الأحد 26 يوليو 2026 09:52:13 GMT+02:00

Netcrook

الرئيسيةالبيان
الأخبار
Techcrook
Geocrook
WikicrookالفريقAppاتصالتسجيل الدخول
EnglishItaliano

#session replay


When the Login Box Becomes the Breach: Device-Code Phishing and MFA Persistence

Published: 09 July 2026 08:05Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.

When Phishing Starts Reusing Trust: The Microsoft 365 Session Trap

Published: 23 June 2026 10:46Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported multi-organization campaign shows how adversary-in-the-middle kits are moving past password theft and toward session replay, where a stolen sign-in can outlive the click that triggered it.

One Plaintext File, One Session, One Very Bad Day for Endpoint Trust

Published: 02 June 2026 10:30Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A Windows client-side state file in StrongDM may let a copied token be replayed under the right conditions, turning local file access into an authentication risk.

Chrome’s Device Bound Session Credentials Reach Windows in a Push Against Session Theft

Published: 30 May 2026 19:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Google has made DBSC generally available for Chrome on Windows, a move that tries to make stolen session data harder to replay on another device.

لم تكن عملية تسجيل الدخول هي خط النهاية: لماذا أصبح موثوقية الجهاز هي التي تحسم أمن السحابة الآن

يمكن لفحوصات الهوية أن تفتح الباب، لكن رموز الجلسات المسروقة ونقاط النهاية غير السليمة قد تبقي المهاجم داخلها ما لم تستمر قرارات الوصول في إعادة التحقق من حالة الجهاز.