Tag

#session-hijacking

21 stories taggedsession-hijacking.

Photoreal editorial 16:9 image of a dimly lit server rack with a single monitor showing abstract Python notebook cells, faint blue glow, shallow depth of field,
Threat Intelligence

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows

A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

4 min read
A dimly lit server room with rows of dark racks, one panel glowing red with warning indicator lights, thin blue fibre-optic cables running along the ceiling, sh
Vulnerabilities

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks

A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

3 min read
Close-up top-down view of a smartphone lying on a wooden table, its screen displaying a generic colourful digital invitation card with balloons and confetti gra
Identity & Access

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)

Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable ways through it, and most organisations are leaving at least one door wide open.

4 min read
Extreme close-up of a server rack's blinking status lights in a darkened data centre, rows of ethernet cables in cool blue and amber tones, shallow depth of fie
Identity & Access

Changing Your Password No Longer Kicks Hackers Out

A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

4 min read
Photoreal news-editorial image of an empty modern football stadium at dusk, floodlights on, viewed from an upper tier, with a faint blue data-grid overlay sugge
Threat Intelligence

Insurance phishing gets faster: attackers now hijack accounts in real time

Researchers say fake insurance login pages are being run live, with criminals stepping in the moment a victim types their password.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a dim government-style operations desk, dark wood surface with a glowing blue network topology map projected
Threat Intelligence

German Police Shut Down Kratos Phishing Network, But Experts Say the Pause Will Be Brief

Authorities seized more than 200 servers and arrested a developer in Indonesia. Security researchers say the 1,800 customers who used the service are already shopping for a replacement.

3 min read
Full-frame close-up of a laptop screen showing a fake browser error dialog with a copy-paste instruction box, warm desk lamp light, blurred office background, m
Identity & Access

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers

The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek dark workstation with several glowing monitors showing abstract code and login prompts, a fain
Identity & Access

Forg365 Sells Ready-Made Microsoft 365 Hijacking Kits on Telegram for $400 a Month

A new phishing service hands criminals automated tools to break into Microsoft 365 accounts and stay there, even after a victim changes their password.

3 min read
Full-frame photoreal editorial shot of a dim server room with rows of blinking network equipment, one rack door slightly ajar, a faint blue glow spilling across
Identity & Access

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks

Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a modern office desk at night, a laptop screen showing a blurred generic corporate login form and a ph
Identity & Access

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins

A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a modern glass office corridor at dusk, with two adjacent identical meeting rooms separated by a cracked gla
AI Security

Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions

A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.

3 min read
Photoreal editorial close-up of a laptop screen showing a generic blurred cloud sign-in prompt, a translucent glowing link being dragged across the screen by a
Identity & Access

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds

A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine — and a step-by-step guide is now circulating on a Russian crime forum.

4 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data center with a single amber warning LED glowing on a network appliance, co
Ransomware

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks

Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

3 min read
Threat Intelligence

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft

The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

3 min read
Threat Intelligence

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC

Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

2 min read
© 2026 Threat Vectr