There’s a specific kind of frustration that comes with seeing a browser vendor store plaintext passwords in 2026, and it’s not just annoyance at poor engineering. It’s the recognition that the entire security architecture built around credential hygiene can be undercut in a single swoop by a product your users trust. That’s the operational thread running through this week’s news: the controls you’ve carefully assembled keep getting flanked from unexpected directions. Cleartext credentials in Microsoft Edge, a sophisticated adversary-in-the-middle phishing campaign targeting US organizations, and the FTC’s final enforcement action against location data broker Kochava all point to the same cybersecurity failure mode. The perimeter assumes trustworthy components beneath it. That assumption keeps getting punished.

What’s Actually Happening With Cleartext Passwords in Edge

Researchers at SANS ISC confirmed this week that Microsoft Edge is storing passwords in cleartext under certain conditions. Yes, in 2026. The specifics matter operationally: this isn’t a theoretical edge case about obscure configurations. If an attacker has any level of local access to an endpoint, whether through malware, a compromised account, or physical proximity, they can potentially harvest credentials that your users expect to be protected by the browser’s built-in vault.

The practical blast radius is significant. Enterprise environments where employees save credentials in Edge for internal tools, cloud portals, or SaaS applications now have a latent credential exposure that bypasses everything you’ve done at the network perimeter. Your firewall rules, your threat detection alerts, your brute-force lockout policies: none of those matter once an attacker reads credentials out of a flat file. This is the kind of vulnerability that feeds post-exploitation phases quietly and persistently, long after initial access is achieved.

The immediate operational response is straightforward. Disable browser-native password saving via Group Policy, push a managed credential store like a proper enterprise password manager, and audit which machines have Edge deployed with default settings. If you haven’t reviewed your browser hardening baseline in the last six months, this is your reason to do it this week.

AI-assisted phishing campaign targeting US organizations with adversary-in-the-middle techniques
Microsoft has warned of a sophisticated AitM phishing campaign using fake conduct reports to harvest session tokens from US organizations.

The AitM Phishing Campaign That Makes MFA Irrelevant

While the Edge story is embarrassing for Microsoft, the phishing campaign Microsoft itself is warning about this week is more immediately dangerous for most organizations. The attack lures targets with a fake employee conduct report, driving them to a lookalike Microsoft login page running an adversary-in-the-middle proxy. The proxy captures not just credentials but the active session token, which means your MFA controls are effectively bypassed. The attacker doesn’t need your password and your one-time code. They just need your already-authenticated session.

AitM attacks have been around for a few years, but the targeting here deserves attention. These aren’t spray-and-pray credential harvesting runs. The conduct report lure is carefully chosen because it creates urgency and authority, the two psychological levers that make employees skip their instinct to pause. Someone who receives an email claiming a workplace conduct report requires their immediate review will often click before thinking. That’s not a user training failure; that’s a well-engineered social engineering payload.

Phishing-resistant authentication, specifically FIDO2 passkeys or hardware security keys, is the actual fix for AitM. Session tokens stolen through a proxy are useless when the initial authentication was bound to a physical device that didn’t traverse the attacker’s infrastructure. If your organization is still on TOTP codes or SMS-based MFA, this campaign is a concrete reason to accelerate the migration timeline. Treat it as a forcing function, not a distant priority.

Kochava and the Data You Didn’t Know You Were Leaking

The FTC’s enforcement action banning data broker Kochava from selling sensitive location data landed this week, and the operational implications extend beyond privacy compliance. Kochava was selling precise geolocation records showing users visiting healthcare clinics, houses of worship, and other sensitive locations. The buyers of that data could include threat actors who use it for targeted social engineering, physical surveillance of executives, or building dossiers on employees with access to sensitive systems.

Security teams rarely think of commercial data brokers as part of their threat model. That’s a gap worth closing. The location data your organization’s mobile apps collect, or that employees’ personal devices generate, doesn’t stay within your walls. It flows through advertising SDKs and data aggregators and can end up in places that directly enable attacks. The threat-protection value of knowing this is in building controls around mobile device management and educating staff about location permission hygiene on personal devices that touch corporate resources.

FTC enforcement action against Kochava banning sensitive location data sales
The FTC’s final order against Kochava marks a significant moment in regulating what data brokers can sell and to whom.

Hardening Steps Your Team Can Execute This Week

These stories share a structural problem: each one represents a control assumption that turned out to be wrong. You assumed browser credential vaults were encrypted. You assumed MFA was sufficient. You assumed location data stayed in your control. Security hardening is the process of systematically questioning those assumptions before attackers exploit them. Here’s what that looks like practically right now.

  • Disable browser password saving in Edge via Group Policy Object (GPO) or your MDM configuration profile. Push a managed enterprise password manager as the alternative so users don’t revert to sticky notes.
  • Audit your MFA posture. Identify which applications and user groups are still using TOTP or SMS MFA, then prioritize migrating high-value accounts to FIDO2 hardware keys or passkeys first.
  • Review mobile app location permissions on corporate-managed devices. Revoke unnecessary location access at the MDM policy level. Brief IT help desk staff to flag unusual permission requests.
  • Check your Apache HTTP Server version against the newly disclosed CVE-2026-23918, a CVSS 8.8 double-free flaw in HTTP/2 handling that enables potential RCE. Patch or apply mitigations before this one gets weaponized widely.
  • Test your email gateway’s AitM phishing detection. Most URL-rewriting controls don’t catch reverse proxy phishing pages because the initial URL looks clean. Evaluate whether your gateway vendor has updated detection logic for proxy-based AitM kits.
  • Run a quick inventory of where Edge is deployed with default settings. Focus on machines that have local admin access or that users regularly access internal portals from.

Defense in depth means each control layer needs to stand independently. When the browser fails, your password manager still works. When MFA tokens are stolen via AitM, hardware-bound authentication still holds. When your perimeter tools miss a phishing page, conditional access policies on session behavior still flag anomalies. The goal is stacking controls so that a single component’s failure doesn’t cascade into a full compromise. That framing should guide your security hardening roadmap, not just this week but structurally.

The Apache flaw is worth a separate callout because web server vulnerabilities have historically been exploited fast once proof-of-concept code surfaces. HTTP/2 is default-enabled on most modern Apache deployments, so the affected surface is broad. Watch the ASF advisory for mitigation guidance if you can’t patch immediately, and consider temporarily disabling HTTP/2 on externally facing servers while you verify patch coverage across your infrastructure.

None of this is glamorous incident response work. Most of it is configuration hygiene. But the stories this week are a reminder that glamorous incidents, the ones that make headlines, are usually built on unglamorous failures in the basics. A cleartext password in a browser, a clicked conduct report, a location record sold to the wrong buyer. Your cybersecurity posture lives or dies in those small gaps.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.