#session-hijacking
20 stories taggedsession-hijacking.

Machine Accounts Are Now the Likeliest Way Into Your Company, and Almost Nobody Is Watching Them
A new SpyCloud survey of 750 security leaders finds that automated accounts and AI agents have become the single most common entry point for attackers, yet fewer than four in ten organisations are actively monitoring them.

JSCeal: The Hidden JavaScript Malware Stealing Google Logins
Researchers at Check Point have pulled apart a stealthy piece of malware that hides inside compiled JavaScript, steals browser session cookies, and watches what victims do online.

Schneider Electric patches weak-randomness flaw across dozens of grid control products
A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem
Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.

Anthropic warns Claude accounts are being hijacked by password-stealing malware
The AI company says common infostealer malware on customer PCs has been lifting active Claude login sessions, letting criminals sign in without a password and burn through usage limits.

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026
As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

Passing the Login Test Does Not Mean You Let In the Right Person
Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows
A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks
A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)
Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

Insurance phishing gets faster: attackers now hijack accounts in real time
Researchers say fake insurance login pages are being run live, with criminals stepping in the moment a victim types their password.

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers
The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions
A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.