#session-hijacking

[ follow ]
Information security
fromComputerWeekly.com
1 week ago

Tycoon2FA phishing platform dismantled in major operation | Computer Weekly

Europol-led operation dismantled Tycoon2FA, a phishing service with 2,000 subscribers that bypassed multifactor authentication by intercepting credentials and session cookies across 24,000 domains.
Information security
fromThe Hacker News
1 month ago

Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

Five malicious Chrome extensions posing as HR/ERP tools steal cookies and authentication tokens, block security responses, and enable full account takeover via session hijacking.
Information security
fromTheregister
4 months ago

MCP attack uses predictable session IDs to hijack AI agents

A flaw in oatpp-mcp's SSE session ID generation allows attackers with network access to predict or capture session IDs and hijack MCP sessions.
fromSecuritymagazine
6 months ago

Cybercriminals Attack VPS to Access Business Email Systems

Attackers now rent trust. Five dollar VPS nodes buy entry to your allow list and they accomplish this by getting a clean ASN and fresh IP making traffic feel like a trusted source, not a criminal. In this case, the adversary is riding live sessions and no longer just harvesting passwords. The mailbox becomes the control plane. Vague rules act like a kind of stealth policy.
Information security
#cybersecurity
fromHackernoon
10 months ago
Privacy technologies

Session Hijacking Is Maturing. What Proactive Measures Can Secure Active Sessions? | HackerNoon

fromHackernoon
10 months ago
Privacy technologies

Session Hijacking Is Maturing. What Proactive Measures Can Secure Active Sessions? | HackerNoon

#citrix
Information security
fromTheregister
9 months ago

Salesforce fixes 5 bugs following spate of reported issues

Salesforce identified five significant vulnerabilities related to configuration weaknesses, urging customers to secure their setups.
[ Load more ]