#9
The Hacker News
general
August 26, 2026 at 13:44 UTC
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
By [email protected] (The Hacker News)
AI Summary
Researchers at Island disclosed NovaCookies, an adversary-in-the-middle (AitM) phishing toolkit sold for $320/month that abuses genuine DocuSign notifications to proxy Microsoft 365 sign-ins and capture authenticated sessions, bypassing MFA entirely. The platform lowers the barrier for credential theft attacks by providing subscription-based infrastructure that handles session cookie harvesting automatically. Security teams should implement phishing-resistant authentication (FIDO2/passkeys) and monitor for AitM-style proxy indicators in M365 telemetry.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →