התחברות ל-baba News

חשבון אחד לאתר, לאייפון ולאנדרואיד — המנוי נשאר איתכם.

או קוד במייל

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

Search stories

הקלידו לפחות שני תווים. התוצאות מגיעות מכל המערכות ש-baba קורא.

to move · to open · esc to close

מסוף חי

התחברות ל-baba News

Sign in to keep asking. News Plus removes the daily limit.

או קוד במייל

לראות את התמונה המלאה

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

FBI Warns of New Kali365 Phishing Attack Bypassing Microsoft 365 Two-Factor Authentication

מאת קובי ברקת
תורגם ותומצת מתוך Behadrei Haredim על ידי baba
The story · English

The FBI has issued a warning about a new phishing platform called Kali365 targeting Microsoft 365 accounts, which can bypass two-factor authentication (2FA). Unlike traditional phishing that steals passwords, Kali365 exploits the legitimate login process by tricking victims into approving device codes. Attackers send fake approval requests, often via convincing phishing messages, redirecting users to genuine Microsoft authentication pages. When users enter the code, they inadvertently grant attackers access tokens, allowing entry to services like Outlook, Teams, and OneDrive without needing a password.

This access exposes emails, files, chats, and sensitive business information. Attackers can impersonate account owners to commit fraud against employees, customers, and suppliers, especially in small businesses and organizations lacking strict security policies. The FBI highlights key warning signs: unexpected device code requests, urgent messages demanding immediate action, and links from unknown sources. Users who did not initiate a login on a new device should not enter codes or approve requests.

The FBI advises accessing Microsoft services only through official websites or apps, avoiding links from emails or messages. They emphasize maintaining 2FA but caution that it is not foolproof against social engineering. Microsoft supports the FBI's guidance and is actively disrupting cybercriminals using these tactics. For organizations, the FBI recommends restricting device code login usage, reviewing necessary authentication processes, and blocking mechanisms that could let attackers bypass existing security layers.

Read the original at Behadrei Haredim
Full coverage · 2 outlets
100% right-leaningFirst: Now 14 · Jun 28

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Right 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

פתיחת המסוף החי