ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

N0va Phishkit Steals Tokens for SSO Access at US and EU Organizations; Separate Sponsored Piece Flags Lingering Microsoft 365 Shared Access

mediumPhishing & fraudexploited in the wildimportance 58
What's new: First merged story for this topic (previous summary: none). New developments: The Hacker News (2026-09-16) disclosed the N0va phishkit campaign and its device-code-phishing-to-token-theft chain, with ANY.RUN providing the /api/verification/init detection pattern; BleepingComputer (2026-09-18) added a tenfold-sponsored governance angle reporting that shared Microsoft 365 access often persists…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

The N0va phishing kit targets government, technology, consulting, and healthcare organizations in North America and Europe with trusted-brand lures, using device code phishing to capture access and refresh tokens and gain SSO access to corporate resources.…

The Hacker News (2026-09-16) reports that the N0va phishing kit targets organizations in government, technology, consulting, and healthcare across North America and Europe with lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Victims are guided through legitimate authentication flows, including device code phishing; N0va then captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish SSO access to corporate resources, enabling payment fraud, data exposure, and operational disruption. ANY.RUN tracks the campaign via its characteristic /api/verification/init URL pattern and demonstrates detection in its interactive sandbox; no CVE identifiers were cited in either report. The second item (BleepingComputer, 2026-09-18) is a tenfold-sponsored article, not coverage of the N0va campaign: it argues shared access in Microsoft 365 frequently outlives its original purpose, citing a Wire survey in which 61% of security leads said access to shared files often remains active longer than intended. It calls native SharePoint Advanced Management sharing reports too coarse and site-level exports too manual, then promotes tenfold's identity governance platform, offering centralized visibility into shared Teams, OneDrive, and SharePoint content plus owner-driven access reviews with confirm-or-revoke actions. The two reports address the same identity-and-access-security theme from the attack side and the governance side, but the sponsored article does not mention N0va.

  • N0va phishkit targets organizations in government, technology, consulting, and healthcare across North America and Europe (The Hacker News, 2026-09-16).
  • Lures impersonate Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Note: the report's bullet list omits Google Drive, which appears only in its summary.
  • Attack chain: victims pass through legitimate authentication flows including device code phishing; N0va captures access and refresh tokens, then abuses token-exchange or device-registration mechanisms to establish SSO access.
  • Compromised identities enable payment fraud, data exposure, and operational disruption.
  • ANY.RUN identifies the campaign via a distinctive /api/verification/init URL query pattern and demonstrates detection in its interactive sandbox.
  • No CVE identifiers, affected product versions, or victim counts were provided in either report.
  • The BleepingComputer item (2026-09-18) is a tenfold-sponsored article and does not reference the N0va campaign.
  • Per a Wire survey cited in the sponsored article, 61% of security leads say access to shared files often remains active longer than intended.

Coverage timeline

  1. · 2d ago
    The Hacker News· 58
    N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

    N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.

  2. · 4h ago
    BleepingComputer· 12
    Secure enterprise sharing with access reviews for Microsoft 365

    tenfold-sponsored article warns Microsoft 365 file sharing often outlives its purpose and pitches its identity governance platform for access reviews.