phishing
FBI Warns of Kali365: Telegram-Sold Phishing Kit Steals Microsoft 365 Tokens Past MFA
The FBI's IC3 has warned organizations about Kali365, a Telegram-sold phishing-as-a-service kit that runs device-code phishing against Microsoft 365 — stealing the OAuth tokens issued after the victim genuinely passes MFA on Microsoft's real sign-in page.