FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens
2026-05-25T14:52:12Z•31149bdc2efabaf7482fba55fe8b8c3c0ab17588491a2cd5359af76a4dc9f914
Microsoft 365OAuthaccount-takeoverandroid-fraudexchange-zero-daygithub-breachinfostealerlaw-enforcement-takedownlinux-kernellocal-privilege-escalationmalwarenpm-supply-chainphishingsupply-chainvs-code-extension
What happened
Multiple high-impact incidents and vulnerabilities were reported across cloud, on‑prem and supply‑chain ecosystems. The FBI warned that the Kali365 phishing‑as‑a‑service kit hijacks Microsoft 365 OAuth tokens, enabling broad account takeover and token misuse; Microsoft disclosed a severe zero‑day affecting on‑prem Exchange Server (2016/2019/Subscription); and GitHub/GitHub Marketplace supply‑chain compromises (malicious Nx Console/VS Code extension, TanStack) resulted in stolen source code and internal repository access. Additional notable issues include Linux kernel flaws (ptrace data leak, '
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 31149bdc2efabaf7482fba55fe8b8c3c0ab17588491a2cd5359af76a4dc9f914
- Enrichment time
- 2026-05-25T14:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.