Misconfigured server exposed three Evilginx campaigns targeting Microsoft 365

Colleagues, please note a fresh cybersecurity case.
Researchers discovered a misconfigured server that exposed tools from three phishing operations against Microsoft 365 based on Evilginx.
Key points:
- one campaign stole sessions via reverse proxy and bypassed MFA;
- another used Microsoft’s legitimate device code flow;
- the infrastructure contained logs, configs, tokens, and RMM tools.
Why it matters: passkeys and FIDO2 effectively block Evilginx-style attacks, but device code flow requires Conditional Access and sign-in monitoring.
What are you already checking in Entra ID and sign-in logs? #cybersecurity #Microsoft365 #phishing #IdentitySecurity

