N0va Phishkit Steals Tokens for SSO Access at US and EU Organizations; Separate Sponsored Piece Flags Lingering Microsoft 365 Shared Access
The N0va phishing kit targets government, technology, consulting, and healthcare organizations in North America and Europe with trusted-brand lures, using device code phishing to capture access and refresh tokens and gain SSO access to corporate resources.…
The Hacker News (2026-09-16) reports that the N0va phishing kit targets organizations in government, technology, consulting, and healthcare across North America and Europe with lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Victims are guided through legitimate authentication flows, including device code phishing; N0va then captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish SSO access to corporate resources, enabling payment fraud, data exposure, and operational disruption. ANY.RUN tracks the campaign via its characteristic /api/verification/init URL pattern and demonstrates detection in its interactive sandbox; no CVE identifiers were cited in either report. The second item (BleepingComputer, 2026-09-18) is a tenfold-sponsored article, not coverage of the N0va campaign: it argues shared access in Microsoft 365 frequently outlives its original purpose, citing a Wire survey in which 61% of security leads said access to shared files often remains active longer than intended. It calls native SharePoint Advanced Management sharing reports too coarse and site-level exports too manual, then promotes tenfold's identity governance platform, offering centralized visibility into shared Teams, OneDrive, and SharePoint content plus owner-driven access reviews with confirm-or-revoke actions. The two reports address the same identity-and-access-security theme from the attack side and the governance side, but the sponsored article does not mention N0va.
- N0va phishkit targets organizations in government, technology, consulting, and healthcare across North America and Europe (The Hacker News, 2026-09-16).
- Lures impersonate Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Note: the report's bullet list omits Google Drive, which appears only in its summary.
- Attack chain: victims pass through legitimate authentication flows including device code phishing; N0va captures access and refresh tokens, then abuses token-exchange or device-registration mechanisms to establish SSO access.
- Compromised identities enable payment fraud, data exposure, and operational disruption.
- ANY.RUN identifies the campaign via a distinctive /api/verification/init URL query pattern and demonstrates detection in its interactive sandbox.
- No CVE identifiers, affected product versions, or victim counts were provided in either report.
- The BleepingComputer item (2026-09-18) is a tenfold-sponsored article and does not reference the N0va campaign.
- Per a Wire survey cited in the sponsored article, 61% of security leads say access to shared files often remains active longer than intended.
Coverage timelineoldest first · each row is one article
- · 2d agoN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News· 58
N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.
- · 4h agoSecure enterprise sharing with access reviews for Microsoft 365
BleepingComputer· 12
tenfold-sponsored article warns Microsoft 365 file sharing often outlives its purpose and pitches its identity governance platform for access reviews.