Back to all news
Security

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News·August 26, 2026·1 min read
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Cybersecurity researchers disclosed a new adversary-in-the-middle phishing toolkit called NovaCookies that acts as a proxy to redirect Microsoft 365 sign-ins while capturing authenticated sessions. Island characterized the $320/month service as a subscription-based phishing platform. The campaign abuses genuine Docusign notifications to steal Microsoft 365 sessions.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store