Back to the radar Cybersecurity

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

Cybersecurity

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

In context

  • Topic: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
  • Source: Dark Reading
  • Published: 26/08/2026

Continue reading at the original source →

Excerpt published automatically by the site radar. The full text belongs to its publisher and is linked above.

Why it matters

Most incidents that end up being expensive did not start with a sophisticated technique. They started with an account that should have been closed when somebody resigned, a server nobody knew was still on, or a broad permission granted to unblock someone that then stayed forever.

I read it with the same short list as always: second factor on anything that grants access, tested backups kept off the network, and a real inventory of what is exposed to the internet. It is not glamorous, and it still prevents most disasters.

What usually goes wrong

Where it usually breaks is response, not prevention. There are tools, there are alerts, and when something real happens nobody knows who decides to disconnect, who gets called first, or what the customer is told. Valuable hours get lost arguing about that while the problem grows.

What to watch

  • What could be restored and how fast — a backup that was never tested does not count.
  • How it was communicated to customers and regulators, which is where reputational cost is decided.
  • Whether third parties or suppliers were in the chain, because the perimeter now includes partners.

How I read this entry

What I would review this very week is access: accounts belonging to people who left, permissions that grew without anyone trimming them, and shared credentials everybody swears do not exist. It is the least glamorous work and the one that cuts off the most attacks.

This entry is an excerpt from the original source, selected by the site radar. The commentary above is the site's own and does not belong to the cited publisher.
Share

Living through this in your own team?

Open the chat and tell me how you're handling it. I'm interested in comparing notes.

Keep reading

More entries from the radar

See all
Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.