Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Exposed Attack Server Unmasks Three Microsoft 365 Phishing Operations

Exposed Attack Server Unmasks Three Microsoft 365 Phishing Operations
Photo by Torsten Dettlaff on Pexels

A misconfigured web server exposed the tools, logs, repositories, and infrastructure behind three phishing operations targeting Microsoft 365 accounts. The campaigns used both Evilginx reverse-proxy attacks and Microsoft device-code abuse, demonstrating why no single authentication control can stop every form of token theft.

A basic server configuration mistake has given defenders a rare view inside three active Microsoft 365 phishing operations. Researchers at French security company Lexfo discovered that an attacker had launched a Python web server with directory browsing enabled, exposing files that included phishing configurations, credential logs, remote-management installers, archives, and command history.

Two Different Paths Around MFA

The exposed material led researchers from one operator to two others, all using customized versions of the open-source Evilginx framework. Traditional Evilginx attacks operate as adversary-in-the-middle proxies. They relay the victim's interaction with the legitimate sign-in service while capturing credentials and session cookies.

One of the uncovered campaigns used a different approach based on Microsoft's legitimate OAuth device-code flow. Victims were directed to a real Microsoft page and persuaded to enter an attacker-generated code. The user then completed a genuine multifactor authentication challenge, unknowingly authorizing the attacker's session.

This distinction is important. Passkeys and FIDO2 security keys can block reverse-proxy phishing because authentication is bound to the legitimate domain. They do not automatically prevent device-code abuse when the victim is authenticating on Microsoft's real infrastructure.

Defensive Priorities

  • Block device-code authentication through Conditional Access unless there is a documented business requirement.
  • Use phishing-resistant authentication for employees with access to sensitive systems.
  • Review Entra sign-in logs for unusual device-code activity, unfamiliar source addresses, and repeated token refreshes.
  • Enable Continuous Access Evaluation and apply location-based access restrictions where practical.
  • Hunt for unauthorized remote-monitoring tools and suspicious scheduled tasks on endpoints.

The investigation also found signs that AI coding tools helped create scripts and other supporting components. In my view, this illustrates the most immediate criminal value of generative AI: it lowers the effort needed to customize existing attack frameworks rather than inventing entirely new malware.

The broader lesson is that MFA must be treated as an identity architecture, not a checkbox. Organizations may successfully block one phishing technique while remaining exposed through another approved authentication flow. Security teams should therefore evaluate how tokens are issued, refreshed, monitored, and revoked, particularly for cloud accounts that can provide access to email, files, and internal applications.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path