FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens

2026-05-25T14:52:12Z31149bdc2efabaf7482fba55fe8b8c3c0ab17588491a2cd5359af76a4dc9f914
Microsoft 365OAuthaccount-takeoverandroid-fraudexchange-zero-daygithub-breachinfostealerlaw-enforcement-takedownlinux-kernellocal-privilege-escalationmalwarenpm-supply-chainphishingsupply-chainvs-code-extension

What happened

Multiple high-impact incidents and vulnerabilities were reported across cloud, on‑prem and supply‑chain ecosystems. The FBI warned that the Kali365 phishing‑as‑a‑service kit hijacks Microsoft 365 OAuth tokens, enabling broad account takeover and token misuse; Microsoft disclosed a severe zero‑day affecting on‑prem Exchange Server (2016/2019/Subscription); and GitHub/GitHub Marketplace supply‑chain compromises (malicious Nx Console/VS Code extension, TanStack) resulted in stolen source code and internal repository access. Additional notable issues include Linux kernel flaws (ptrace data leak, '

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
31149bdc2efabaf7482fba55fe8b8c3c0ab17588491a2cd5359af76a4dc9f914
Enrichment time
2026-05-25T14:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens · Baitaphish