A reported campaign against US and Canadian universities shows how a webmail flaw can shift the fight from phishing to session theft and account-level compromise.