Wire
09:38ZDDGEOPOLITUK Maritime Trade Operations reports an incident involving a tanker and military forces in the Gulf of Oman n…09:38ZGEOPWATCHTrump says media never talked about his amazing accomplishments, for example, under his regime, "Iran has tur…09:37ZOSINTLIVEWarTranslatedRussia's Defense Ministry claims 1,052 UAVs were shot down in 24 hours.Over 300 Ukrainian drones…09:37ZOSINTLIVEWarTranslatedA gunner in a Yak-52 cockpit shot down a Shahed drone near Odesa over the sea. https://twitter.c…09:37ZWARTRANSLAThe Tyumen refinery was attacked this morning in Tyumen.🔥Tyumen refinery right now.09:36ZJAHANTASNIHebrew media: Washington is in a weak position.09:35ZTHECRADLEMSaudi air defense forces reportedly intercept two ballistic missiles launched from YemenReuters reports that…09:34ZFARSNEWSINHebrew media: Strait of Hormuz is Iran's greatest strategic achievement in history 🔹Hebrew newspaper "Ma'ari…
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusTech

One exposed folder just mapped three Microsoft 365 phishing rings, and the schools trying to teach around AI

A misconfigured server laid bare three campaigns targeting Microsoft 365 logins, while a separate debate over AI tutors in private schools reopens the question of who sets the curriculum.

A graphic displays the word "COUPONS" in bold white capital letters over a purple and dark blue checkered background with a grainy texture.
A graphic displays the word "COUPONS" in bold white capital letters over a purple and dark blue checkered background with a grainy texture. @WIRED · Telegram

On 13 July 2026, researchers at The Hacker News catalogued three distinct phishing operations against Microsoft 365 tenants after a single misconfigured open directory revealed their inner workings. The exposed server logged 218 credential-capture sessions and exposed the operators' tooling: two adversarial-in-the-middle proxies using the Evilginx framework and a parallel device-code phishing track that abuses Microsoft's own sign-in flow. Within hours, security teams across the Fortune 500 were comparing notes against shared indicators of compromise. The lesson is not new, but it is sharper than usual. Identity is the perimeter now, and the perimeter is leaking.

The incident shows how fragile the human-authentication layer has become. Microsoft 365's single sign-on was sold to enterprises as a productivity upgrade, then quietly became the highest-value target on the internet. Once an attacker captures a session cookie, they do not need a password, a token, or a vulnerability. They are already the user. Evilginx turns that asymmetry into a product: a relay that sits between the victim and Microsoft's legitimate login page, harvests the session cookie at the moment of authentication, and forwards everything else. Device-code phishing takes a different path. It tricks a user into entering a short code at Microsoft's real sign-in page while the attacker, on a separate device, completes the corresponding flow. Either route ends with the same result: a valid session for a paying tenant.

Three rings, one folder

The misconfigured directory did the police work. Investigators said one open bucket exposed infrastructure tied to three campaigns running in parallel, including command-and-control scripts, the Evilginx phishing kit configuration, and session logs with enough metadata to fingerprint the operators. The 218 capture sessions are a floor, not a ceiling: only the campaigns that wrote to that directory are visible. The other two operations used the same open-folder footprint, which is what linked them in the first place.

For defenders, the artefact map matters more than the headline number. Shared hosting, reused certificates, and a common logging path suggest coordination or at least a common supplier. Either reading points the same direction: phishing-as-a-service is now modular enough to run three campaigns from one rented server, and careless operation gives defenders the receipts.

The AI tutor question

A separate thread from 14 July raises a parallel governance problem. According to Unusual Whales' reporting on a private-school trend, high-earning families are moving children into schools that replace the language of "teachers" with "guides" or "coaches," and hand the actual instruction over to AI tutors that tailor the curriculum to each child. The pitch is differentiation at scale. The risk is the same one Microsoft 365 tenants face with single sign-on: outsourcing the trust layer.

Schools have always been a soft target for credential harvesting, and AI tutors inherit that exposure. A model that builds a per-pupil curriculum also builds a per-pupil behavioural dossier, including reading level, attention patterns, family routine, and likely mental health flags. Every parent account becomes an authentication surface. Every tutor session becomes a session cookie that travels between vendor, school, and home. The regulatory perimeter for minors is thicker than the corporate one, in principle, but it has not caught up to the architecture.

The platform layer

What links the two stories is the platform layer underneath. Microsoft sets the rules for how identity flows across an enterprise; AI-vendor platforms set the rules for how instruction flows across a child. In both cases, the operator bought into a managed service on the promise that someone else would handle security, privacy, and compliance. In both cases, the managed-service tier turned out to be the exact surface the attackers found, and the buyers ended up reading the post-mortem.

The structural shift is not subtle. Two decades ago, defenders worried about patches. Now they worry about proxies and prompt-injection, session cookies and model-training data. The toolchain for offence updates faster than the procurement cycle for defence. A Fortune 500 CISO and a private-school headteacher are reading the same playbook by accident.

Stakes for the rest of the year

The honest read is that the 218 sessions disclosed on 13 July will not be the largest number attached to a Microsoft 365 phishing story before the end of 2026. The volume of identity-driven intrusion attempts reported across the sector has tracked upward every quarter for the past two years, and the tools are getting cheaper. The exposed directory gave defenders a rare early look at the inside of three concurrent operations. Most campaigns will not slip like that again. The ones that did taught a clear lesson, repeated in every breach report since 2023: identity is the perimeter, and the perimeter only holds when the operator is paying attention.

On the education side, the harder question is whether AI tutors will be regulated as ed-tech, as medical devices, or as neither. The families buying into the model have the disposable income to exit public oversight entirely. That means the first generation of children taught primarily by AI may grow up outside the data-protection regimes that apply to public schools. The vendors know this. So do the regulators. Neither has solved it.

What remains uncertain

The sources do not specify which Microsoft 365 tenants were targeted in the 13 July campaigns, nor whether any of the 218 captured sessions were used for downstream intrusions beyond the initial credential theft. The Hacker News reporting describes the exposed infrastructure in detail but does not name the operators or attribute the three rings to a known threat-actor cluster. On the AI tutor trend, Unusual Whales' reporting cites the schools' pedagogical structure but not a specific vendor, deployment scale, or compliance framework. Both stories will firm up as primary documents appear, and both will probably look smaller in the rear-view. For now, the exposed directory and the unusual schools are two faces of the same governance question: who audits the trust layer you bought?

Desk note: this piece draws on a single cybersecurity disclosure and a single media report on private education; where the two connect, it does so structurally, not via shared sources. Monexus reads them as parallel cases of platform governance rather than a coordinated campaign.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/thehackernews/3071
  • https://t.me/c/1725939944/3071
  • https://x.com/unusual_whales/status/1817600000000000000
  • https://x.com/middleeasteye/status/1817700000000000000
© 2026 Monexus Media · AI-native reporting from public-source material