NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
- ID
- 18209
- Status
- summarized
- Published
- 26 Aug 2026, 9:44 PM
- Fetched
- 26 Aug 2026, 11:40 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 26 Aug 2026, 11:44 PM
- Tags
- Audience
- developerssaas_founders
What happened
A phishing-as-a-service toolkit called NovaCookies is using genuine DocuSign envelopes to proxy Microsoft 365 sign-ins and steal authenticated sessions, bypassing MFA. Priced at $320/month and advertised on Telegram, it targets hundreds of organizations and includes flows for Okta and Entra domains federated to GoDaddy.
Why it matters
If your SaaS or workplace relies on MFA as the primary defense for M365 or Okta, this AitM kit defeats it by harvesting the session token post-login. Review conditional access policies, session lifetime controls, and user training on DocuSign lures, especially if you use Entra federation.
Discussion angle
How to implement session-bound authentication and conditional access to mitigate AitM phishing kits that bypass MFA.