Kali365: The Phishing-as-a-Service Platform Weaponizing Microsoft's Own Authentication Against You

If you think MFA is your safety net, Kali365 just cut it. In May 2026, the FBI issued Public Service Announcement I-052126-PSA warning organizations about a rapidly emerging Phishing-as-a-Service (PhaaS) platform called Kali365. First observed in April 2026 and distributed openly through Telegram, Kali365 doesn’t steal your password. It doesn’t even need to. It steals something more valuable: your OAuth token, and with it, persistent, credential-free access to your entire Microsoft 365 environment. ...

June 16, 2026 · 9 min · Logan

Device Code Phishing — The Attack That Makes MFA Irrelevant

When most people think about phishing, they picture a fake login page harvesting credentials. Device code phishing doesn’t work that way. There’s no spoofed domain. No credential harvesting. No malware. The victim authenticates against real Microsoft infrastructure, completes their MFA challenge, and hands an attacker a fully valid Bearer token — all without knowing anything unusual happened. ...

June 2, 2026 · 10 min · Logan

From the Trenches: Defending Salesforce Against ShinyHunters' Playbook

If you haven’t read the threat intelligence breakdown of the ShinyHunters Salesforce campaign, start there. This article assumes you know what happened and focuses on what to do about it. ...

May 22, 2026 · 7 min · Logan

ShinyHunters' Salesforce Campaign: Three Rounds, 1.5 Billion Records

ShinyHunters didn’t hack Salesforce. That distinction matters. Across three separate campaigns spanning mid-2025 through early 2026, the group — tracked by security researchers as UNC6040 and UNC6395 — systematically exploited how organizations configure, connect, and authenticate into Salesforce. The platform’s infrastructure was never the vulnerability. The integrations, the OAuth flows, and the guest user permissions were. ...

May 22, 2026 · 7 min · Logan