July 14, 2026
- A misconfigured public Python HTTP server exposed three separate AiTM phishing operations run by operators "codemado," "mail-argenta," and "saroula01," revealing custom Evilginx forks used to bypass MFA and harvest credentials across platforms for over a year. Lexfo · Cloud & Identity
in New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs