FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account

2026-05-22T20:51:41Z363c498b84009af4305950c70e2e66db6b7520f6b856cd5c3703e0445ee2e10a
AI-assisted attacksAndroid malwareCI workflowsGCPGitHubGoogle API keysKali365MFA bypassMSHTAMegalodonMicrosoft 365TeamPCPVPN seizureVS Code extensionVerizon DBIRcloud credential theftdata exposurefileless malwarephishingpremium SMS fraudransomware infrastructurerepository theftsupply chaintrusted remote accessvulnerability exploitation

What happened

Feed of security incidents and research: FBI warns of Kali365, a phishing-as-a-service that can bypass MFA to hijack Microsoft 365 accounts; SafeDep reports the Megalodon supply-chain attack that injected malicious CI workflows into 5,561 GitHub repos to steal cloud credentials; researchers found deleted Google API keys remain active up to 23 minutes exposing GCP/Gemini/BigQuery/Maps data; Europol seized First VPN used by ransomware groups and arrested its administrator; Android malware covertly subscribes victims to premium services; attackers are abusing MSHTA for fileless Windows malware; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
363c498b84009af4305950c70e2e66db6b7520f6b856cd5c3703e0445ee2e10a
Enrichment time
2026-05-22T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account · Baitaphish