AI Weekly Malaysia

Back to items Summaries

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

ID
18209
Status
summarized
Published
26 Aug 2026, 9:44 PM
Fetched
26 Aug 2026, 11:40 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
26 Aug 2026, 11:44 PM
Tags
Audience
developerssaas_founders

What happened

A phishing-as-a-service toolkit called NovaCookies is using genuine DocuSign envelopes to proxy Microsoft 365 sign-ins and steal authenticated sessions, bypassing MFA. Priced at $320/month and advertised on Telegram, it targets hundreds of organizations and includes flows for Okta and Entra domains federated to GoDaddy.

Why it matters

If your SaaS or workplace relies on MFA as the primary defense for M365 or Okta, this AitM kit defeats it by harvesting the session token post-login. Review conditional access policies, session lifetime controls, and user training on DocuSign lures, especially if you use Entra federation.

Discussion angle

How to implement session-bound authentication and conditional access to mitigate AitM phishing kits that bypass MFA.

Top