Session Token Theft: Multi-Factor Authentication Without a Multi-Factor Prompt
Adversary-in-the-middle phishing does not defeat MFA by breaking it. It waits until MFA has already succeeded, then takes what MFA produced.
Intelligence register
A working register of intrusions, techniques and exposures. Each record explains how the failure happened, which signals were available, and what would have changed the outcome.
Featured record
An intrusion that never touched production directly. The attacker modified a build agent, and the organisation shipped the backdoor itself through its own signed release channel.
Incident Analysis4 min read
Latest intelligence
Each record is a self-contained analysis: what happened, how it worked, and which controls would have changed the outcome.
Adversary-in-the-middle phishing does not defeat MFA by breaking it. It waits until MFA has already succeeded, then takes what MFA produced.
Public buckets are rarely the result of someone choosing "public". They are the result of inherited permissions, broad principals, and policies that outlive their purpose.
When every tool in the intrusion ships with the operating system, signature-based detection has nothing to match. What remains is relationship, context and frequency.
A class of flaw where the vulnerable code is often correct, the input is often authenticated, and the exposure window is set by patch logistics rather than by exploit difficulty.
Five detections, in deployment order, with the telemetry each one needs, the noise it produces, and the tuning required before it earns a place in a queue.
Browse by category
Categories describe the kind of question a record answers, not the vendor or product involved.
Reconstructions of confirmed intrusions: entry point, dwell time, impact and the controls that would have changed the outcome.
How a single technique works in practice, where it shows up in telemetry, and what reliably detects it.
Root-cause breakdowns of software weaknesses, exploitation conditions and realistic exposure windows.
Identity, workload and storage failures specific to managed infrastructure and shared-responsibility gaps.
Authentication bypasses, session abuse, privilege paths and the directory misconfigurations that enable them.
Detection logic, hardening sequences and response steps written to be implemented, not admired.
Methodology
The same four stages apply to every record, in this order. Nothing is published that has not completed all four.
Primary material only: incident reports, vendor advisories, telemetry samples and published research. Aggregator coverage is treated as a pointer, never as a source.
Each material claim is checked against a second independent source. Claims that survive only one source are marked as such or removed.
Events are placed on a timeline with explicit gaps. Where sequence is inferred rather than evidenced, the record says so in plain language.
Every record closes with a confidence assessment and states what would change it. Analysis without a stated confidence level is opinion.
Editorial standards
These four commitments are the reason a record is worth reading. They are also the easiest things to check.
Subscribe
One message per record. No newsletter digest, no product mail, and you can unsubscribe from any message.