Issue #012May 25, 2026
VP of Marketing, Rebecca WarrenRebecca Warren

What's happening in email security: May 18 – May 24, 2026

The FBI doesn't issue a public warning about a phishing kit every week. This week it did, because Kali365 steals your Microsoft 365 access without ever touching your password or tripping MFA. Meanwhile a business professional in Singapore wired away S$4.9 million after a video call with people who were not real, and on-prem Exchange admins spent the week without a patch for an actively exploited flaw. The connecting thread: the login prompt is no longer where attacks are won or lost.

The FBI put its name on the Kali365 warning

Kali365 is a Phishing-as-a-Service platform that showed up in April, sold over Telegram, and it's built around one idea: don't steal the password, steal the token. It abuses Microsoft's OAuth 2.0 device code flow. A phishing email hands the victim a device code and steers them to a real Microsoft verification page, where they unknowingly authorize the attacker's device. The OAuth token gets captured, and now there's persistent access to Outlook, Teams, and OneDrive with no further MFA prompts.

That last part is why this matters. Your MFA policy did its job and the attacker is still in the mailbox. The FBI's recommended fix is specific and worth actioning this week: use Conditional Access to restrict or block the device code flow, audit where device code is actually being used in your tenant, and block authentication transfer policies. Exempt your emergency access accounts so you don't lock yourself out.

An FBI PSA moves this from "interesting vendor blog post" to national warning. Treat it that way.

On-prem Exchange had an actively exploited zero-day and no patch

CVE-2026-42897 is a cross-site scripting flaw in Exchange Server's Outlook Web Access. An attacker sends a crafted email, and when the recipient opens it in OWA, JavaScript runs in their authenticated browser session. Session hijacking, credential theft, spoofed mail from the account, all with no link to click. Microsoft disclosed it on May 14, confirmed in-the-wild exploitation, and had no permanent fix during this window.

It hits on-prem Exchange 2016, 2019, and Subscription Edition at every update level. Exchange Online is clear. Through this week the only protection was the Exchange Emergency Mitigation Service or the manual mitigation tool, so the job was confirming those were actually active. (Good news for later: the real patch lands June 9. More on that in a few weeks.)

A deepfake Zoom call cost one victim S$4.9 million

A Singapore business professional joined what looked like a high-level government video meeting. On the call: AI-generated deepfakes of Prime Minister Lawrence Wong, the President, a cabinet minister, and purported reps from MAS and BlackRock. The deepfaked PM even named the victim directly to build trust. The victim transferred S$4.9 million (about US$3.8 million) across multiple wires before realizing, on May 14, that none of it was real.

The entry point wasn't the video call. It was a WhatsApp message from the profile of a real senior official, followed by a forged "letter of guarantee" with the PM's signature. Impersonation has jumped from text in an inbox to live synthetic video, but it still starts with a trusted-channel lure and still ends with a payment request. The defense hasn't changed: out-of-band verification of any payment instruction, no matter how senior or convincing the person asking appears to be.

  • Lookalike domains hit financial institutions worldwide

    A spear-phishing campaign impersonated executives and IT support at banks across North America, Europe, and Asia using single-character or swapped-TLD lookalike domains to harvest credentials and MFA codes, and because the attackers registered their own domains rather than spoofing the exact brand domain, DMARC won't catch it (single-source report, so treat the specifics as indicative).

This roundup is published weekly by Red Sift. Test your email authentication set-up with Red Sift Investigate.