Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.
A reported multi-organization campaign shows how adversary-in-the-middle kits are moving past password theft and toward session replay, where a stolen sign-in can outlive the click that triggered it.
A Windows client-side state file in StrongDM may let a copied token be replayed under the right conditions, turning local file access into an authentication risk.
Google has made DBSC generally available for Chrome on Windows, a move that tries to make stolen session data harder to replay on another device.
Identity checks can open the door, but stolen session tokens and unhealthy endpoints can still keep an attacker inside unless access decisions keep re-checking device state.