Security1 distinct publisher2 min readPublished
The figure comes from a vendor selling stealer-log monitoring, and no methodology is stated, but it lands on the awkward half of the response: containment on hardware the employer does not own, while the session cookie circulates.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Flare's triage example is the part of the guide worth keeping. Two alerts arrive the same morning: one is a six-month-old log holding an employee's old password for a consumer website, the other was collected yesterday and carries corporate identity credentials plus an authenticated browser session for the organization's identity provider [9]. Standard tooling files both under employee credential exposure, and Flare's argument is that they are not the same event [9].
A reset revokes the password and nothing else in the log. Flare's asset priority follows from that, weighting corporate domains and subdomains, enterprise identity providers, session cookies, VPN and RDP endpoints and cloud consoles, with SSO identities at Microsoft Entra ID, Okta or Google Cloud Identity singled out for attention [10].
In the case Flare opens with, Vidar landed on an employee's personal computer hundreds of miles from the company's offices, and the log still held a corporate SaaS username and password, browser cookies for live sessions, and further credentials saved in files [6]. None of that sits on hardware the employer can query. The complement of the 46 percent is where ordinary incident response still applies: 54 percent of corporate-credential logs come from devices Flare does not flag as likely unmanaged or personal [12]. On the other half, a single infection that can yield hundreds or thousands of records [8] has to be assessed from the outside, using the log itself as the only forensic artifact.
The growth estimate sets a clock. At 29 percent a year, exposure of SaaS credentials and sessions doubles in about 2.7 years, since ln(2) divided by ln(1.29) is 2.72 [11]. Resale sets a shorter one: by the time the analyst opens the ticket, Flare says the same record may already be with an initial access broker, ransomware affiliate or opportunistic attacker [14].
Every figure here is Flare's, and the write-up gives no sample size and no collection methodology for the 46, 29 or 90 percent [15]. Read them as descriptions of what one commercial collector sees. The Telegram share is the most self-referential of the three, because a monitoring vendor's channel coverage decides what it can count. The response logic survives that caveat, since it needs only two fields from the log: the collection date, and whether a cookie is in it.
Ranked by verification strength, evidence, and original report placement.
Stealer logs contain browser cookies, meaning live sessions that can be exploited; if a stealer captured an authenticated session cookie, an attacker may already have a way into the application without needing the password or another MFA prompt.
The article was published on BleepingComputer and promotes Flare's real-time monitoring of stealer logs across the dark web and Telegram, closing with an offer of a free two-week trial.
In the scenario the article opens with, a personal employee computer located hundreds of miles from the company's offices was infected by Vidar, and the resulting log contained a username and password for a corporate SaaS application, browser cookies, and several other saved credentials in files.
Infostealers named include RedLine, Lumma and Vidar; depending on the malware and configuration, harvested data can include saved browser passwords, cookies, autofill information, cryptocurrency wallets, system information and VPN configurations.
A single infostealer infection can produce hundreds or thousands of individual records.
Flare contrasts two alerts: one involving an employee's old password for a consumer website in a six-month-old stealer log, the other collected yesterday and containing the employee's corporate identity credentials and an authenticated browser session for the organization's identity provider; both may be labelled employee credential exposures but they are completely different.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Anthropic wipes saved cards after infostealers copy Claude login sessions1 distinct publisher
security
Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told5 distinct publishers
security
Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call1 distinct publisher
security
Anthropic says everyday infostealers are lifting live Claude sessions off victim machines1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's guide, unshown data
The three headline figures all come from Flare's own guide, and the write-up gives no sample size, no collection period and no rule for deciding when a log came from an 'unmanaged or personal' device. That last judgement is where the 46% actually lives, and the word 'likely' is doing the work. What stands without Flare is the technical description: infostealers do take cookies, replayed sessions do skip the MFA prompt, and one infection does produce a great many records.
No usage anywhere in the reporting
Nothing in this coverage says how many organisations monitor stealer logs, how many use Flare, or how often one of these exposures became an actual intrusion. A free trial offer is not a deployment count, so we score nothing rather than read the vendor's growth estimate as uptake.
Real problem, borrowed precision
The underlying problem is not inflated. Session cookies genuinely defeat a password reset, and analysts genuinely drown in volume. The overstatement is in the decimal-free confidence of 46, 90 and 29, which arrive as research findings inside a piece selling the remedy, while the half of Flare's own split that points somewhere other than personal devices never gets mentioned because it does not sharpen the pitch.
The measurer sells the monitoring
Flare wrote the guide, produced the statistics, and the body text breaks off mid-argument for a free two-week trial of Flare's monitoring. Readers get genuinely usable triage advice; in exchange Flare gets to define what counts as urgent, and the definition happens to enumerate a monitoring product's coverage: corporate domains, identity providers, session cookies, VPN and RDP endpoints, cloud consoles.
Clear on who benefits, blind on who verified
We can see precisely where each claim originates and precisely what is missing from it, which makes the read on incentives firm. The figures themselves we can neither confirm nor knock down: no second publisher in our coverage engaged with them, and Flare's underlying corpus is not published. That asymmetry caps how much weight anyone should put on the number in the headline.