# Misconfigured Server Exposes Three Phishing Operations Targeting Microsoft 365

Researchers discovered a misconfigured server that revealed three separate phishing operations using the Evilginx framework, targeting Microsoft 365 credentials. The attackers employed reverse proxy techniques to bypass multi-factor authentication. The exposure highlights the persistent threat of advanced phishing campaigns against enterprise cloud services.

**Importance:** 3/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html) — Mon, 13 Jul 2026 13:00:00 +0530