#SessionHijack
September 7, 2026 at 8:26 AM
SIM swap, OTP abuse, and session hijacking nearly took over a wireless account. A trusted call, SMS approvals, and a carrier passcode show why identity checks must cover the full session. #SIMSwap #IdentityRisk #SessionHijack
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
A coordinated identity attack against a wireless services account combined social engineering, SIM swapping, OTP abuse, and session hijacking, exposing how one-time authentication can fail against determined adversaries. The incident shows why organizations must continuously evaluate identity risk across the full session and protect high-risk actions with stronger verification. #ScatteredSpider #ShinyHunters...
www.hendryadrian.com
July 22, 2026 at 2:45 PM
Two vulnerabilities in Ivanti Neurons ITSM (CVE-2026-4913 & CVE-2026-4914) allow session persistence and stored XSS to expose session data. Cloud fixes released Dec 12, 2025; on-prem users must update via Ivanti License System. #IvantiFix #SessionHijack
Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence
Two newly disclosed vulnerabilities in Ivanti Neurons for IT Service Management (CVE-2026-4913 and CVE-2026-4914) could allow authenticated attackers to persist in user sessions or inject stored XSS payloads to expose session data. Ivanti has applied cloud fixes on December 12, 2025 and released a patched version 2025.4 for all customers, with...
www.hendryadrian.com
April 15, 2026 at 2:45 PM
January 15, 2026 at 12:00 AM