[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftnKr68I0Xcn_FddHEZgFzJBeQUMIt_EYYycU_T0df64":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"8d50e43f-1aea-4a01-88e9-f4a388cf27fd","kali365-abuses-microsoft-device-code-auth-to-hijack-enterprise-accounts","5135b991-7cad-43a0-9d75-4ac234527f63","Kali365 Abuses Microsoft Device Code Auth to Hijack Enterprise Accounts","The Kali365 phishing kit exploits Microsoft's legitimate device code authentication flow, tricking users into approving attacker-controlled codes on Microsoft's real login page — making the attack nearly indistinguishable from a genuine sign-in. Because the victim interacts with an authentic Microsoft domain, traditional phishing indicators (fake URLs, spoofed branding) are absent, drastically lowering user suspicion. Once a device code is approved, attackers receive valid OAuth access tokens that bypass passwords and MFA entirely, granting persistent access to email, files, and downstream services. This matters because the attack weaponizes trust in a legitimate platform, meaning technical controls alone are insufficient without user education and strict authentication policy enforcement.","**Immediate actions:**\n- Disable or restrict the OAuth device code authentication flow in Azure AD\u002FEntra ID Conditional Access policies for all non-approved use cases.\n- Audit existing OAuth token grants and revoke any suspicious or unrecognized delegated permissions across the Microsoft 365 tenant.\n- Alert users and IT staff immediately about unsolicited device code approval requests via phishing awareness communications.\n\n**Long-term improvements:**\n- Enforce Conditional Access policies that require compliant, registered devices and block legacy or device-code authentication flows by default.\n- Implement phishing-resistant MFA methods (e.g., FIDO2 hardware keys, Windows Hello) to reduce reliance on approval-based authentication flows.\n- Establish a formal OAuth app governance program to inventory, review, and approve all third-party and internal app token grants regularly.\n\n**Detection measures:**\n- Enable and monitor Azure AD sign-in logs and Unified Audit Logs for device code authentication events, especially from unfamiliar IP addresses or geolocations.\n- Configure SIEM alerts for anomalous OAuth token issuance patterns, including device code grants followed by unusual data access or mail forwarding rules.\n- Integrate Microsoft Defender for Cloud Apps to detect and respond to suspicious delegated permission grants in near real-time.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4 — Secure Configuration of Enterprise Assets and Software","CIS Control 6 — Access Control Management","CIS Control 14 — Security Awareness and Skills Training","NIST SP 800-63B — Digital Identity Guidelines (Authenticator Assurance)","NIST AC-2 — Account Management","NIST AC-17 — Remote Access","NIST SI-4 — System Monitoring","MITRE ATT&CK T1528 — Steal Application Access Token","MITRE ATT&CK T1566 — Phishing","GDPR Article 32 — Security of Processing (where EU data subjects are involved)","published","2026-08-05T14:21:53.791807+00:00","2026-08-05T14:21:53.521+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fkali365-weaponizes-microsoft.html","kali365-weaponizes-microsoft-authentication-against-us-companies-new-enterprise--716e0f","Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]