Open Directory Exposes Three Evilginx Phishing Operators

2026-07-13T20:52:18Z9d10bd0306a2b08c84240660b8d82bd4c38429087c24d79fe103f14f35d201ef
adobe-coldfusionagentic-ransomwareai-securitycloud-securityevilginxexposed-credentialsghostapprovalgigaWipergoddamninfostealerjadepuffermfa-bypassmicrosoft-entraidmisconfigurationnation-state-espionageoauth-spoofingphishingpoisonxprompt-injectionransomwarerouterssharefilesnmpstorage-zone-controllervulnerability-exploit

What happened

Collection of Infosecurity Magazine headlines (July 2026) summarizing multiple high-impact incidents and research: a misconfigured open directory exposed three Evilginx phishing operators (MFA bypass); novel OAuth Client ID spoofing technique targeting Microsoft Entra ID; Progress Software urges customers to shut down a Storage Zone Controller; Russian state-backed actors actively exploiting routers via weak SNMP credentials; active exploitation of an Adobe ColdFusion flaw with CVSS 10.0; exposed AWS GovCloud credentials and CISA response; new destructive and espionage-capable malware (GigaWIP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
9d10bd0306a2b08c84240660b8d82bd4c38429087c24d79fe103f14f35d201ef
Enrichment time
2026-07-13T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Open Directory Exposes Three Evilginx Phishing Operators · Baitaphish