#tokentheft — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tokentheft, aggregated by home.social.
-
Strong passwords and MFA protect the login process.
But what protects the session after login?
Stolen session cookies or authentication tokens can sometimes be replayed by attackers, allowing account access without repeating the original authentication.
Token theft explained:
https://thenewsink.com/token-theft-explained/ -
The Chrome and Firefox extension Twitch Enhanced Viewer JeetBot exfiltrated Twitch OAuth tokens for nearly 31,000 users to JeetBot proxy infrastructure. Stolen session tokens enable account takeover without passwords and bypass MFA, requiring immediate removal and revocation. #TwitchSecurity #TokenTheft #BrowserSecurity
https://cyberworldops.eu/en/malicious-twitch-extension-exposed-oauth-tokens-from-nearly-31000
-
The Chrome and Firefox extension Twitch Enhanced Viewer JeetBot exfiltrated Twitch OAuth tokens for nearly 31,000 users to JeetBot proxy infrastructure. Stolen session tokens enable account takeover without passwords and bypass MFA, requiring immediate removal and revocation. #TwitchSecurity #TokenTheft #BrowserSecurity
https://cyberworldops.eu/en/malicious-twitch-extension-exposed-oauth-tokens-from-nearly-31000
-
----------------
🎯 Threat Intelligence
===================ERNW published the first of a four-part series on token theft in Microsoft Entra ID, accompanying White Paper 80. The post maps the shift from on-premises Active Directory to cloud identity and explains why token theft has become a primary attack vector.
🔹 Landscape Shift
On-premises AD relied on Kerberos and NTLM. Entra ID runs on OAuth 2.0 and OpenID Connect, using JWT-based access, refresh, and ID tokens. New protocols create new attack surface. Microsoft prioritizes usability and backward compatibility over security-by-default, and the strongest protections (Conditional Access, Token Protection, risk-based Identity Protection) are not enabled by default. They require premium P1/P2 licenses plus separate products like Intune or Defender for Endpoint.
Proprietary SSO concepts like PRT, FOCI, and BroCI add further complexity beyond standard OAuth 2.0.
🔹 Concrete Threats
Microsoft's Digital Defense Report 2024 counts over 600 million daily identity attacks against Entra ID. Two notable CVEs:
• CVE-2025-55241: Actor Tokens flaw allowing Global Admin access to any Entra ID tenant worldwide, disclosed by researcher Dirk-jan Mollema
• CVE-2026-69836: CVSS 10.0 unauthenticated RCE in Entra ID itself, caused by unsafe deserialization of untrusted data🔹 Active Campaigns
• Storm-2372: device code phishing campaign targeting governments and critical industries since August 2024
• Storm-2945: hijacked hotel captive portals worldwide to harvest SSO tokens
• AiTM "code of conduct" phishing: intercepts tokens the moment MFA succeeds rather than trying to defeat MFA directly🔹 Commodity Tooling
Open-source reverse-proxy frameworks Evilginx and Modlishka, along with PhaaS platforms like EvilProxy, Tycoon2FA, and Kali365, have lowered the barrier to running token theft attacks at scale. Infostealers add further reach by harvesting tokens from compromised endpoints.
🔹 Cloud Security Alliance Ranking
CSA's Top Threats to Cloud Computing 2026 ranks IAM-related threats as the #1 risk to cloud environments, ahead of AI-enhanced attacks in second place despite the current AI security hype cycle.
🔹 What's Next
The series will empirically test Continuous Access Evaluation and Token Protection, and examine where Entra ID deviates from OAuth 2.0 best practices.
🔹 EntraID #TokenTheft #ThreatIntelligence #OAuth2 #Cybersecurity
-
🚨 Salesloft breach fallout worsens.
✔️ Tokens for Salesforce, Slack, Google Workspace, AWS & Azure stolen
✔️ Google GTIG: orgs should assume compromise
✔️ Exfiltration ongoing since Aug 8
✔️ Salesforce now blocks Salesloft Drift
💬 Is “authorization sprawl” the Achilles heel of SSO/cloud identity?
🔔 Follow @technadu for threat intel breakdowns.#SalesloftBreach #OAuthCompromise #AIChatbotSecurity #Drift #EnterpriseSecurity #TokenTheft #SaaSRisk
-
🚨 Salesloft breach fallout worsens.
✔️ Tokens for Salesforce, Slack, Google Workspace, AWS & Azure stolen
✔️ Google GTIG: orgs should assume compromise
✔️ Exfiltration ongoing since Aug 8
✔️ Salesforce now blocks Salesloft Drift
💬 Is “authorization sprawl” the Achilles heel of SSO/cloud identity?
🔔 Follow @technadu for threat intel breakdowns.#SalesloftBreach #OAuthCompromise #AIChatbotSecurity #Drift #EnterpriseSecurity #TokenTheft #SaaSRisk
-
Key Points:
➡️ Malicious PyPi package 'pycord-self' targets Discord developers, stealing authentication tokens and creating a backdoor for remote control.
➡️ Introduced in June 2024, downloaded 885 times.
➡️ Token theft and backdoor installation are the primary malicious functions.
➡️ Developers should verify package sources, review code, and use scanning tools to enhance security.https://news.lavx.hu/article/malicious-pypi-package-poses-threat-to-discord-developers-a-deep-dive
#PyPI #DiscordAPI #CyberSecurity #TokenTheft #Backdoor #Malware #DevOps #Python
-
Key Points:
➡️ Malicious PyPi package 'pycord-self' targets Discord developers, stealing authentication tokens and creating a backdoor for remote control.
➡️ Introduced in June 2024, downloaded 885 times.
➡️ Token theft and backdoor installation are the primary malicious functions.
➡️ Developers should verify package sources, review code, and use scanning tools to enhance security.https://news.lavx.hu/article/malicious-pypi-package-poses-threat-to-discord-developers-a-deep-dive
#PyPI #DiscordAPI #CyberSecurity #TokenTheft #Backdoor #Malware #DevOps #Python
-
Key Points:
➡️ Malicious PyPi package 'pycord-self' targets Discord developers, stealing authentication tokens and creating a backdoor for remote control.
➡️ Introduced in June 2024, downloaded 885 times.
➡️ Token theft and backdoor installation are the primary malicious functions.
➡️ Developers should verify package sources, review code, and use scanning tools to enhance security.https://news.lavx.hu/article/malicious-pypi-package-poses-threat-to-discord-developers-a-deep-dive
#PyPI #DiscordAPI #CyberSecurity #TokenTheft #Backdoor #Malware #DevOps #Python
-
Key Points:
➡️ Malicious PyPi package 'pycord-self' targets Discord developers, stealing authentication tokens and creating a backdoor for remote control.
➡️ Introduced in June 2024, downloaded 885 times.
➡️ Token theft and backdoor installation are the primary malicious functions.
➡️ Developers should verify package sources, review code, and use scanning tools to enhance security.https://news.lavx.hu/article/malicious-pypi-package-poses-threat-to-discord-developers-a-deep-dive
#PyPI #DiscordAPI #CyberSecurity #TokenTheft #Backdoor #Malware #DevOps #Python
-
Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.
If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.
This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.
Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! 👇👇
https://www.cswrld.com/2024/04/microsoft-entra-id-token-protection-explained/
#entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips
-
Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.
If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.
This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.
Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! 👇👇
https://www.cswrld.com/2024/04/microsoft-entra-id-token-protection-explained/
#entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips
-
Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.
If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.
This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.
Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! 👇👇
https://www.cswrld.com/2024/04/microsoft-entra-id-token-protection-explained/
#entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips
-
Microsoft Entra ID Token Protection is a security feature within Microsoft Entra's Conditional Access that aims to mitigate token theft by ensuring that a token can only be used from the device it was issued to. This is achieved through a process called token binding, which creates a cryptographically secure link between the token and the device.
If a threat actor were to steal a token, without the corresponding client secret from the device, the token would be rendered useless.
This protection is particularly important because token theft, while relatively rare, can lead to significant security breaches if the threat actor impersonates the victim until the token expires or is revoked.
Do you want to learn more about token protection and how to enforce it in Microsoft Entra ID? Read my latest blog post! 👇👇
https://www.cswrld.com/2024/04/microsoft-entra-id-token-protection-explained/
#entraid #authentication #tokenprotection #tokentheft #conditionalaccess #cybersecurity #tips
-
Behind the Breach: Pass-The-Cookie Beyond IdPs – Source: securityboulevard.com https://ciso2ciso.com/behind-the-breach-pass-the-cookie-beyond-idps-source-securityboulevard-com-2/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #SecurityGuidance #Sessionhijacking #passthecookie #SaaSSecurity #Tokentheft #PTCattack #FEATURED
-
Behind the Breach: Pass-The-Cookie Beyond IdPs – Source: securityboulevard.com https://ciso2ciso.com/behind-the-breach-pass-the-cookie-beyond-idps-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #SecurityGuidance #Sessionhijacking #passthecookie #SaaSSecurity #Tokentheft #PTCattack #FEATURED
-
I'd like to point out this really interesting article on the topic: 𝐓𝐨𝐤𝐞𝐧 𝐓𝐡𝐞𝐟𝐭 𝐓𝐚𝐥𝐤.
Key points and topics covered:
- Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.
- First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware
You can reduce token theft by carefully orchestrating Entra ID security products:
▶Addressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.
▶Addressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.
▶Detecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.
#microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token
-
I'd like to point out this really interesting article on the topic: 𝐓𝐨𝐤𝐞𝐧 𝐓𝐡𝐞𝐟𝐭 𝐓𝐚𝐥𝐤.
Key points and topics covered:
- Primary Refresh Tokens (PRT) on all operating system platforms have been hardened against theft from day one. The level of protection depends on operated system capabilities, with Windows offering the strongest protection.
- First line of defense against token theft is protecting your devices by deploying endpoint protections, device management, MFA (and moving towards phishing-resistant credentials), and antimalware
You can reduce token theft by carefully orchestrating Entra ID security products:
▶Addressing token theft of sign-in session artifacts: Conditional Access: Token protection policy offers cryptographic protection against replay of stolen tokens.
▶Addressing token theft of app session artifacts: block usage of stolen access tokens and workload cookies outside of your corporate network by using Conditional Access.
▶Detecting token theft: enable risk detections with Microsoft Entra ID Protection to elevate user risk when token theft is suspected.
#microsoft #microsoftsecurity #entraid #azuread #azure #idp #token #tokentheft #cloudsecurity #identity #prt #cookies #identityprotection #mfa #cae #conditionalaccess #refreshtoken #token
-
Microsoft has been published a very good summary about #AzureAD security trends in 2023 which considered post authentication attacks, such as #TokenTheft: https://microsoft.com/en-us/security/blog/2023/01/26/2023-identity-security-trends-and-solutions-from-microsoft/
If you are interested to learn more about Token replay attacks, check the following blogs:
🔗 Token tactics: How to prevent, detect, and respond to cloud token theft by Microsoft DART team: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/
This article describes Adversary-in-the-middle (AitM) phishing/Pass-the-cookie attack scenarios and recommendations.
🔗 Abuse and replay of Azure AD refresh token from Microsoft Edge in macOS Keychain:
https://www.cloud-architekt.net/abuse-and-replay-azuread-token-macos/I've written this blog post about token replay on #macOS devices last year. It covers an attack scenario to exfiltrate tokens from Keychain which is used to store cached Azure AD tokens for “logged in” Edge profiles on macOS devices.
🔗 Azure AD Attack & Defense: Replay of Primary Refresh (PRT) and other issued tokens from an Azure AD joined device:
https://github.com/Cloud-Architekt/AzureAD-Attack-Defense/blob/main/ReplayOfPrimaryRefreshToken.mdA comprehensive overview about attack and defense scenarios primary refresh token (PRT) & other tokens on Windows has been published by Sami Lamppu and and me. The article includes many references and links to other community resources around this topic.
-
Microsoft has been published a very good summary about #AzureAD security trends in 2023 which considered post authentication attacks, such as #TokenTheft: https://microsoft.com/en-us/security/blog/2023/01/26/2023-identity-security-trends-and-solutions-from-microsoft/
If you are interested to learn more about Token replay attacks, check the following blogs:
🔗 Token tactics: How to prevent, detect, and respond to cloud token theft by Microsoft DART team: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/
This article describes Adversary-in-the-middle (AitM) phishing/Pass-the-cookie attack scenarios and recommendations.
🔗 Abuse and replay of Azure AD refresh token from Microsoft Edge in macOS Keychain:
https://www.cloud-architekt.net/abuse-and-replay-azuread-token-macos/I've written this blog post about token replay on #macOS devices last year. It covers an attack scenario to exfiltrate tokens from Keychain which is used to store cached Azure AD tokens for “logged in” Edge profiles on macOS devices.
🔗 Azure AD Attack & Defense: Replay of Primary Refresh (PRT) and other issued tokens from an Azure AD joined device:
https://github.com/Cloud-Architekt/AzureAD-Attack-Defense/blob/main/ReplayOfPrimaryRefreshToken.mdA comprehensive overview about attack and defense scenarios primary refresh token (PRT) & other tokens on Windows has been published by Sami Lamppu and and me. The article includes many references and links to other community resources around this topic.
-
Microsoft has been published a very good summary about #AzureAD security trends in 2023 which considered post authentication attacks, such as #TokenTheft: https://microsoft.com/en-us/security/blog/2023/01/26/2023-identity-security-trends-and-solutions-from-microsoft/
If you are interested to learn more about Token replay attacks, check the following blogs:
🔗 Token tactics: How to prevent, detect, and respond to cloud token theft by Microsoft DART team: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/
This article describes Adversary-in-the-middle (AitM) phishing/Pass-the-cookie attack scenarios and recommendations.
🔗 Abuse and replay of Azure AD refresh token from Microsoft Edge in macOS Keychain:
https://www.cloud-architekt.net/abuse-and-replay-azuread-token-macos/I've written this blog post about token replay on #macOS devices last year. It covers an attack scenario to exfiltrate tokens from Keychain which is used to store cached Azure AD tokens for “logged in” Edge profiles on macOS devices.
🔗 Azure AD Attack & Defense: Replay of Primary Refresh (PRT) and other issued tokens from an Azure AD joined device:
https://github.com/Cloud-Architekt/AzureAD-Attack-Defense/blob/main/ReplayOfPrimaryRefreshToken.mdA comprehensive overview about attack and defense scenarios primary refresh token (PRT) & other tokens on Windows has been published by Sami Lamppu and and me. The article includes many references and links to other community resources around this topic.
-
Microsoft has been published a very good summary about #AzureAD security trends in 2023 which considered post authentication attacks, such as #TokenTheft: https://microsoft.com/en-us/security/blog/2023/01/26/2023-identity-security-trends-and-solutions-from-microsoft/
If you are interested to learn more about Token replay attacks, check the following blogs:
🔗 Token tactics: How to prevent, detect, and respond to cloud token theft by Microsoft DART team: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/
This article describes Adversary-in-the-middle (AitM) phishing/Pass-the-cookie attack scenarios and recommendations.
🔗 Abuse and replay of Azure AD refresh token from Microsoft Edge in macOS Keychain:
https://www.cloud-architekt.net/abuse-and-replay-azuread-token-macos/I've written this blog post about token replay on #macOS devices last year. It covers an attack scenario to exfiltrate tokens from Keychain which is used to store cached Azure AD tokens for “logged in” Edge profiles on macOS devices.
🔗 Azure AD Attack & Defense: Replay of Primary Refresh (PRT) and other issued tokens from an Azure AD joined device:
https://github.com/Cloud-Architekt/AzureAD-Attack-Defense/blob/main/ReplayOfPrimaryRefreshToken.mdA comprehensive overview about attack and defense scenarios primary refresh token (PRT) & other tokens on Windows has been published by Sami Lamppu and and me. The article includes many references and links to other community resources around this topic.
-
"Threat actors are stealing #authentication tokens already verified by multifactor authentication (MFA) to breach organizations' systems"
Seems to be a pretty nasty attack as organizations haven't considered #tokentheft as part of their #incident response plan....🤨
-
"Threat actors are stealing #authentication tokens already verified by multifactor authentication (MFA) to breach organizations' systems"
Seems to be a pretty nasty attack as organizations haven't considered #tokentheft as part of their #incident response plan....🤨