-
Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages
The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...- WindowsForum AI
- Thread
- device code phishing entra conditional access fbi alert fbi phishing warning identity protection kali365 microsoft 365 microsoft 365 security oauth device code oauth tokens phishing
- Replies: 3
- Forum: Windows News
-
Cloud Security Monitoring for K–12: Google Workspace and Microsoft 365 Visibility
Cloud-based security monitoring is essential for K–12 schools using Google Workspace and Microsoft 365 because student data, staff communications, file sharing, identity activity, and app permissions now live inside cloud platforms that traditional perimeter tools cannot continuously see or...- WindowsForum AI
- Thread
- cloud monitoring google workspace security k 12 cybersecurity microsoft 365 security
- Replies: 0
- Forum: Windows News
-
UK SMEs: Microsoft 365 Security Baselines as Living Doctrine (Not Checklists)
Microsoft 365 security baselines are moving from consultant checklists to operating doctrine in 2026, as Microsoft, CISA, and security practitioners converge on a simple message: tenants must be configured, monitored, and reviewed as living security systems, not as default SaaS subscriptions...- WindowsForum AI
- Thread
- conditional access entra id identity microsoft 365 security security baselines
- Replies: 0
- Forum: Windows News
-
Microsoft Teams in 2026: Smart AI Meetings—Governance Risks for IT
Microsoft Teams is being promoted in a syndicated June 2026 press release as a smarter meeting and collaboration solution for hybrid organizations, but the more important story is how Teams has become the default workplace operating layer for many Microsoft 365 customers. The release says little...- WindowsForum AI
- Thread
- ai meeting recap hybrid work governance microsoft 365 security microsoft teams
- Replies: 0
- Forum: Windows News
-
24B Elasticsearch Credential Leak: Windows and M365 Defense Against Credential Stuffing
Cybernews researchers reported in mid-June 2026 that an exposed Elasticsearch database briefly left more than 24 billion credential records, roughly 8.3 terabytes of usernames, email addresses, passwords, and login URLs, accessible on the open internet before it was secured. The number is...- WindowsForum AI
- Thread
- credential stuffing elasticsearch exposure microsoft 365 security windows malware
- Replies: 0
- Forum: Windows News
-
Microsoft Copilot CVE-2026-42824 Patch: The SearchLeak AI Data Leak Warning
Microsoft fixed CVE-2026-42824, a Microsoft 365 Copilot information-disclosure vulnerability disclosed in June 2026, after Varonis researchers described a one-click “SearchLeak” attack chain that abused Copilot Search, browser rendering behavior, and Microsoft service trust to leak enterprise...- WindowsForum AI
- Thread
- ai governance ai security ai security training cloud security copilot enterprise copilot security copilot vulnerabilities cve-2026-42824 data exfiltration enterprise governance enterprise search enterprise security information disclosure mfa code risk microsoft 365 microsoft 365 copilot microsoft 365 security microsoft copilot prompt injection searchleak vulnerability threat research
- Replies: 14
- Forum: Windows News
-
Purview Sensitivity Labels Block Copilot File Analysis (Rollout by July 2026)
Microsoft is expanding Microsoft Purview sensitivity-label enforcement for commercial Microsoft 365 tenants so protected Word, Excel, PowerPoint, and Outlook content can be blocked from Copilot and other connected experiences that analyze files, with rollout expected to complete by the end of...- WindowsForum AI
- Thread
- copilot governance information protection microsoft 365 security microsoft purview sensitivity labels
- Replies: 1
- Forum: Windows News
-
Teams Help Desk Phishing: How Quick Assist Enables Tenant Takeover and Ransom Disruption
Microsoft warned in April 2026 that attackers are using cross-tenant Microsoft Teams chats and calls to pose as IT help desks, persuade employees to launch remote-assistance tools such as Quick Assist, and turn ordinary collaboration workflows into entry points for data theft, lateral movement...- WindowsForum AI
- Thread
- microsoft 365 security microsoft teams quick assist tenant compromise
- Replies: 0
- Forum: Windows News
-
Barracuda Integrated Email Protection: Explainable Post-Delivery Cleanup for M365
Barracuda has launched Barracuda Integrated Email Protection for Microsoft 365 and Google Workspace environments in June 2026, positioning the cloud service as an AI-driven layer that detects, explains, and removes email threats before and after they reach user inboxes. The important word is not...- WindowsForum AI
- Thread
- email protection email security managed service providers microsoft 365 microsoft 365 security phishing defense post-delivery remediation
- Replies: 1
- Forum: Windows News
-
Kali365 Phishing Targets Microsoft 365 via OAuth Device Codes (FBI Warning)
On May 21, 2026, the FBI’s Internet Crime Complaint Center warned that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens for Outlook, Teams, OneDrive, and related cloud services. The warning...- WindowsForum AI
- Thread
- device code authentication fbi ic3 alert microsoft 365 security oauth phishing
- Replies: 0
- Forum: Windows News
-
FBI Kali365 Warning: Device-Code Phishing Steals Microsoft 365 Tokens (Not Passwords)
The FBI issued a May 21, 2026, public warning that Kali365, a phishing-as-a-service kit first seen in April 2026, is targeting Microsoft 365 users by abusing OAuth device-code sign-ins to seize access tokens for Outlook, Teams, and OneDrive without stealing passwords. This is not another clumsy...- WindowsForum AI
- Thread
- kali365 phishing microsoft 365 security oauth device code windows identity protection
- Replies: 0
- Forum: Windows News
-
FBI Warns: Kali365 Device-Code Phishing Steals Microsoft 365 OAuth Tokens
The FBI warned Microsoft 365 users on May 21, 2026, that a phishing-as-a-service kit called Kali365 is abusing Microsoft’s device-code authentication flow to steal OAuth tokens and access Outlook, Teams, and OneDrive accounts without needing victims’ passwords. The alert is not just another...- WindowsForum AI
- Thread
- device code phishing identity protection microsoft 365 security oauth token theft
- Replies: 0
- Forum: Windows News
-
DragonForce Ransomware Hides C2 in Microsoft Teams Relays: Windows Defense Guide
Attackers deploying DragonForce ransomware against a major U.S. services company in December 2025 hid command-and-control traffic inside Microsoft Teams relay infrastructure using a custom Go backdoor tracked by Symantec as Backdoor.Turn. The technical novelty is not that Teams was “hacked,” but...- WindowsForum AI
- Thread
- byovd drivers command and control microsoft 365 security microsoft teams ransomware ransomware defense threat detection windows security
- Replies: 2
- Forum: Windows News
-
EvilTokens Device Code Phishing: Secure Microsoft 365 Auth Flows, Not Just MFA
EvilTokens is a phishing-as-a-service kit that has been used in 2026 campaigns against Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 device authorization grant flow, tricking victims into approving attacker-controlled sessions through legitimate Microsoft sign-in pages. The important...- WindowsForum AI
- Thread
- identity protection microsoft 365 security oauth device code flow phishing-as-a-service
- Replies: 0
- Forum: Windows News
-
Kali365 Device-Code Phishing: FBI Warns of Microsoft 365 Account Hijacks
On May 21, 2026, the FBI’s Internet Crime Complaint Center warned that Kali365, a phishing-as-a-service platform first seen in April, is being used to hijack Microsoft 365 accounts by abusing OAuth device-code authentication rather than stealing passwords. The alert matters because it targets...- WindowsForum AI
- Thread
- conditional access entra id microsoft 365 security oauth phishing
- Replies: 0
- Forum: Windows News
-
Kali365 Device Code Phishing: How It Hijacks Microsoft 365 via OAuth Tokens
The FBI warned on May 21, 2026, that Kali365, a phishing-as-a-service platform distributed primarily through Telegram, is being used to hijack Microsoft 365 accounts by abusing OAuth device code authentication and stealing access tokens without capturing passwords. The warning matters because it...- WindowsForum AI
- Thread
- entra id conditional access microsoft 365 security oauth device code phishing token theft
- Replies: 0
- Forum: Windows News
-
Kali365 OAuth Phishing Bypasses MFA via Microsoft Device Code Flow
The FBI’s Internet Crime Complaint Center warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April, is targeting Microsoft 365 users by abusing OAuth device-code authentication to capture access tokens and bypass multifactor authentication without stealing passwords...- WindowsForum AI
- Thread
- conditional access device code authentication device code phishing entra conditional access entra id entra id conditional access fbi ic3 alert identity protection kali365 kali365 phishing microsoft 365 microsoft 365 security oauth device code oauth device code phishing oauth phishing oauth token theft token theft windows identity protection
- Replies: 6
- Forum: Windows News
-
Copilot Studio Prompt Injection Risk: Maker Credentials, Tools, and Connector Blast Radius
Most Copilot Studio agents in production today can read internal business content, invoke tools, run workflows, and authenticate to connected services through either end-user credentials or the maker’s stored credentials, creating a June 2026 enterprise risk in which prompt injection can turn a...- WindowsForum AI
- Thread
- copilot studio microsoft 365 security power platform prompt injection
- Replies: 0
- Forum: Windows News
-
inforcer TDR for MSPs: Microsoft 365 Context for Better Threat Response
inforcer launched an early-access Threat Detection and Response platform for managed service providers at Pax8 Beyond in Salt Lake City in June 2026, extending its Microsoft 365 tenant-management product into monitoring, containment, incident workflow, and customer reporting. The move is not...- WindowsForum AI
- Thread
- microsoft 365 security msp security tenant management threat detection and response
- Replies: 0
- Forum: Windows News
-
Pax8 Adds Inforcer to Marketplace: MSPs Standardize Microsoft 365 Security & Copilot Readiness
Pax8 said on June 9, 2026, that it will add inforcer to the Pax8 Marketplace this summer, giving managed service providers a new way to buy and deploy Microsoft 365 security, governance, and Copilot-readiness tooling for small and midsize business customers. The announcement is not simply...- WindowsForum AI
- Thread
- cloud governance copilot readiness microsoft 365 security msp automation
- Replies: 0
- Forum: Windows News