'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
2026-08-26T14:51:34Z•770cae3d0a10f65f7e273b1c3b2581bd6f3975537dedfefc683038193179fd8f
CVE-2026-19478CVE-2026-73570AI-agentsAI-securityLLM-poisoningMicrosoft 365OT-securityadversary-in-the-middlebanking-trojanbotnetcloud-securitycredential-theftcybercrimeexploitationindustrial-control-systemsinfostealermalwarenation-statephishingransomwaresession-theftthreat-intelligencevulnerabilitieszero-click
What happened
Dark Reading feed covering active exploitation, malware and phishing campaigns, cloud and identity threats, AI-agent security risks, critical vulnerabilities, OT exposure, and cybercrime operations. Notable items include NovaCookies adversary-in-the-middle phishing targeting Microsoft 365 sessions, exploited Zimbra CVE-2026-73570, a critical GitLab zero-click flaw (CVE-2026-19478), malware families such as Amatera, SynkLoader, ToxicPanda, Grandoreiro, and Evooo1Bot, plus emerging risks involving LLM poisoning and rogue AI agents.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 770cae3d0a10f65f7e273b1c3b2581bd6f3975537dedfefc683038193179fd8f
- Enrichment time
- 2026-08-26T14:51:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.