Find notable cyber news and cases, enriched with sources, timelines, and signals.

N0va phishing campaign targeting North America and Europe

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-account access that can expose sensitive data, business systems, and cloud resources. The operation uses familiar business-platform lures to increase trust and reduce suspicion. The resulting access can spread from a single account into broader corporate compromise.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

RecruitTrap recruitment-themed phishing campaign

Campaign
H score25 First: 14.08.2026 13:57 Last: 14.08.2026 13:57 Sources 1

About this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Timeline

  1. 16.09.2026 14:58 2 articles · 2h ago

    N0va phishing campaign targets North America and Europe

    Initial Disclosure

    N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted business services and abuse legitimate authentication flows. The activity has been observed across government, technology, consulting, healthcare, and other sectors, and successful compromises can capture access and refresh tokens to establish SSO access to email, files, cloud applications, and other corporate resources.

    Show sources