logo

Stealing cookies: Researchers describe how to bypass modern authentication

ID: ced81f8f-e4a3-5742-bfc3-28c73f11696a

STIX ID: report--ced81f8f-e4a3-5742-bfc3-28c73f11696a

Feed Name: CyberScoop

Date Published: 2024-05-06

Date Updated: 2026-04-21

Author: djohnson

...
...

Research highlighted by Silverfort shows that attackers can bypass passwordless FIDO2-protected logins by intercepting and reusing SSO session tokens via man-in-the-middle techniques, enabling session hijacking despite strong initial authentication. While not a flaw in FIDO2 itself, the weakness lies in post-authentication session management; mitigations like token binding or Google’s Device Bound Session Credentials can bind tokens to specific TLS sessions or devices, but adoption remains limited and attacks require conditions such as malicious browser extensions or compromised public Wi‑Fi.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.