The Federal Bureau of Investigation (FBI) is issuing this Public Service Announcement (PSA) to warn the public about an emerging Phishing1-as-a-Service2 (PhaaS) platform called Kali365, first seen in April 2026. Kali365 has primarily been distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication3 (MFA) protocols without intercepting the user’s credentials.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach
October 5, 2026
A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...
- ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau
October 3, 2026
A suspected member of the ShinyHunters hacking group, which says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...
- AI agents aggressively tried to hack US and Canadian government websites
October 2, 2026
AI agents simply won’t take ‘no’ for an answer. Security researchers from nonprofit Transluce found bots making numerous attempts to hack US and Canadian government websites in search of private information. In a new report, Transluce singled out two incidents: one against the US Department of Education, and one against Library and Archives Canada. Both seem ...
- SMTP is the key: BPFDoor and AVERAT hitting the network edge
October 2, 2026
Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...
- Operation KillSwitch: Teenager suspected of leading KillSec ransomware group
October 1, 2026
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...
- Hackers steal protective order and foster care records from Arizona courts
September 30, 2026
This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal information of “many Arizonans.” The court says the attack began with a phishing email containing a malicious link that a court employee clicked. The attackers copied sensitive backup files containing records related to protective orders and foster ...
