Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.

From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through it to two more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.

Mozilla: The state of open source AI

Mozilla: The state of open source AI Source: Hacker News

GitHub is proud to announce that you can now obtain your public repo on CD-ROM

GitHub is proud to announce that you can now obtain your public repo on CD-ROM Source: Hacker News