Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

FBI Warns Microsoft 365 Users of Kali365 Phishing Attack Bypassing Passwords

By דסק החדשות C14
Translated & summarized from Now 14 by baba
FBI Warns Microsoft 365 Users of Kali365 Phishing Attack Bypassing Passwords
Editorial illustration generated by baba News — not a photograph of the event.
The story · English

The FBI has issued a serious warning about a new phishing method called Kali365 targeting Microsoft 365 users. This attack bypasses traditional authentication by exploiting Microsoft's "device code" login mechanism, allowing attackers to access accounts without knowing the victim's password. Kali365, first identified in April 2026 and mainly distributed via Telegram, operates as a phishing-as-a-service platform, providing automated tools, AI-generated messages, and systems to capture access tokens.

The attack begins when the attacker initiates a login attempt from their device, prompting the victim to receive a convincing email that appears to be a legitimate file-sharing service. This email contains a code and directs the victim to Microsoft's official authentication page. When the victim enters the code on the genuine Microsoft site, they inadvertently grant the attacker access. The attacker then obtains access and refresh tokens, enabling continuous access without further authentication.

Security experts highlight the significant risk this poses to businesses and organizations. Since the victim enters the code on a legitimate Microsoft page, many security tools and password managers fail to detect suspicious activity. Once inside an organizational email account, attackers can read communications, send fraudulent invoices, and impersonate trusted sources to other employees.

To mitigate these risks, the FBI and Microsoft security teams recommend users never enter device codes unless they initiated the login process, avoid clicking on unexpected links, and access Microsoft 365 directly through browsers. Organizations should regularly monitor login logs and connected devices, revoke unknown sessions immediately, and consider restricting device code usage through conditional access policies. In case of suspected compromise, immediate actions include logging out from all devices, changing passwords, and checking email forwarding rules. Organizations must promptly report incidents to their security teams to revoke stolen access tokens and prevent ongoing breaches.

Read the original at Now 14
Full coverage · 2 outlets
100% right-leaningFirst: Now 14 · Jun 28

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Right 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal