<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Session Hijacking</title><description>Cybersecurity articles tagged #Session Hijacking on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Zimbra Classic Web Client Stored XSS Leads to Session Hijacking</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-stored-xss-leads-to-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-stored-xss-leads-to-session-hijacking</guid><description>Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.</description><pubDate>Sat, 11 Jul 2026 09:39:05 GMT</pubDate><category>Zimbra</category><category>Stored Xss</category><category>Webmail Security</category><category>Session Hijacking</category></item><item><title>MongoBleed: Unauthenticated Credential Theft via Server Memory</title><link>https://runtimerebel.com/blog/mongobleed-unauthenticated-credential-theft-via-server-memory</link><guid isPermaLink="true">https://runtimerebel.com/blog/mongobleed-unauthenticated-credential-theft-via-server-memory</guid><description>Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…</description><pubDate>Wed, 17 Jun 2026 13:27:52 GMT</pubDate><category>MongoBleed</category><category>Attack Surface Management</category><category>Credential Theft</category><category>Session Hijacking</category><category>Unauthenticated Access</category><category>Memory Disclosure</category><category>MongoDB</category></item><item><title>Google Chrome DBSC: Preventing Account Takeover via Cookie Theft</title><link>https://runtimerebel.com/blog/google-chrome-dbsc-preventing-account-takeover-via-cookie-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-dbsc-preventing-account-takeover-via-cookie-theft</guid><description>Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.</description><pubDate>Fri, 29 May 2026 13:17:47 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Identity Theft</category><category>TPM</category></item><item><title>CVE-2021-22291: ABB EIBPORT V3 &lt;3.9.2 Session Hijacking Vulnerability</title><link>https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-22291-abb-eibport-v3-3-9-2-session-hijacking-vulnerability</guid><description>ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.</description><pubDate>Thu, 28 May 2026 17:27:09 GMT</pubDate><category>CVE-2021-22291</category><category>ABB EIBPORT</category><category>XSS</category><category>Session Hijacking</category><category>ICS</category><category>Building Automation</category><category>Critical Manufacturing</category></item><item><title>Italy Dismantles CINEMAGOAL App for Streaming Auth Token Theft</title><link>https://runtimerebel.com/blog/italy-dismantles-cinemagoal-app-for-streaming-auth-token-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/italy-dismantles-cinemagoal-app-for-streaming-auth-token-theft</guid><description>Italian authorities dismantled the CINEMAGOAL piracy app, which harvested authentication tokens and session cookies from users to access streaming services.</description><pubDate>Sat, 23 May 2026 16:25:53 GMT</pubDate><category>CINEMAGOAL</category><category>Piracy</category><category>Session Hijacking</category><category>Authentication Theft</category><category>Italy</category></item><item><title>Zero Trust: Why Device Security is Essential Beyond Identity</title><link>https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</guid><description>Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.</description><pubDate>Wed, 20 May 2026 17:12:24 GMT</pubDate><category>Zero Trust</category><category>Device Security</category><category>Identity and Access Management</category><category>Session Hijacking</category><category>Endpoint Security</category></item><item><title>AitM Phishing Attacks Target US Organizations with Conduct Reports</title><link>https://runtimerebel.com/blog/aitm-phishing-attacks-target-us-organizations-with-conduct-reports</link><guid isPermaLink="true">https://runtimerebel.com/blog/aitm-phishing-attacks-target-us-organizations-with-conduct-reports</guid><description>Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.</description><pubDate>Tue, 05 May 2026 16:40:58 GMT</pubDate><category>Phishing</category><category>AitM</category><category>Microsoft 365</category><category>Session Hijacking</category><category>Credential Theft</category></item><item><title>Telegram tdata Credential Harvesting: Risks and Mitigation Strategies</title><link>https://runtimerebel.com/blog/telegram-tdata-credential-harvesting-risks-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/telegram-tdata-credential-harvesting-risks-and-mitigation-strategies</guid><description>Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.</description><pubDate>Wed, 22 Apr 2026 08:47:07 GMT</pubDate><category>Telegram Desktop</category><category>Credential Harvesting</category><category>Tdata Exploitation</category><category>Session Hijacking</category></item><item><title>OAuth Token Hijacking in AI Tools: Vercel Breach Analysis</title><link>https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</guid><description>An investigation into how stolen OAuth tokens from a Vercel employee&apos;s AI tool session led to unauthorized internal access and the risks of AI integration.</description><pubDate>Tue, 21 Apr 2026 05:03:55 GMT</pubDate><category>OAuth</category><category>Vercel</category><category>AI Security</category><category>Session Hijacking</category><category>Token Theft</category></item><item><title>Storm Infostealer: Bypassing Local Decryption for Session Hijacking</title><link>https://runtimerebel.com/blog/storm-infostealer-bypassing-local-decryption-for-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/storm-infostealer-bypassing-local-decryption-for-session-hijacking</guid><description>Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.</description><pubDate>Mon, 13 Apr 2026 16:33:45 GMT</pubDate><category>Storm</category><category>Infostealer</category><category>Session Hijacking</category><category>Credential Theft</category><category>Varonis</category></item><item><title>Chrome DBSC: Securing Session Cookies with Device Binding — Analysis</title><link>https://runtimerebel.com/blog/chrome-dbsc-securing-session-cookies-with-device-binding-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-dbsc-securing-session-cookies-with-device-binding-analysis</guid><description>Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.</description><pubDate>Fri, 10 Apr 2026 08:38:17 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Cookie Theft</category><category>Infostealer</category></item><item><title>Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking</title><link>https://runtimerebel.com/blog/google-chrome-146-dbsc-implementation-hardens-windows-against-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-146-dbsc-implementation-hardens-windows-against-session-hijacking</guid><description>Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.</description><pubDate>Fri, 10 Apr 2026 08:37:21 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Cookie Theft</category><category>TPM</category><category>Windows Security</category></item><item><title>Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers</title><link>https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</guid><description>Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.</description><pubDate>Mon, 06 Apr 2026 16:21:46 GMT</pubDate><category>Infostealers</category><category>Session Hijacking</category><category>Credential Harvesting</category><category>MFA Bypass</category></item><item><title>Beyond MFA: Bridging the Zero Trust Gap in Session Security</title><link>https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</guid><description>Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.</description><pubDate>Tue, 24 Mar 2026 16:29:03 GMT</pubDate><category>Zero Trust</category><category>MFA Bypass</category><category>Session Hijacking</category><category>Identity Security</category><category>Device Trust</category></item><item><title>CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide</title><link>https://runtimerebel.com/blog/cve-2023-4966-critical-citrix-netscaler-memory-leak-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-4966-critical-citrix-netscaler-memory-leak-patching-guide</guid><description>Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.</description><pubDate>Tue, 24 Mar 2026 12:25:18 GMT</pubDate><category>CVE-2023-4966</category><category>Citrix</category><category>NetScaler</category><category>Session Hijacking</category><category>Citrix Bleed</category></item><item><title>2025 Identity Threat Report: Analyzing the Infostealer Economy</title><link>https://runtimerebel.com/blog/2025-identity-threat-report-analyzing-the-infostealer-economy</link><guid isPermaLink="true">https://runtimerebel.com/blog/2025-identity-threat-report-analyzing-the-infostealer-economy</guid><description>Recorded Future&apos;s 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.</description><pubDate>Mon, 16 Mar 2026 16:31:44 GMT</pubDate><category>Infostealer</category><category>Credential Theft</category><category>Session Hijacking</category><category>Recorded Future</category><category>MFA Bypass</category></item><item><title>Google Gemini Side Panel Bug Enables Session Hijacking — Update Now</title><link>https://runtimerebel.com/blog/google-gemini-side-panel-bug-enables-session-hijacking-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-side-panel-bug-enables-session-hijacking-update-now</guid><description>Researchers discovered a security flaw in the Google Gemini side panel that allows for unauthorized session hijacking and cross-origin data exfiltration.</description><pubDate>Mon, 02 Mar 2026 16:20:11 GMT</pubDate><category>Google Gemini</category><category>Chrome Security</category><category>Session Hijacking</category><category>Hiddenlayer</category><category>Ai Vulnerability</category></item><item><title>Token Theft and Session Hijacking: Mitigating Device Trust Failures</title><link>https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</guid><description>An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…</description><pubDate>Mon, 23 Feb 2026 16:23:45 GMT</pubDate><category>Token Theft</category><category>Session Hijacking</category><category>Zero Trust</category><category>Endpoint Security</category></item></channel></rss>