{"id":17782,"date":"2026-06-08T12:03:00","date_gmt":"2026-06-08T08:03:00","guid":{"rendered":"https:\/\/eternos974.live\/?p=17782"},"modified":"2026-06-08T06:49:22","modified_gmt":"2026-06-08T02:49:22","slug":"kali365-comment-loutil-de-piratage-exploite-le-code-dappareil-microsoft-365","status":"publish","type":"post","link":"https:\/\/eternos974.live\/index.php\/2026\/06\/08\/kali365-comment-loutil-de-piratage-exploite-le-code-dappareil-microsoft-365\/","title":{"rendered":"Kali365 : comment l&rsquo;outil de piratage exploite le code d&rsquo;appareil Microsoft 365"},"content":{"rendered":"<p>Le FBI a r\u00e9v\u00e9l\u00e9 une menace in\u00e9dite pour les utilisateurs de Microsoft 365 : un outil de piratage nomm\u00e9 Kali365, vendu en abonnement \u00e0 partir de 250 dollars par mois. Ce kit de phishing-as-a-service (PhaaS) permet aux cybercriminels de prendre le contr\u00f4le de comptes Outlook, Teams ou OneDrive sans m\u00eame voler de mot de passe. L\u2019astuce ? Exploiter un m\u00e9canisme l\u00e9gitime de Microsoft, le code d\u2019appareil, pour contourner la double authentification.<\/p>\n<p>Kali365 op\u00e8re via des emails de phishing g\u00e9n\u00e9r\u00e9s par l\u2019intelligence artificielle. Ces messages, d\u00e9guis\u00e9s en notifications cloud (partage de document, alerte OneDrive\u2026), contiennent un code \u00e0 usage unique. L\u2019utilisateur est invit\u00e9 \u00e0 le saisir sur le site officiel microsoft.com\/devicelogin, un domaine valide sans faute d\u2019orthographe. L\u00e0 r\u00e9side la ruse : en entrant le code, l\u2019utilisateur autorise en r\u00e9alit\u00e9 un appareil distant (celui du pirate) \u00e0 se connecter \u00e0 son compte. Microsoft ne d\u00e9tecte rien, car la connexion semble l\u00e9gitime.<\/p>\n<p>Une fois le code valid\u00e9, Kali365 r\u00e9cup\u00e8re un jeton OAuth, un acc\u00e8s temporaire \u00e0 l\u2019ensemble des applications connect\u00e9es (Outlook, Teams, OneDrive\u2026). Ce jeton permet aux cybercriminels d\u2019envoyer des emails de hame\u00e7onnage depuis le compte victime, amplifiant l\u2019attaque. La double authentification, souvent per\u00e7ue comme un bouclier infaillible, devient alors inutile. Le FBI a document\u00e9 des centaines d\u2019attaques depuis avril 2026, ciblant des entreprises et des particuliers.<\/p>\n<p>Pour se pr\u00e9munir, le FBI recommande de d\u00e9sactiver le flux d\u2019authentification par code d\u2019appareil via les politiques d\u2019acc\u00e8s conditionnel de Microsoft. Les experts de MalwareBytes ajoutent un conseil crucial : ne jamais saisir un code sur une page Microsoft si un email ou message vous y invite sans contexte. Enfin, surveiller r\u00e9guli\u00e8rement les appareils connect\u00e9s \u00e0 son compte sur account.microsoft.com\/devices. Si un appareil inconnu est d\u00e9tect\u00e9, supprimer imm\u00e9diatement la session et changer le mot de passe. La cybercriminalit\u00e9 \u00e9volue, et les outils comme Kali365 rappellent que la vigilance reste la meilleure arme.<\/p>\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.01net.com\/actualites\/double-authentification-inutile-outil-piratage-kali365-ravages-comptes-microsoft.html\" target=\"_blank\" rel=\"nofollow noopener\">Source 1<\/a><\/li>\n<\/ul>\n<p>\u00c0 tr\u00e8s vite sur <a href=\"https:\/\/eternos974.live\" target=\"_blank\" rel=\"noopener\"><strong>l\u2019EternoStation<\/strong><\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>D\u00e9couvrez comment Kali365 utilise le code d&rsquo;appareil Microsoft 365 pour pirater des comptes. Mesures de s\u00e9curit\u00e9 recommand\u00e9es par le FBI.<\/p>\n","protected":false},"author":1,"featured_media":17783,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"cybocfi_hide_featured_image":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[393],"tags":[],"class_list":["post-17782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-infos"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/eternos974.live\/wp-content\/uploads\/2026\/06\/microsoft-double-authentification-1344x896-1.jpg?fit=1344%2C896&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/posts\/17782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/comments?post=17782"}],"version-history":[{"count":1,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/posts\/17782\/revisions"}],"predecessor-version":[{"id":17784,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/posts\/17782\/revisions\/17784"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/media\/17783"}],"wp:attachment":[{"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/media?parent=17782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/categories?post=17782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eternos974.live\/index.php\/wp-json\/wp\/v2\/tags?post=17782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}