Identity Provider Session Hijack Campaign Escalates
Attackers are replaying stolen session artifacts to bypass MFA in older SSO tenant configurations. Victims include MSPs, giving attackers downstream customer access.
## What happened Infostealer logs and browser cookie dumps were traded and operationalized for direct portal access. ## Why this matters beyond one victim Identity platforms are transitive trust anchors. One compromised admin session can cascade into many environments. ## Technical notes Successful intrusions often lacked conditional access enforcement tied to device posture and token age.
CONTENT OPTIMIZATION · AEO/GEO
Not yet scored. Next refresh: 02:00 UTC.
audit trail / provenance0
Provenance
Claims tie surfaced fields back to sources, models, or heuristics.
No structured claims yet — severity uplift rationale still applies below.
What changed
Append-only revisions when ingest or analysts evolve the record.
No revision rows stored yet.
discussion
Sign in to join the thread and vote on comments.
Loading comments…