What Happened
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,
Why It Matters
The article describes Kali365, a phishing-as-a-service kit that abuses Microsoft's legitimate OAuth 2.0 device code authentication flow to steal access and refresh tokens for Microsoft 365, enabling persistent access to email, documents, and cloud resources without needing passwords or repeated MFA challenges.[1][4][5] It reportedly offers AI-generated phishing lures and turnkey campaigns, lowering the barrier for attackers to compromise US organizations' Microsoft 365 environments.[1][2][3] From a RealGround perspective, this introduces a significant SaaS AI risk: AI-driven phishing lures and token-abuse flows can directly impact AI-enabled collaboration, email, and document-processing agents integrated with Microsoft 365, allowing attackers to silently pivot into AI workflows and exfiltrate or manipulate data processed by those agents. Organizations should implement conditional access controls to restrict device code flow, continuously red-team Microsoft 365 and SaaS-integrated AI agents for token theft and OAuth abuse paths, and ensure that any AI agents using Microsoft 365 APIs strictly validate authentication context and minimize token scope.[1][2][7][9]
RealGround Analysis
This signal maps to SaaS AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
