Security Matters  cover image

Security Matters

EP 49 - Secure Browsing and Session-Based Threats

Apr 3, 2024
Shay Nahari, VP of CyberArk Red Team Services, discusses session-based threats and secure browsing. Topics include cookie theft dangers, expanding attack surfaces, and CyberArk Secure Browser's end-to-end identity control. Importance of least privilege, assume breach mindset, and protecting organizations from session-based attacks.
30:13

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Post-authentication attacks target cookies, API keys, and certificates to bypass authentication.
  • Browsers lacking enterprise security controls pose challenges in designing identities and handling authentication.

Deep dives

The Vulnerability of Session-Based Authentication

Attackers have shifted focus to session-based authentication due to the widespread adoption of multifactor authentication (MFA), making traditional password-based authentication less vulnerable. Post-authentication processes like cookies, API keys, and machine certificates have become prime targets for attackers as stealing these can bypass the authentication stage entirely. The attractiveness of post-authentication attacks lies in the ability to exploit credentials obtained after authentication, giving attackers a direct route to sensitive systems.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode