'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
LowDark Reading · Elizabeth Montalbano·
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- Microsoft
- Reported by
- 1 outlet
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
Read the full story at darkreading.com ↗Established Source
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Coverage
One outlet has carried this so far.
2026-08-26 11:33 UTC
Related stories
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Infosecurity Magazine · 2026-09-16
- Ministry of Justice apologizes after court staff accessed Southport victims' files
The Register · 2026-09-16
- Windows Server 2022 reaches end of mainstream support next month
BleepingComputer · 2026-09-16