Advertisement
Zimbra Classic Web Client Stored XSS Leads to Session Hijacking
Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.
MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…
Google Chrome DBSC: Preventing Account Takeover via Cookie Theft
Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.
CVE-2021-22291: ABB EIBPORT V3 <3.9.2 Session Hijacking Vulnerability
ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.
Italy Dismantles CINEMAGOAL App for Streaming Auth Token Theft
Italian authorities dismantled the CINEMAGOAL piracy app, which harvested authentication tokens and session cookies from users to access streaming services.
Zero Trust: Why Device Security is Essential Beyond Identity
Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.
Advertisement
AitM Phishing Attacks Target US Organizations with Conduct Reports
Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.
Telegram tdata Credential Harvesting: Risks and Mitigation Strategies
Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.
OAuth Token Hijacking in AI Tools: Vercel Breach Analysis
An investigation into how stolen OAuth tokens from a Vercel employee's AI tool session led to unauthorized internal access and the risks of AI integration.
Storm Infostealer: Bypassing Local Decryption for Session Hijacking
Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.
Chrome DBSC: Securing Session Cookies with Device Binding — Analysis
Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.
Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers
Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.
Beyond MFA: Bridging the Zero Trust Gap in Session Security
Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.
CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide
Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.
2025 Identity Threat Report: Analyzing the Infostealer Economy
Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.
Google Gemini Side Panel Bug Enables Session Hijacking — Update Now
Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.
Token Theft and Session Hijacking: Mitigating Device Trust Failures
An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…