32942a3a386b777f4251a5eb
Enrichment time
2026-05-25T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI warns of Kali365 phishing service targeting Microsoft 365 accounts · Baitaphish