<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions]]></title><description><![CDATA[<p dir="auto">Security researchers have uncovered a new adversary-in-the-middle (AitM) phishing toolkit dubbed <strong>NovaCookies</strong>, which is being leveraged in active campaigns that abuse legitimate Docusign notifications to intercept Microsoft 365 authentication sessions.</p>
<p dir="auto">According to a report from Island, shared ahead of publication, NovaCookies operates as a subscription-based phishing platform priced at <strong>$320/month</strong>. The service functions as a proxy, sitting between the victim and genuine Microsoft 365 sign-in pages to capture authenticated session cookies in real time.</p>
<ul>
<li>
<p dir="auto">The attacks begin with a legitimate-looking Docusign notification, often forwarded or spoofed, to lure targets into clicking a link.</p>
</li>
<li>
<p dir="auto">Victims are then redirected through a malicious proxy that relays their login request to the real Microsoft 365 service.</p>
</li>
<li>
<p dir="auto">Once the victim authenticates, NovaCookies captures the session token, allowing the attacker to maintain access even after the victim logs out.</p>
</li>
<li>
<p dir="auto">The phishing kit is rented as a service, lowering the technical barrier for aspiring attackers.</p>
</li>
<li>
<p dir="auto">Campaigns appear focused on organizations relying on <strong>Microsoft 365</strong> for email and collaboration.</p>
</li>
<li>
<p dir="auto">The abuse of genuine Docusign notifications adds a layer of trust, making the phishing attempt harder to detect.</p>
</li>
</ul>
<p dir="auto">To reduce exposure, organizations should enforce phishing-resistant multi-factor authentication (MFA), such as FIDO2 security keys, and monitor for unusual session activity or impossible travel patterns.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your organization taken steps to harden Microsoft 365 sessions against AitM phishing toolkits like NovaCookies?</p>
]]></description><link>https://xploitlk.com/topic/116/novacookies-campaigns-abuse-genuine-docusign-notifications-to-steal-microsoft-365-sessions</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:26:41 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/116.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 27 Aug 2026 06:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>