FBI warns of Kali phishing scam targeting Microsoft OAuth tokens

The FBI has issued a warning about a new phishing kit called Kali365 that targets Microsoft OAuth tokens. The kit is being offered on Telegram and uses AI-generated lures.

The warning highlights how Kali365 lowers the barrier of entry for less-technical attackers. It provides access to AI-generated phishing lures that can compromise Microsoft accounts through OAuth tokens.

Awọn iroyin ti o ni ibatan

Illustration of a hacker exploiting Meta's AI chatbot to hijack Instagram accounts by changing email addresses and bypassing security.
Àwòrán tí AI ṣe

Meta patches ai chatbot flaw used to hijack instagram accounts

Ti AI ṣe iroyin Àwòrán tí AI ṣe

Hackers exploited Meta's AI support chatbot to take over Instagram accounts by tricking it into changing associated email addresses. The vulnerability allowed password resets without two-factor authentication after matching locations via VPN. Meta resolved the issue with an emergency patch on May 29.

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

Ti AI ṣe iroyin

Microsoft has alerted users that hackers are targeting password reset processes to breach accounts. The activity is attributed to the group Storm-2949.

Developer platform Socket has identified a malware known as TrapDoor that is targeting crypto and AI developers.

Ti AI ṣe iroyin

A Hong Kong woman lost more than HK$1 million after being lured into a fraudulent cryptocurrency scheme through a fake artificial intelligence-powered trading app. Police recorded over 70 similar investment scams in the past week, with total losses exceeding HK$50 million.

Ojú-ìwé yìí nlo kuki

A nlo kuki fun itupalẹ lati mu ilọsiwaju wa. Ka ìlànà àṣírí wa fun alaye siwaju sii.
Kọ