mfabypass (3)

31266419499?profile=RESIZE_180x180Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time.  The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems.  Victims are directed to what appears to be a legitimate login process, allowing the service to collect credentials and intercept the authenticated session after the user enters a password and completes multi-fac

31169618668?profile=RESIZE_400xNew research from Barracuda Networks has identified a surge in attacks by Saiga 2FA, a small-scale but sophisticated phishing kit.  Activity increased significantly in February 2026, following earlier sightings targeting legal organizations in Australia in 2025.  The kit operates as a boutique service rather than a high-volume automated platform, focusing on highly targeted campaigns against enterprise email users.   Saiga 2FA serves as an Adversary-in-the-Middle tool that bypasses multifactor a

31016873059?profile=RESIZE_400xThe Hoxhunt 2025 Cyber Threat Intelligence Report delivers a sobering message for security professionals: the most dangerous threats are no longer the most obvious ones.  As 2026 approaches, enterprises are no longer fighting clumsy, error-riddled bulk spam; they are facing a quiet revolution where sophisticated, convincing attacks blend seamlessly into daily workflows, fueled by AI and advanced token-theft toolkits.

See:  https://hoxhunt.com/guide/threat-intelligence-report

The report, based on