Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time. The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems. Victims are directed to what appears to be a legitimate login process, allowing the service to collect credentials and intercept the authenticated session after the user enters a password and completes multi-fac
m365 (2)
The US Federal Bureau of Investigation (FBI) has issued a public service announcement warning organizations and individuals about Kali365, a Phishing-as-a-Service (PhaaS) platform first observed in April 2026. The service is distributed primarily through Telegram and enables even less-technical attackers to hijack Microsoft 365 accounts by stealing OAuth access and refresh tokens, bypassing the need for passwords or multi-factor authentication (MFA). This gives almost anyone the means to carry