Home / Aug 27, 2026 / Story
0
#9 The Hacker News general August 26, 2026 at 13:44 UTC

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

By [email protected] (The Hacker News)

AI Summary

Researchers at Island disclosed NovaCookies, an adversary-in-the-middle (AitM) phishing toolkit sold for $320/month that abuses genuine DocuSign notifications to proxy Microsoft 365 sign-ins and capture authenticated sessions, bypassing MFA entirely. The platform lowers the barrier for credential theft attacks by providing subscription-based infrastructure that handles session cookie harvesting automatically. Security teams should implement phishing-resistant authentication (FIDO2/passkeys) and monitor for AitM-style proxy indicators in M365 telemetry.

Relevance score: 80.0/100

# More from August 27