
Infostealer Logs Expose Employee Credentials and Authenticated Sessions, Heightening Account Takeover Risk
A recent advisory from Flare, reported by BleepingComputer, highlights that infostealer malware can exfiltrate more than just passwords. Stolen browser cookies, session tokens, and authenticated sessions may allow attackers to bypass multi-factor authentication and gain unauthorized access to organizational accounts. The guidance emphasizes the need for defenders to prioritize compromised identities, assess whether stolen access is still usable, and implement credential rotation and session invalidation procedures before account takeover occurs.
