NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.

In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 06.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 388 requests (recent log) 213.209.159.175 — 263 requests (recent log) 216.244.66.232 — 95 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 10.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 104.194.8.156 — 1007 requests (recent log) 89.167.35.212 — 464 requests (recent log) 216.244.66.232 — 135 requests (recent