Tag

#session-hijacking

20 stories taggedsession-hijacking.

A data center environment with server racks, focusing on indicator lights and automated processes, with transparent overlay showing invisible machine account lo
Identity & Access

Machine Accounts Are Now the Likeliest Way Into Your Company, and Almost Nobody Is Watching Them

A new SpyCloud survey of 750 security leaders finds that automated accounts and AI agents have become the single most common entry point for attackers, yet fewer than four in ten organisations are actively monitoring them.

4 min read
A security researcher's workstation showing decompiled JavaScript code on the screen, Google login credentials highlighted, malware analysis tools open, network
Threat Intelligence

JSCeal: The Hidden JavaScript Malware Stealing Google Logins

Researchers at Check Point have pulled apart a stealthy piece of malware that hides inside compiled JavaScript, steals browser session cookies, and watches what victims do online.

4 min read
An industrial control room with SCADA systems and power grid monitoring displays, overlaid session token streams with weak encryption indicators highlighted in
Vulnerabilities

Schneider Electric patches weak-randomness flaw across dozens of grid control products

A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

3 min read
A dual-monitor workstation displaying a compromised login session on one screen and an infostealer malware interface on the other, digital fingerprints and sess
Identity & Access

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem

Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.

4 min read
A compromised Windows desktop showing infostealer malware activity in background processes, Anthropic Claude login screen in foreground being accessed without c
Identity & Access

Anthropic warns Claude accounts are being hijacked by password-stealing malware

The AI company says common infostealer malware on customer PCs has been lifting active Claude login sessions, letting criminals sign in without a password and burn through usage limits.

3 min read
A security operations center with multiple displays showing interconnected identity verification systems, access logs, and authentication protocols visualized a
Identity & Access

Why 'Identity Fabric' Is the Phrase Every Security Team Will Hear in 2026

As passwords fade and machine accounts outnumber humans, a new architecture promises to watch every login, token and API call in one place. What it actually means.

4 min read
A corporate network access point with multi-factor authentication confirmation displayed on screen, showing successful login while simultaneously an attacker ga
Identity & Access

Passing the Login Test Does Not Mean You Let In the Right Person

Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

3 min read
A Windows desktop with Chrome browser window open, and a developer tools panel glowing with active debugging information in the lower portion of the screen
Threat Intelligence

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows

A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

3 min read
A cellular network infrastructure facility with towering antenna arrays against sky, data flow visualizations showing vulnerability points highlighted in the ne
Vulnerabilities

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks

A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

3 min read
Four different authentication bypass scenarios displayed across a split-screen interface, each showing a different vector of attack against multi-factor authent
Identity & Access

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)

Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable routes through it, and most organisations are leaving at least one wide open.

5 min read
A laptop screen showing an attacker's session still active in an email inbox even after a user has reset their password, demonstrating a persistent session toke
Identity & Access

Changing Your Password No Longer Kicks Hackers Out

A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

4 min read
Real-time security monitoring dashboard showing live login activity, with a fake insurance company login page displayed on one screen and rapid cursor movements
Threat Intelligence

Insurance phishing gets faster: attackers now hijack accounts in real time

Researchers say fake insurance login pages are being run live, with criminals stepping in the moment a victim types their password.

4 min read
Full-frame close-up of a laptop screen showing a fake browser error dialog with a copy-paste instruction box, warm desk lamp light, blurred office background, m
Identity & Access

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers

The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

4 min read
Full-frame photoreal editorial shot of a dim server room with rows of blinking network equipment, one rack door slightly ajar, a faint blue glow spilling across
Identity & Access

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks

Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a modern glass office corridor at dusk, with two adjacent identical meeting rooms separated by a cracked gla
AI Security

Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions

A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.

3 min read
© 2026 Threat Vectr