The images in this article were generated with artificial intelligence. How we publish
The combination of hybrid work, personal devices at the post and third-party access has made the identities - human and non-human - the main security perimeter of many organizations. The attackers know this: compromising an account is often faster, quieter and more cost-effective than exploiting infrastructure vulnerability and that reality forces us to rethink how we validate trust in each access.
In recent years we have seen a tactical evolution: it is not enough to steal passwords, now the adversaries point to sessions and the authentication process. Techniques such as the so-called "MFA fatigue" (bombing of notifications until the user accepts) or the interception of session tokens by frameworks of adversary-in- the-middle allow you to evade controls that, on paper, were robust. Successful authentication ceased to be a guarantee of trust on its own.

Another critical vector is endpoints. With employees using unmanaged personal and mobile computers, the risk of infostealers and other malware that extract credentials and session cookies grows in parallel. A compromised device turns a legitimate identity into an open door and many organizations still lack the continuous visibility to detect this condition in real time.
The implications are both technical and commercial: data loss, service interruption, regulatory sanctions and reputational damage. In addition, the need to balance safety and productivity introduces operational dilemmas; blocking default access can paralyze equipment, while allowing too much increases the risk. That is why merely reactive strategies are no longer enough.
The good news is that there are practical and complementary measures to reduce the probability and impact of account hijackings. Instead of relying only on the moment of the login, organizations should adopt continuous verification models incorporating the device's position, session context and behavioral signals throughout the connection. For technical guidance, see recommendations for modern authentication such as those collected by NIST: NIST SP 800-63B.
Implement phishing-resistant authentication methods, such as FIDO2 and physical keys, significantly reduces the effectiveness of campaigns that try to capture credentials or deceive with prompts. At the same time, it is critical to disable and block legacy authentication protocols that do not support modern controls; Microsoft documents how these methods remain a frequent entry path and how to mitigate them in cloud environments: legacy authentication management in Azure AD.
The effective defence combines identity controls with endpoint protection and session detection. EDR / EDRms tools combined with conditional access policies that evaluate device hygiene and user location allow access decisions based on risk, not presumptions. Protecting session cookies and tokens, monitoring behavior anomalies and applying access point mediation are practices that reduce the success of session kidnapping techniques.
No less important is governance: full inventory of identities (including service accounts and automation), minimum privilege principles and regular access reviews. The integration of detailed records into a IMS and continuous threat hunting and attack simulation exercises (team network, controlled phishing) make early detection an operational capacity, not a hope.

The formation must evolve: stop focusing only on "not clicking" and show concrete signs of attacks on MFA, how to react to unexpected prompts and how to report incidents without criminalizing those who warn. The human factor remains vital, but it needs to be empowered by processes and solutions that reduce friction and increase security.
For teams that design a defensive strategy, the path requires combining policies, technology and processes: physical-resistant authentication, continuous device verification, inherited authentication blocking, advanced endpoints protection, session visibility and rigid identity governance. No one can guarantee zero risk, but the sum of these measures transforms an easy objective at a much less attractive operational and tactical cost to the attacker.
Finally, and beyond concrete tools, it is essential to measure. Establishing risk indicators, simulating attacks and reviewing policies according to real metrics allows to adapt investments and prioritize controls with proven impact. For those who want to deepen the nature and scale of the problem, quarterly and annual reports such as the Verizon DBIR provide valuable data on gaps trends: Verizon DBIR.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...