Martedi 28 Luglio 2026 20:29:07 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#session replay


When the Login Box Becomes the Breach: Device-Code Phishing and MFA Persistence

Published: 09 July 2026 08:05Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

Identity abuse is replacing noisy malware in some intrusions, and the sharp edge now sits in legitimate sign-in flows, token replay, and methods added to keep access alive.

When Phishing Starts Reusing Trust: The Microsoft 365 Session Trap

Published: 23 June 2026 10:46Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported multi-organization campaign shows how adversary-in-the-middle kits are moving past password theft and toward session replay, where a stolen sign-in can outlive the click that triggered it.

One Plaintext File, One Session, One Very Bad Day for Endpoint Trust

Published: 02 June 2026 10:30Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A Windows client-side state file in StrongDM may let a copied token be replayed under the right conditions, turning local file access into an authentication risk.

Chrome’s Device Bound Session Credentials Reach Windows in a Push Against Session Theft

Published: 30 May 2026 19:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Google has made DBSC generally available for Chrome on Windows, a move that tries to make stolen session data harder to replay on another device.

Il login non era il traguardo: perché la fiducia nel dispositivo decide oggi la sicurezza cloud

Pubblicato: 21 Maggio 2026 07:07Categoria: Sicurezza cloud, SaaS e identitàArea: Nord America / USAAutore: SHADOWFIREWALL

I controlli sull'identità possono aprire la porta, ma token di sessione rubati e endpoint compromessi possono comunque tenere un attaccante dentro, a meno che le decisioni di accesso non continuino a ricontrollare lo stato del dispositivo.