logo

Why Tokens Are Like Gold for Opportunistic Threat Actors

ID: b530fd25-d25b-521d-ad27-8de6d0c75f78

STIX ID: report--b530fd25-d25b-521d-ad27-8de6d0c75f78

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-13

Date Updated: 2026-04-21

Author: John A. Smith

...
...

Authentication/session tokens are being actively targeted by threat actors — stolen via AitM, pass-the-cookie, and synced browser credentials — enabling broad access to corporate SaaS and IdP-integrated systems without MFA. The report cites Okta and Cloudflare incidents and a Microsoft token-signing misuse that exposed large volumes of data, warns that long-lived tokens extend attacker dwell time, and recommends aggressive token expiry and blocking personal-device or synced-credential access to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.