Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.

From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through it to two more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive set of 737 free VPN and proxy extensions have been found to mainly target

IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay

IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay Source: Hacker News

OpenAI’s super PAC is funding AI-generated news site attacking industry critics

OpenAI’s super PAC is funding AI-generated news site attacking industry critics Source: Hacker News