Martedi 28 Luglio 2026 21:39:18 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#session tokens


La falsa pagina Microsoft che insegue la sessione, non solo la password

Pubblicato: 22 Luglio 2026 12:06Categoria: Consapevolezza della sicurezza e ingegneria socialeArea: Nord America / USAAutore: NEURALSHIELD

Il phishing AiTM trasforma una schermata di accesso fidata in un punto di inoltro per credenziali, output MFA e token di sessione attivi, rendendo il furto dell'account simile a un normale accesso.

ACR Stealer and the Browser Vault Problem That Keeps Defeating Passwords

Published: 18 July 2026 18:03Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Microsoft’s warning about a surge in ACR Stealer activity is a reminder that modern intrusions often begin with stolen browser state, not a dramatic breach of the network perimeter.

When a Paste Becomes a Breach: The Stealer Playbook Behind ClickFix

Published: 17 July 2026 14:44Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A user-driven lure can turn a single Windows command into credential theft, session replay, and local document harvesting from synced cloud workspaces.

The New Stealer Trap: How Attackers Turned Windows Convenience Into Credential Theft

Published: 17 July 2026 08:09Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A recent ACR Stealer campaign shows how social engineering, remote file delivery, and hidden scripting can work together to steal browser credentials and session tokens without a classic exploit chain.

Session Theft at the Gateway: Why CitrixBleed 2 Turns MFA Into a False Sense of Safety

Published: 10 July 2026 12:04Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A cluster of incidents tied to Citrix NetScaler gateways shows how a stolen session can matter more than a stolen password, especially when the edge appliance itself is the weak point.

Verified, Sponsored, and Still Dangerous: The Trust Signals Cybercriminals Are Learning to Hijack

Published: 04 July 2026 08:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Two separate techniques show how attackers are leaning on user trust - one through a promoted macOS lure, the other through browser-based Microsoft 365 token abuse.

Claude on the Move: Why a Phone-Based AI Workspace Changes the Security Equation

Published: 26 June 2026 02:09Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

Anthropic is testing mobile support for Claude Cowork, and even a modest interface change can reshape how identities, sessions, and task context need to be protected.

The Login Problem: Why Identity Has Become the New Perimeter

Published: 20 June 2026 08:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

ITDR is emerging as a response to attackers who do not smash endpoints first, but abuse valid logins, stolen tokens, and identity paths that ordinary tools may not fully watch.

The Real Breach Start: Exposed Panels, Reused Passwords, and a New Memory Leak

Published: 17 June 2026 17:47Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

When admin panels and reused credentials remain exposed, a single new vulnerability like MongoBleed can increase risk quickly.

OnyxC2 Turns Windows Tricks Into a Low-Cost Stealer Economy

Published: 11 June 2026 19:14Category: Malware & BotnetsAuthor: IRONQUERY

Researchers describe a $250-a-month malware package built around broad application targeting and familiar Windows evasion tactics, a reminder that commodity theft is becoming more technically disciplined.

A Ransom Note Meets Precision Farming: Why a Tiny Alleged Leak Can Matter More Than Its Size

Published: 02 June 2026 08:18Category: Ransomware & ExtortionGeo: Europe / SwitzerlandAuthor: NEBULASCOUT

An indexed extortion claim aimed at Cropwise shows how agritech platforms can concentrate identities, geospatial records, and machine telemetry into one high-value target.

Il nuovo trucco di Gremlin Stealer: nascondere il suo sistema nervoso all’interno delle risorse .NET

Pubblicato: 21 Maggio 2026 08:04Categoria: Malware e BotnetAutore: SIGNALMONK

Una variante di Gremlin Stealer recentemente identificata sta օգտագործando sezioni di risorse .NET crittografate per occultare l’infrastruttura di comando e la logica di sottrazione dei dati, una mossa che spinge l’analisi del malware lontano dalla semplice ricerca di stringhe e verso l’ispezione runtime.

Il login non era il traguardo: perché la fiducia nel dispositivo decide oggi la sicurezza cloud

Pubblicato: 21 Maggio 2026 07:07Categoria: Sicurezza cloud, SaaS e identitàArea: Nord America / USAAutore: SHADOWFIREWALL

I controlli sull'identità possono aprire la porta, ma token di sessione rubati e endpoint compromessi possono comunque tenere un attaccante dentro, a meno che le decisioni di accesso non continuino a ricontrollare lo stato del dispositivo.

La questione dell’iPhone dietro una lista da 20 milioni di nomi

Pubblicato: 16 Maggio 2026 12:12Categoria: Cloud, SaaS e sicurezza dell'identitàArea: Nord America / USAAutore: AUDITWOLF

Un dataset segnalato e collegato a ICE e Palantir, descritto come accessibile da iPhone, pone una domanda di sicurezza più difficile: quale tipo di percorso di accesso mobile era effettivamente in uso?

Quando un download fidato diventa la botola

Pubblicato: 11 Maggio 2026 22:21Categoria: Consapevolezza della sicurezza e ingegneria socialeArea: Nord America / USAAutore: PATCHKNIGHT

Una campagna guidata dal phishing sta abusando di GitHub Releases come superficie di distribuzione dall’aspetto affidabile per un infostealer in Python, trasformando la normale distribuzione di software in un canale furtivo per il furto di account.

Inside the Zero Trust Revolution: Why Your MFA Isn’t Enough

Published: 24 March 2026 15:39Category: Cloud, SaaS & Identity SecurityAuthor: SECPULSE

As cybercriminals sidestep old defenses, the real battle is making sure authentication and device trust work hand-in-hand.

Dentro la rivoluzione Zero Trust: perché la tua MFA non basta

Pubblicato: 24 Marzo 2026 15:39Categoria: Cloud, SaaS & Identity SecurityAutore: SECPULSE

Mentre i cybercriminali aggirano le vecchie difese, la vera battaglia è far sì che autenticazione e fiducia nel dispositivo lavorino mano nella mano.