Session Hijacking
The latest Session Hijacking coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Session Hijacking Flaw in Siemens SIPROTEC 5 Relays Demands Immediate OT Action, CISA Warns
Operators of Siemens SIPROTEC 5 protection relays must urgently assess and patch their devices after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) amplified a alert about a serious...
Storm-2755 AiTM hijacks Canadian payroll with fake job ads, bypassing MFA.
Microsoft's Digital Crimes Unit has uncovered a sophisticated payroll fraud campaign targeting Canadian organizations through advanced adversary-in-the-middle (AiTM) attacks. The Storm-2755 operation...
Libsoup cookie leak in CONNECT requests lets proxy attackers hijack sessions
A critical vulnerability in the libsoup network library exposes HTTP cookies during proxy CONNECT requests, enabling attackers to hijack user sessions across multiple applications. CVE-2026-5119,...
CISA Warns: Rockwell ArmorBlock 5000 Flaws Allow Remote Session Hijack, Score Hits 8.8
Two high-severity vulnerabilities in Rockwell Automation’s ArmorBlock 5000 I/O modules allow attackers to hijack web management sessions without credentials, CISA warned on August 14, 2025. The...
The 2025 Surge in Sophisticated Phishing Attacks Targeting Microsoft Accounts: Strategies and Defenses
In 2025, the battleground for digital security has shifted dramatically, with Microsoft account holders standing on the front lines of an escalating war against increasingly sophisticated phishing...
2025 Microsoft 365 OAuth Phishing Attacks: Anatomy, Impact, and Defense Strategies
A rapidly escalating threat is reshaping the cybersecurity landscape for organizations dependent on Microsoft 365. In 2025, hackers unleashed a new wave of phishing attacks that leverage OAuth abuse...
2025 Cloud Security Crisis: Microsoft OAuth Phishing Bypasses MFA in Industrialized Cyberattacks
Cloud security defenders in 2025 face their most formidable challenge yet: a global surge of cyberattacks weaponizing Microsoft OAuth to reliably bypass multi-factor authentication (MFA). While...
2025 Microsoft OAuth Phishing Attacks: Evolving Threats Beyond MFA
Phishing campaigns continue to evolve at a staggering pace, keeping security professionals on perpetual alert. In 2025, the latest surge in Microsoft OAuth-centric phishing attacks illustrates just...
Securing Microsoft 365 Identities: Strategies to Combat Advanced Cyber Threats
The battle for securing organizational identities has never been fiercer. As Microsoft 365 cements itself as the backbone of modern enterprise productivity, cybercriminals are shifting their focus...
Mastering Microsoft 365 Identity Security in 2025: Threats, Best Practices, and Future Directions
In today’s hyper-connected era, Microsoft 365 serves as the digital backbone for organizations spanning the globe, empowering real-time collaboration, seamless communication, and centralized data...
PoisonSeed: The Next-Generation Phishing Toolkit Threatening FIDO2 Passwordless Authentication
A new chapter in enterprise cybersecurity has begun with the recent discovery of the PoisonSeed phishing toolkit—a weaponized kit aimed directly at undermining the foundations of FIDO2, the widely...
AI-Driven Phishing Attacks: How to Secure Microsoft 365 & Cloud Services
The cybersecurity landscape is undergoing a seismic shift as AI-powered phishing attacks target cloud services like Microsoft 365 and Okta with unprecedented sophistication. These next-generation...