Wire
09:48ZWFWITNESSNBC: The House passed a bill imposing new sanctions on Russia and Iran by a vote of 262-159, sending it to Pr…09:47ZTASNIMNEWSYemeni sources: We’ve disrupted Saudi Arabia’s oil exports for months🔹An economic source in Sanaa told Al-Ak…09:45ZNOELREPORTUkraine has repatriated the bodies of 252 people killed in the war. Russia claims the remains belong to Ukrai…09:45ZALLAFRICAEquatorial Guinea: Facebook, TikTok Shut Down in Equatorial Guinea After VP Corruption Video‍[Leadership] Fac…09:44ZDAILYNATIOSifuna's motorcade blocked from entering JKUAT Karen Campus where he was invited for event09:43ZCLASHREPORBIG: German Chancellor Merz is facing growing pressure after recent election setbacks and internal criticism.…09:43ZBOWESCHAYGreek MEP Greek Latinopoulou takes Von Der Liar apart like a lego set in front of a packed chamber in Brussel…09:41ZOSINTLIVEZelensky on China:"It's a pity that China is not on our side in this war, politically, even it's not about we…
  • S&P 500 ETF 0.78%
  • Nasdaq 0.01%
  • Nasdaq 100 0.02%
  • Dow ETF 0.74%
Terminal ↗
← The MonexusTech

One exposed folder just mapped three Microsoft 365 phishing rings, and the schools trying to teach around AI

A misconfigured server laid bare three campaigns targeting Microsoft 365 logins, while a separate debate over AI tutors in private schools reopens the question of who sets the curriculum.

A graphic displays the word "COUPONS" in bold white capital letters over a purple and dark blue checkered background with a grainy texture.
A graphic displays the word "COUPONS" in bold white capital letters over a purple and dark blue checkered background with a grainy texture. @WIRED · Telegram

On 13 July 2026, researchers at The Hacker News catalogued three distinct phishing operations against Microsoft 365 tenants after a single misconfigured open directory revealed their inner workings. The exposed server logged 218 credential-capture sessions and exposed the operators' tooling: two adversarial-in-the-middle proxies using the Evilginx framework and a parallel device-code phishing track that abuses Microsoft's own sign-in flow. Within hours, security teams across the Fortune 500 were comparing notes against shared indicators of compromise. The lesson is not new, but it is sharper than usual. Identity is the perimeter now, and the perimeter is leaking.

The incident shows how fragile the human-authentication layer has become. Microsoft 365's single sign-on was sold to enterprises as a productivity upgrade, then quietly became the highest-value target on the internet. Once an attacker captures a session cookie, they do not need a password, a token, or a vulnerability. They are already the user. Evilginx turns that asymmetry into a product: a relay that sits between the victim and Microsoft's legitimate login page, harvests the session cookie at the moment of authentication, and forwards everything else. Device-code phishing takes a different path. It tricks a user into entering a short code at Microsoft's real sign-in page while the attacker, on a separate device, completes the corresponding flow. Either route ends with the same result: a valid session for a paying tenant.

Three rings, one folder

The misconfigured directory did the police work. Investigators said one open bucket exposed infrastructure tied to three campaigns running in parallel, including command-and-control scripts, the Evilginx phishing kit configuration, and session logs with enough metadata to fingerprint the operators. The 218 capture sessions are a floor, not a ceiling: only the campaigns that wrote to that directory are visible. The other two operations used the same open-folder footprint, which is what linked them in the first place.

For defenders, the artefact map matters more than the headline number. Shared hosting, reused certificates, and a common logging path suggest coordination or at least a common supplier. Either reading points the same direction: phishing-as-a-service is now modular enough to run three campaigns from one rented server, and careless operation gives defenders the receipts.

The AI tutor question

A separate thread from 14 July raises a parallel governance problem. According to Unusual Whales' reporting on a private-school trend, high-earning families are moving children into schools that replace the language of "teachers" with "guides" or "coaches," and hand the actual instruction over to AI tutors that tailor the curriculum to each child. The pitch is differentiation at scale. The risk is the same one Microsoft 365 tenants face with single sign-on: outsourcing the trust layer.

Schools have always been a soft target for credential harvesting, and AI tutors inherit that exposure. A model that builds a per-pupil curriculum also builds a per-pupil behavioural dossier, including reading level, attention patterns, family routine, and likely mental health flags. Every parent account becomes an authentication surface. Every tutor session becomes a session cookie that travels between vendor, school, and home. The regulatory perimeter for minors is thicker than the corporate one, in principle, but it has not caught up to the architecture.

The platform layer

What links the two stories is the platform layer underneath. Microsoft sets the rules for how identity flows across an enterprise; AI-vendor platforms set the rules for how instruction flows across a child. In both cases, the operator bought into a managed service on the promise that someone else would handle security, privacy, and compliance. In both cases, the managed-service tier turned out to be the exact surface the attackers found, and the buyers ended up reading the post-mortem.

The structural shift is not subtle. Two decades ago, defenders worried about patches. Now they worry about proxies and prompt-injection, session cookies and model-training data. The toolchain for offence updates faster than the procurement cycle for defence. A Fortune 500 CISO and a private-school headteacher are reading the same playbook by accident.

Stakes for the rest of the year

The honest read is that the 218 sessions disclosed on 13 July will not be the largest number attached to a Microsoft 365 phishing story before the end of 2026. The volume of identity-driven intrusion attempts reported across the sector has tracked upward every quarter for the past two years, and the tools are getting cheaper. The exposed directory gave defenders a rare early look at the inside of three concurrent operations. Most campaigns will not slip like that again. The ones that did taught a clear lesson, repeated in every breach report since 2023: identity is the perimeter, and the perimeter only holds when the operator is paying attention.

On the education side, the harder question is whether AI tutors will be regulated as ed-tech, as medical devices, or as neither. The families buying into the model have the disposable income to exit public oversight entirely. That means the first generation of children taught primarily by AI may grow up outside the data-protection regimes that apply to public schools. The vendors know this. So do the regulators. Neither has solved it.

What remains uncertain

The sources do not specify which Microsoft 365 tenants were targeted in the 13 July campaigns, nor whether any of the 218 captured sessions were used for downstream intrusions beyond the initial credential theft. The Hacker News reporting describes the exposed infrastructure in detail but does not name the operators or attribute the three rings to a known threat-actor cluster. On the AI tutor trend, Unusual Whales' reporting cites the schools' pedagogical structure but not a specific vendor, deployment scale, or compliance framework. Both stories will firm up as primary documents appear, and both will probably look smaller in the rear-view. For now, the exposed directory and the unusual schools are two faces of the same governance question: who audits the trust layer you bought?

Desk note: this piece draws on a single cybersecurity disclosure and a single media report on private education; where the two connect, it does so structurally, not via shared sources. Monexus reads them as parallel cases of platform governance rather than a coordinated campaign.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/thehackernews/3071
  • https://t.me/c/1725939944/3071
  • https://x.com/unusual_whales/status/1817600000000000000
  • https://x.com/middleeasteye/status/1817700000000000000

At the source.

Open the posts cited in this article.

Telegram postOpen original ↗

Live content may have changed since this article was published. Loading it contacts Telegram.

X postOpen original ↗

Live content may have changed since this article was published. Loading it contacts X.

X postOpen original ↗

Live content may have changed since this article was published. Loading it contacts X.

© 2026 Monexus Media · AI-native reporting from public-source material
The Monexus

Read with context.

Using this article and its related event records

Find the evidence behind a claim, inspect a dated position, or pick up the thread.

Source lookup is available to everyone. Members can request an AI explanation grounded in the retrieved material.

Browse event files →
One exposed folder just mapped three Microsoft 365 phishing rings, and the schools trying to teach around AI - The Monexus