Skip to content

Topic

Session and Cookie Hijacking

Attacks that steal or replay authenticated session material so that account password resets alone do not restore control.

Current stories

security1 publisher

Australian Signals Directorate tells AI customers to guard their own keys and sessions

Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence50
security7 publishers

Commodity infostealers are now cashing out stolen Claude sessions

Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.

Perspective Coverage

7 publishers
Builder
Builder 19%
Operator
Operator 72%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence60