VMTech
Discuss a project

Misconfigured server exposed three Evilginx campaigns targeting Microsoft 365

Misconfigured server exposed three Evilginx campaigns targeting Microsoft 365

Colleagues, please note a fresh cybersecurity case.

Researchers discovered a misconfigured server that exposed tools from three phishing operations against Microsoft 365 based on Evilginx.

Key points:
- one campaign stole sessions via reverse proxy and bypassed MFA;
- another used Microsoft’s legitimate device code flow;
- the infrastructure contained logs, configs, tokens, and RMM tools.

Why it matters: passkeys and FIDO2 effectively block Evilginx-style attacks, but device code flow requires Conditional Access and sign-in monitoring.

What are you already checking in Entra ID and sign-in logs? #cybersecurity #Microsoft365 #phishing #IdentitySecurity

Open analytics
On the site 3 views
min read 1 13.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Misconfigured server exposed three Evilginx campaigns targeting Microsoft 365

Open the post on Instagram ↗