Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

NovaCookies offers adversary-in-the-middle M365 session theft at just $320/month, commoditising attacks that bypass conventional MFA — enterprises still relying on push-based authentication face escalating exposure.

Summary written by editorial AI · Source link below

Filed by Dark Reading1 min readRead at source ↗

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

Editorial Analysis

Why it matters

Commoditised AitM phishing kits make session hijacking accessible to low-skill attackers, rendering push-based MFA insufficient for enterprise Microsoft 365 protection.

What to do

Accelerate migration to phishing-resistant authentication (FIDO2/passkeys) and implement token-binding or continuous-access evaluation in Entra ID.

Board brief

Session-stealing phishing kits are now sold as cheap subscriptions — traditional MFA no longer stops them; phishing-resistant alternatives are essential.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Dark Reading

External link — opens at Dark Reading in a new tab.

§
Continue with

More from the Threat Intel Desk