Misconfigured Server Exposes Three Phishing Operations Targeting Microsoft 365
Researchers discovered a misconfigured server that revealed three separate phishing operations using the Evilginx framework, targeting Microsoft 365 credentials. The attackers employed reverse proxy techniques to bypass multi-factor authentication. The exposure highlights the persistent threat of advanced phishing campaigns against enterprise cloud services.