'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

2026-08-26T14:51:34Z770cae3d0a10f65f7e273b1c3b2581bd6f3975537dedfefc683038193179fd8f
CVE-2026-19478CVE-2026-73570AI-agentsAI-securityLLM-poisoningMicrosoft 365OT-securityadversary-in-the-middlebanking-trojanbotnetcloud-securitycredential-theftcybercrimeexploitationindustrial-control-systemsinfostealermalwarenation-statephishingransomwaresession-theftthreat-intelligencevulnerabilitieszero-click

What happened

Dark Reading feed covering active exploitation, malware and phishing campaigns, cloud and identity threats, AI-agent security risks, critical vulnerabilities, OT exposure, and cybercrime operations. Notable items include NovaCookies adversary-in-the-middle phishing targeting Microsoft 365 sessions, exploited Zimbra CVE-2026-73570, a critical GitLab zero-click flaw (CVE-2026-19478), malware families such as Amatera, SynkLoader, ToxicPanda, Grandoreiro, and Evooo1Bot, plus emerging risks involving LLM poisoning and rogue AI agents.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
770cae3d0a10f65f7e273b1c3b2581bd6f3975537dedfefc683038193179fd8f
Enrichment time
2026-08-26T14:51:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month · Baitaphish