Open Directory Exposes Three Evilginx Phishing Operators
2026-07-13T20:52:18Z•9d10bd0306a2b08c84240660b8d82bd4c38429087c24d79fe103f14f35d201ef
adobe-coldfusionagentic-ransomwareai-securitycloud-securityevilginxexposed-credentialsghostapprovalgigaWipergoddamninfostealerjadepuffermfa-bypassmicrosoft-entraidmisconfigurationnation-state-espionageoauth-spoofingphishingpoisonxprompt-injectionransomwarerouterssharefilesnmpstorage-zone-controllervulnerability-exploit
What happened
Collection of Infosecurity Magazine headlines (July 2026) summarizing multiple high-impact incidents and research: a misconfigured open directory exposed three Evilginx phishing operators (MFA bypass); novel OAuth Client ID spoofing technique targeting Microsoft Entra ID; Progress Software urges customers to shut down a Storage Zone Controller; Russian state-backed actors actively exploiting routers via weak SNMP credentials; active exploitation of an Adobe ColdFusion flaw with CVSS 10.0; exposed AWS GovCloud credentials and CISA response; new destructive and espionage-capable malware (GigaWIP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 9d10bd0306a2b08c84240660b8d82bd4c38429087c24d79fe103f14f35d201ef
- Enrichment time
- 2026-07-13T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.