ZeroHour

Search: “workload identity”

2 stories in the last 30d

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

CloudSEK uncovered BigBear 2.0, a PhaaS operation that captured 4,148 Microsoft 365 session cookies, hijacking authenticated sessions after MFA via AiTM proxy.

CloudSEK infiltrated the BigBear 2.0 phishing-as-a-service panel in June, finding 5,137 credential records tied to 461 organizations in over 40 countries, including 4,148 captured session cookies and 474 completed post-MFA logins. The operation, built on Evilginx2, uses an attacker-controlled reverse proxy to steal authenticated session cookies and residential proxies to defeat location-based Conditional Access checks, while custom code disables FIDO2/WebAuthn on phishing pages. At least five affiliates operated 42 VPS nodes, with IT services and managed service providers the most targeted sector.

CSO Online · 9d agoPhishing & fraud in the wild1

New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.

The N0va phishkit uses lures imitating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to draw victims into a device code authentication flow. After the user completes legitimate authentication, N0va captures access and refresh tokens and abuses token-exchange and device-registration mechanisms to establish persistent SSO access to corporate resources. Because the flow relies on real Microsoft authentication, it can evade MFA-focused detections, and token access can outlive takedown of the phishing page. ANY.RUN says it observed the campaign in sandbox sessions, with targeting spanning government, technology, consulting, and healthcare sectors.

Cyber Security News · 7d agoPhishing & fraud in the wild1