A misconfigured server exposed three separate Evilginx phishing operations targeting Microsoft 365 users, highlighting the importance of proper security configurations and awareness about emerging threats. The revelation comes as AI-powered tools are increasingly being used to identify and exploit vulnerabilities in software systems.
The compromised server, which has not been named for privacy reasons, appears to have been used by attackers to set up three distinct phishing operations using Evilginx, a type of phishing tool designed to intercept and manipulate authentication cookies from Microsoft 365 services. This allowed the attackers to bypass two-factor authentication (2FA) and gain unauthorized access to sensitive user data.
To understand how this works, let’s break it down: when a user attempts to sign in to their Microsoft 365 account, Evilginx injects malicious JavaScript code into the login page. If successful, this code captures the authentication cookie, which can then be used to authenticate without needing to enter the actual password or pass the second factor of authentication. The misconfigured server allowed these operations to run undetected, allowing attackers to harvest user credentials and potentially lead to more targeted attacks.
The discovery has significant implications for organizations relying on Microsoft 365 services. The use of AI-powered tools to identify vulnerabilities in software systems is becoming increasingly prevalent, as seen with the recent emergence of AI-driven vulnerability scanning solutions. These tools are capable of identifying weaknesses in complex software systems that traditional security measures may miss. However, they also raise concerns about who has access to this information and how it’s being used.
The exposure of these phishing operations raises questions about the effectiveness of current security measures in detecting such threats. The reliance on AI-powered solutions for vulnerability scanning is a double-edged sword – while they can identify vulnerabilities that human analysts might miss, they also introduce new risks if not properly implemented or managed.
To protect against similar threats, organizations should prioritize robust server configuration and security monitoring practices. Regular vulnerability assessments and penetration testing can help identify weaknesses before attackers exploit them. Furthermore, users of Microsoft 365 services must remain vigilant about phishing attempts, especially those that seem too good (or bad) to be true. Always verify the authenticity of login requests and never enter sensitive information on untrusted websites or email links.
Source: The Hacker News — 2026-07-13