Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Session Cookie Flaw Risks Entra ID MFA Security

Session Cookie Flaw Risks Entra ID MFA Security

Posted on October 2, 2026 By CWS

A critical flaw in a custom session-cookie system has been identified, allowing unauthorized attackers to impersonate employees and administrators on a yard management platform. This issue does not directly compromise Microsoft Entra ID, but instead affects the application-side session management, enabling identity forgery post sign-in.

Understanding the Vulnerability

The compromised platform employed Entra ID’s single sign-on and multi-factor authentication, but relied on a signed cookie to maintain sessions. This design flaw mirrors risks in cookie-based account attacks, where controlling a session can surpass password importance.

According to Resecurity, which disclosed the vulnerability to Cyber Security News, the flaw was found during a review of a supply-chain yard management system. The assessment, which did not involve production systems, revealed the potential for attackers to impersonate users by exploiting the session management weakness.

Implications of the Security Breach

Researchers demonstrated the vulnerability by impersonating 95 employee accounts out of 241 tested, including those with elevated permissions. A forged administrator session allowed the execution of state-changing API requests, which could expose sensitive operational data and enable actions under a legitimate user’s identity.

The flaw stemmed from two linked design errors: the session cookie was signed with a static secret identical to its name, and the signed value was the user’s public database ID. These issues allowed attackers to create cookies recognized by the server, bypassing the need for passwords or MFA approvals.

Mitigation and Future Prevention

To mitigate the risk, it is crucial to rotate the session-signing secret and invalidate existing sessions. Monitoring authentication and application logs for unusual activity can help detect unauthorized session creation and account changes.

Developers should replace client-controlled session values with server-verified, randomly generated identifiers. Unique, high-entropy secrets must be securely maintained across different environments. Additionally, organizations should review their application layers to ensure a robust integration with cloud identity providers.

Implementing lessons from session hijacking techniques, such as monitoring suspicious sign-ins and enforcing device compliance, can strengthen defenses. For systems requiring stateless tokens, employing strong cryptographic keys and replay protections is advised.

This case highlights the importance of session management following MFA verification. Employing random server-side session references and rotating secrets can significantly reduce the risk of account impersonation due to exposed identifiers.

Cyber Security News Tags:API, Attackers, Authentication, cookie-based attack, Cryptography, Cybersecurity, Entra ID, identity theft, login security, MFA, Resecurity, security breach, session cookie, session management, technology news

Post navigation

Previous Post: Sony Enhances PS5 Security Amid Relapse Jailbreak Concerns

Related Posts

Cisco Unified Contact Center Express Vulnerabilities Let Remote Attacker Execute Malicious Code Cisco Unified Contact Center Express Vulnerabilities Let Remote Attacker Execute Malicious Code Cyber Security News
Exploit Code Published for Microsoft SCCM Vulnerability Exploit Code Published for Microsoft SCCM Vulnerability Cyber Security News
Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials Cyber Security News
PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel’s POSIX CPU Timers Implementation PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel’s POSIX CPU Timers Implementation Cyber Security News
OpenClaw Vulnerabilities Lead to Security Risks OpenClaw Vulnerabilities Lead to Security Risks Cyber Security News
K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges K7 Antivirus Vulnerability Allows Attackers Gain SYSTEM-level Privileges Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Session Cookie Flaw Risks Entra ID MFA Security
  • Sony Enhances PS5 Security Amid Relapse Jailbreak Concerns
  • Critical Dell CSM Vulnerabilities Allow Admin Access
  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Session Cookie Flaw Risks Entra ID MFA Security
  • Sony Enhances PS5 Security Amid Relapse Jailbreak Concerns
  • Critical Dell CSM Vulnerabilities Allow Admin Access
  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark