Esecurityplanet N0va Phishkit Exploits Microsoft Logins Across North America and Europe
Article Content
- •N0va phishkit targets Microsoft logins, bypassing MFA.
- •Affected sectors include government, healthcare, and technology.
- •Security teams should enhance monitoring and restrict device-code authentication.
The N0va phishkit has been identified as a significant threat targeting organizations in North America and Europe, including government, technology, consulting, and healthcare sectors. It exploits Microsoft device-code authentication to obtain access and refresh tokens, even after users complete multifactor authentication (MFA). The attack method involves lures impersonating trusted brands and leveraging compromised websites and cloud infrastructure. ANY.RUN disclosed the campaign in September 2026, highlighting the need for enhanced identity monitoring and access controls. Microsoft previously documented similar vulnerabilities in April 2026, indicating a recurring issue. Security teams are advised to audit device-code authentication and monitor for suspicious activity to mitigate risks. The scope of the attack is extensive, affecting enterprises managing Microsoft identities across multiple jurisdictions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…