FBI warns about fast-growing phishing kit targeting Microsoft 365 users

2026-05-22T20:51:41Z8e21b17f3a2311d15ee21eeeab43bd6dba6ab584db73b9efdb65dd89a4d3ed32
AI-securityCISAClarityEuropolFirst VPNGitHubKali365KimwolfMicrosoft 365OAuthRampartVS Code extensionaccess-tokensbotnetcredential-leakcredential-theftexfiltrationlaw-enforcementopen-source-vulnerabilitiesphishingred-teamingsupply-chain

What happened

This CyberScoop feed highlights multiple active and emerging cyber threats and enforcement actions: the FBI warns of Kali365, a fast-growing phishing kit (first observed April) that abuses Microsoft device-authorization flows to obtain persistent Microsoft 365 access tokens and grant criminal-controlled applications long-term access; an alleged Kimwolf botnet administrator in Canada was arrested and faces extradition; Europol and partners took down First VPN and seized infrastructure tied to widespread cybercrime use; GitHub suffered internal repository exfiltration after a poisoned Visual St

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
8e21b17f3a2311d15ee21eeeab43bd6dba6ab584db73b9efdb65dd89a4d3ed32
Enrichment time
2026-05-22T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI warns about fast-growing phishing kit targeting Microsoft 365 users · Baitaphish