Misconfigured Server Exposes Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
Evilginx is an open-source adversary-in-the-middle (AiTM) phishing framework used to bypass multi-factor authentication by proxying live login sessions. It has been forked…
Lexfo is a French security company that discovered and analyzed three Evilginx phishing operations targeting Microsoft 365, leveraging a misconfigured server to…
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories Ravie LakshmananJul 09, 2026Hacking News / Cybersecurity News…
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
A critical vulnerability in Google's Dialogflow CX, dubbed 'Rogue Agent' by security firm Varonis, could have allowed an attacker with edit permissions…
A new Android malware operation called RedWing is being offered as a ready-made bank-fraud service on Telegram, allowing low-skill criminals to take…
RedWing is a new Android malware operation offered as a subscription-based service on Telegram, enabling criminals to steal banking credentials and intercept…
Microsoft Entra is Microsoft's cloud-based identity and access management service. Attackers are using fake passkey enrollment pages that mimic Entra's passkey registration…