CISA Advisories

8.7M Travelers Exposed 🛬 and a $320 Tool That Walks Past Your MFA

Two stories from today's security news deserve your attention: one exposed the personal details of nearly 9 million airline passengers, and the other proves that the "extra login code" you rely on is no longer the safety net you think it is.

🛬 8.7 Million Airport Customers Just Had Their Details Taken

Attackers breached the operator behind Manchester, London Stansted, and East Midlands airports and accessed data belonging to 8.7 million customers. The stolen information came from everyday conveniences — car park bookings, airport lounge reservations, fast-track passes, and free in-airport WiFi signups — and includes email addresses, phone numbers, vehicle registration numbers, and postcodes.

So why does this matter if you weren't on a flight? Because none of that feels sensitive until it is combined. An attacker who knows your email, your phone number, your car's plate, and roughly where you live has everything needed to build a convincing scam — a fake "parking fine" text, a "your booking failed" email, or a phone call that sounds legitimate because the caller already knows your details. This is also a reminder that the WiFi signup form you breeze through at the gate is a real data collection point, and the company holding that data may not protect it as carefully as you would.

Read more →

🍪 "NovaCookies" Rents Out MFA Bypass for $320 a Month

A criminal service called NovaCookies is selling ready-made phishing infrastructure for the price of a decent gym membership. Here is the clever, unsettling part: it does not try to steal your password and second factor to reuse them later. It sits invisibly between you and the real Microsoft 365 login page, passes your credentials through so the login genuinely succeeds, and then steals the session cookie — the digital wristband your browser gets after you have already proven who you are. With that wristband in hand, the attacker is inside your account and never has to face a multi-factor prompt at all.

Researchers at Island found at least 755 domains supporting the operation, targeting hundreds of organizations, often disguised as a shared DocuSign document. The takeaway for any business: standard MFA via text or app codes is no longer enough on its own. Move toward phishing-resistant MFA such as passkeys or hardware security keys, watch for logins from unusual devices or locations, and if you suspect a compromise, revoke active sessions and refresh tokens — a password reset alone will not evict an attacker holding a valid cookie.

Read more →

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts