LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

zeroday.news ·

The proliferation of infostealer logs has become a significant operational security challenge for organizations, moving beyond a niche underground commodity to a mainstream threat. Security teams are increasingly confronted with alerts indicating that employee corporate credentials, including email addresses and passwords for SaaS applications, have appeared in these logs. These logs often contain not only static credentials but also active browser cookies, which can enable attackers to bypass multi-factor authentication (MFA) and access live sessions.

A key challenge stems from the origin of these exposures. Approximately 46% of infostealer logs containing corporate credentials are believed to originate from unmanaged or personal devices, often hundreds of miles from corporate offices. Malware families like RedLine, Lumma, and Vidar are designed to harvest a wide array of information from infected systems, including saved browser passwords, cookies, autofill data, cryptocurrency wallets, system information, and VPN configurations. A single infection can yield hundreds or thousands of individual records, creating a massive scale problem for defenders.

The volume and nature of the data in these logs make prioritization difficult. Security analysts must distinguish between an old, potentially meaningless password for a consumer website and a fresh log containing corporate identity credentials and an authenticated browser session for an enterprise identity provider. The latter scenario, especially when combined with session cookies, presents a critical risk, as it can lead to immediate account takeover without requiring a password or MFA prompt.

Session cookies are particularly dangerous because they represent an already authenticated state. If an infostealer captures such a cookie, an attacker can replay it to gain access to an application, effectively bypassing traditional authentication steps and MFA. This means that even if a password is reset, an attacker might still maintain access through a stolen session. The exposure of credentials and sessions for major productivity SaaS and cloud services is estimated to be growing by about 29% annually.

Most infostealer logs, roughly 90%, are now found on Telegram channels, both public and private, rather than traditional underground forums. This shift makes the data more accessible to initial access brokers, ransomware affiliates, and opportunistic attackers.

Upon discovering potentially relevant infostealer data, an immediate assessment is crucial to determine the necessary reaction speed. This initial phase involves identifying what was stolen, when the infection occurred, the system involved, the number of corporate credentials present, and whether authenticated sessions were captured. Business context is also vital; a credential for a test server should not receive the same priority as one for a finance system, nor should an intern's exposed identity be treated identically to an administrator's with access to critical infrastructure.

Enterprise identity credentials combined with session cookies are considered a critical severity exposure, warranting a response target of under one hour. VPN/RDP access paired with multiple corporate credentials is classified as high severity due to its potential for lateral movement within a network.

Following the initial assessment, the next step is to determine if the stolen information has already been used. This involves correlating the exposed identity with authentication telemetry, looking for successful or failed logins from unexpected geographies, unusual devices, unfamiliar IP addresses, or access to resources outside the employee's normal behavior. Defenders must also verify if the stolen information is still usable, checking if passwords have changed, sessions have expired, or accounts are still active.

A comprehensive investigation workflow expands to include browser fingerprint information, the complete inventory of saved credentials, details about the infected system, and other artifacts like VPN configurations or SSH keys. It's important to ascertain the employee's role, their access privileges, whether the infected machine was corporate or personal, and if the incident is an isolated infection or part of a broader campaign. Authentication logs across all systems accessible to the exposed identity should be examined, prioritizing the most sensitive resources, to identify any behaviors indicative of account takeover.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

phishing

Outsider Phishing Kit Survives Takedown With 700 New Pages

Outsider phishing kit generated 700 new pages after a Google-led disruption

breach

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United Sta

breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University