Skip to main content
← All Articles

Tag

#Session Hijacking

18 articles

Advertisement

Zimbra Classic Web Client Stored XSS Leads to Session Hijacking
HIGH
Vulnerabilities

Zimbra Classic Web Client Stored XSS Leads to Session Hijacking

Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.

Runtime Rebel Intel
4 min read · Jul 11, 2026
MongoBleed: Unauthenticated Credential Theft via Server Memory
HIGH
Vulnerabilities

MongoBleed: Unauthenticated Credential Theft via Server Memory

Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…

Runtime Rebel Intel
4 min read · Jun 17, 2026
MEDIUM
Identity & Access

Google Chrome DBSC: Preventing Account Takeover via Cookie Theft

Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.

Runtime Rebel Intel
3 min read · May 29, 2026
HIGH
Vulnerabilities

CVE-2021-22291: ABB EIBPORT V3 <3.9.2 Session Hijacking Vulnerability

ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.

Runtime Rebel Intel
4 min read · May 28, 2026
MEDIUM
Threat Intel

Italy Dismantles CINEMAGOAL App for Streaming Auth Token Theft

Italian authorities dismantled the CINEMAGOAL piracy app, which harvested authentication tokens and session cookies from users to access streaming services.

Runtime Rebel Intel
3 min read · May 23, 2026
INFO
Identity & Access

Zero Trust: Why Device Security is Essential Beyond Identity

Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.

Runtime Rebel Intel
4 min read · May 20, 2026

Advertisement

MEDIUM
Threat Intel

AitM Phishing Attacks Target US Organizations with Conduct Reports

Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.

Runtime Rebel Intel
3 min read · May 5, 2026
HIGH
Threat Intel

Telegram tdata Credential Harvesting: Risks and Mitigation Strategies

Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.

Runtime Rebel Intel
3 min read · Apr 22, 2026
OAuth Token Hijacking in AI Tools: Vercel Breach Analysis
MEDIUM
Identity & Access

OAuth Token Hijacking in AI Tools: Vercel Breach Analysis

An investigation into how stolen OAuth tokens from a Vercel employee's AI tool session led to unauthorized internal access and the risks of AI integration.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Malware

Storm Infostealer: Bypassing Local Decryption for Session Hijacking

Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.

Runtime Rebel Intel
3 min read · Apr 13, 2026
MEDIUM
Identity & Access

Chrome DBSC: Securing Session Cookies with Device Binding — Analysis

Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
INFO
Identity & Access

Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking

Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Identity & Access

Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers

Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.

Runtime Rebel Intel
4 min read · Apr 6, 2026
MEDIUM
Identity & Access

Beyond MFA: Bridging the Zero Trust Gap in Session Security

Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.

Runtime Rebel Intel
4 min read · Mar 24, 2026
HIGH
Vulnerabilities

CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide

Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.

Runtime Rebel Intel
3 min read · Mar 24, 2026
2025 Identity Threat Report: Analyzing the Infostealer Economy
HIGH
Identity & Access

2025 Identity Threat Report: Analyzing the Infostealer Economy

Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.

Runtime Rebel Intel
3 min read · Mar 16, 2026
Google Gemini Side Panel Bug Enables Session Hijacking — Update Now
HIGH
Vulnerabilities

Google Gemini Side Panel Bug Enables Session Hijacking — Update Now

Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.

Runtime Rebel Intel
4 min read · Mar 2, 2026
HIGH
Identity & Access

Token Theft and Session Hijacking: Mitigating Device Trust Failures

An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…

Runtime Rebel Intel
2 min read · Feb 23, 2026