Token Theft
The latest Token Theft coverage — news, analysis, and updates from the WindowsNews.AI desk.
FBI Warns Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Slip Past MFA
The FBI’s Internet Crime Complaint Center (IC3) issued an urgent alert in May 2026 about Kali365, a newly identified phishing‑as‑a‑service platform that is systematically hijacking Microsoft...
FlagLeft Bug Exposed Microsoft 365 Tokens on Android—Patched, But Lessons Remain
A vulnerability that allowed any app on an Android device to silently steal Microsoft 365 authentication tokens has been patched by Microsoft, but the incident highlights critical gaps in mobile...
FBI Warns Kali365 Phishing Steals OAuth Tokens to Bypass MFA in Microsoft 365
The FBI has issued an urgent public warning about a phishing-as-a-service platform called Kali365 that is systematically targeting Microsoft 365 accounts by abusing device-code authentication. The...
Authentic Antics: Unveiling Russian State-Sponsored Cyber Attacks Targeting Microsoft Outlook and Microsoft 365
Russian state-sponsored cyber attacks are once again dominating the headlines, driving fresh anxiety across the global IT and security communities. The latest disclosures—centered on a sinister...
New Cloud Attack Steals Microsoft Entra Refresh Tokens to Bypass MFA
New Cloud Attack Technique Bypasses MFA by Stealing Microsoft Entra Refresh Tokens A sophisticated new cloud attack technique has emerged, leveraging a manipulation of Microsoft Entra (formerly Azure...
Storm-237 Exploits Microsoft Device Code Auth to Bypass MFA on Microsoft 365
Storm-237: The Rising Threat of Device Code Phishing Targeting Microsoft 365 Microsoft 365 users are facing a sophisticated new threat from a Russian cybercriminal group known as Storm-237. This...
Exploiting Microsoft Device Code Authentication: An Emerging Threat to Microsoft 365 Security
Introduction In recent months, cybersecurity researchers and Microsoft have uncovered a sophisticated new threat targeting Microsoft 365 (M365) accounts through an unexpected vulnerability: the...
Windows 11’s New Admin Protection Blocks Token Theft with Real-Time Monitoring
Microsoft has unveiled a groundbreaking security feature in Windows 11 called Administrator Protection, designed to combat token theft attacks and strengthen system defenses. This innovative security...
Microsoft Entra Token Theft Protection Blocks 135% Surge in Identity Attacks
Microsoft has unveiled a groundbreaking security feature for its Entra identity platform: Token Theft Protection, marking a significant advancement in enterprise cybersecurity. This new capability...