Why Tokens Are Like Gold for Opportunistic Threat Actors
ID: b530fd25-d25b-521d-ad27-8de6d0c75f78
STIX ID: report--b530fd25-d25b-521d-ad27-8de6d0c75f78
Feed Name: Dark Reading
Authentication/session tokens are being actively targeted by threat actors — stolen via AitM, pass-the-cookie, and synced browser credentials — enabling broad access to corporate SaaS and IdP-integrated systems without MFA. The report cites Okta and Cloudflare incidents and a Microsoft token-signing misuse that exposed large volumes of data, warns that long-lived tokens extend attacker dwell time, and recommends aggressive token expiry and blocking personal-device or synced-credential access to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
