Skip to content
N0va Phishkit Exploits Microsoft Logins Across North America and Europe

N0va Phishkit Exploits Microsoft Logins Across North America and Europe

First seen 14 Sep 2026, 15:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 17:19 UTC
  • N0va phishkit targets Microsoft logins, bypassing MFA.
  • Affected sectors include government, healthcare, and technology.
  • Security teams should enhance monitoring and restrict device-code authentication.

The N0va phishkit has been identified as a significant threat targeting organizations in North America and Europe, including government, technology, consulting, and healthcare sectors. It exploits Microsoft device-code authentication to obtain access and refresh tokens, even after users complete multifactor authentication (MFA). The attack method involves lures impersonating trusted brands and leveraging compromised websites and cloud infrastructure. ANY.RUN disclosed the campaign in September 2026, highlighting the need for enhanced identity monitoring and access controls. Microsoft previously documented similar vulnerabilities in April 2026, indicating a recurring issue. Security teams are advised to audit device-code authentication and monitor for suspicious activity to mitigate risks. The scope of the attack is extensive, affecting enterprises managing Microsoft identities across multiple jurisdictions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-01
Microsoft documents similar vulnerabilities
Microsoft reported vulnerabilities in device-code authentication that were exploited in a separate campaign.
Esecurityplanet
2026-09-01
N0va phishkit identified
ANY.RUN researchers uncovered the N0va phishkit targeting organizations in North America and Europe.
Cybersecuritynews
2026-09-12
N0va phishkit disclosure
ANY.RUN disclosed the N0va phishkit, detailing its methods and impact on various sectors.
Esecurityplanet

More articles in this cluster (2)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed