Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream
In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...
Insights
Articles in Microsoft 365.
In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...
MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...
Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...
Device code phishing kits like EvilTokens trick users into completing MFA on an attacker's behalf. Blocking device code flow with Conditional Access removes...
In July 2025, Chinese state actors and a ransomware group exploited ToolShell zero-days in on-premises SharePoint Server, stealing machine keys that let them persist after patching. SharePoint Online wasn't affected. Here is what happened and what to do with the servers you still run.
EchoLeak (CVE-2025-32711) was the first widely reported zero-click prompt injection against Microsoft 365 Copilot: a crafted email could cause Copilot to leak data with no user interaction. Microsoft fixed it server-side. Here is what it teaches about AI assistant risk.
On September 16, 2024, Microsoft announced Copilot Wave 2 — Pages, agents and more — alongside tools to tackle the oversharing that stalled many pilots. Here is what changed and a practical playbook for scaling Copilot safely.
In January 2024, Microsoft disclosed that Midnight Blizzard read email of its senior leaders. The path ran through a legacy test tenant without MFA and an OAuth app with elevated access. Here is the chain and how to find the same risks in your tenant.
Microsoft 365 Copilot reached enterprise general availability on November 1, 2023. It respects existing permissions — which is exactly the problem in tenants with years of oversharing. Here is how Copilot uses your data and how to prepare.
In 2023, a China-based actor used a stolen Microsoft consumer signing key to forge tokens and read government email. A customer caught it because it had detailed audit logs. Here is what happened, what Microsoft later corrected, and what it means for your logging.
Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.
The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...
Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.
The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...
On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...
After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...
Use this checklist to plan a Windows 11 migration with security improvements built in.
The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...
ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.
SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...
The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...
Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...
Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.
The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...