Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.
A reported multi-organization campaign shows how adversary-in-the-middle kits are moving past password theft and toward session replay, where a stolen sign-in can outlive the click that triggered it.
A Windows client-side state file in StrongDM may let a copied token be replayed under the right conditions, turning local file access into an authentication risk.
Google has made DBSC generally available for Chrome on Windows, a move that tries to make stolen session data harder to replay on another device.
I controlli sull'identità possono aprire la porta, ma token di sessione rubati e endpoint compromessi possono comunque tenere un attaccante dentro, a meno che le decisioni di accesso non continuino a ricontrollare lo stato del dispositivo.