الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Don’t let the cookies bite: Kaspersky warns of the looming threat of web session hijacking

A new Kaspersky report reveals that 87% of randomly surveyed websites display cookie notifications, yet most users remain unaware of the serious threats posed by these small data files. Cookies are text files stored by browsers to enhance website functionality and track user activity, and they sometimes become targets for cyberattacks. One such threat, session ID hijacking, involves attackers gaining unauthorized access to users’ active sessions on websites. This could potentially give attackers access to sensitive data or the ability to perform actions on a victim’s behalf, like setting up unauthorized transactions. With global regulations like GDPR and others mandating transparency in data collection, the report emphasizes the critical need for robust cookie management to protect personal and corporate information from exploitation.
Depending on the website’s configuration, cookie files can store a variety of data including browsing preferences, personal details such as phone numbers or payment information, and even login credentials. Attackers can steal these cookies to hijack a user’s session on a website. For instance, with a session sniffing technique, attackers might intercept a user’s session ID on public Wi-Fi, or if the site uses HTTP protocol instead of HTTPS. Cross-site scripting (XSS) allows attackers to inject malicious scripts into a website, which are executed in a user’s browser to steal session IDs or other cookie data. Session fixation is used by attackers to trick victims into using a pre-set session ID, allowing access to their account after authentication.
In a real-life scenario, if an attacker intercepts a user’s session ID while the user is logged into an online store, the attacker can, for instance, get the shipping address or access the user’s payment credentials if the session grants access to the account’s payment settings. Thus, session ID hijacking can lead to privacy breaches, financial loss, as well as account compromise or even identity theft. The user may also face reputational damage if the attacker misuses their account to send fraudulent messages or make unauthorized posts.
“Cookies are the backbone of seamless online experiences, enabling everything from personalized settings to streamlined logins, but they’re also a target for hackers if not handled with care. Without proper safeguards, attackers can exploit session IDs to hijack user accounts, steal sensitive data, or even manipulate website interactions, making it imperative for developers to prioritize security measures and for users to stay proactive in protecting their digital footprint,” comments Natalya Zakuskina, Senior Web Content Analyst at Kaspersky.
To counter these threats, Kaspersky recommends users the following:
• Avoid browsing HTTP-based websites and should never input any sensitive information on these websites as it is easily intercepted. Users should also avoid sharing sensitive or confidential information when using public Wi-Fi networks without virtual private network (VPN).
• Opt for minimal cookie acceptance when possible. Remember to clear browser’s cookies and cache regularly.
• Enable two-factor authentication, avoid clicking on suspicious links, and regularly clear browser data.
Website developers should enforce HTTPS, use HttpOnly and Secure flags, implement CSRF tokens, and adopt cryptographically secure session ID generation.

 

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com

Follow us on:

Related Posts:

GB Auto Launches Exclusive Promotional Campaign on the All-New Hyundai “Santa Fe” in the Egyptian Market

Celebrate The Third Beat of ALAYA With a One-Night-Only Anniversary Extravaganza

Selim Holding strengthens its team with new hires to lead Hilton Capital project

   InterContinental Abu Dhabi Hotel & Residences Appoints Erika Anggreini as Cluster Assistant Director of Marketing

EFG Hermes Unveils Cutting-Edge, Intelligent Risk-Based Advisory Service in Partnership with Kenzi Wealth, Offering Tailored, Risk-Optimized Investment Services to Empower Clients in Growing and Safeguarding Their Investments

Madinet Masr Secures FRA Approval to Establish “SAFE” Real Estate Fund

Egypt Innovation Week 2025 Transforms Regional Tech Landscape

MCS, EMGF Sign MoU on Cybersecurity Capacity Building

آخر الأخبار
رئيس الوزراء يهنئ الشعب المصرى بمناسبة ذكرى المولد النبوى الشريف بيان مصرى سودانى: السد الإثيوبى مخالف للقانون وآثاره جسيمة على دولتى المصب ١٣ مليون و ٣٩ ألف جنيه حصيلة البيع بجلسة مزاد ٣ سبتمبر ٢٠٢٥ لسيارات وبضائع جمارك بورسعيد رئيس الوزراء يلتقي رئيس شركة "إيليت سولار" الصينية المُصنعة لمكونات محطات الطاقة الشمسية والرياح وزير العمل: 70% من العمالة في المانيا من خريجي التعليم الفني وزير العمل: القانون الجديد تلافي كل العيوب بالقانون القديم مصر وكندا: شراكة استثمارية جديدة تفتح آفاقًا واعدة تعليم الجيزة يكرم المبدعين… تكريم استثنائي لنجوم التفوق والإبداع تعليم الجيزة تتابع استعدادات العام الدراسي الجديد 2025/2026 بإدارة الهرم التعليمية سعيد عطية : الذكاء الاصطناعي أصبح ركيزة أساسية في التطوير التربوي تقرير كاسبرسكي: ملفات تعريف الارتباط) الكوكيز( تهدد الخصوصية وسرية البيانات Don’t let the cookies bite: Kaspersky warns of the looming threat of web session hijacking وزير الإسكان يتفقد أعمال رفع كفاءة محطة المياه الرئيسية بمدينة العبور الإمارات وجنوب أفريقيا تبحثان فرص تعاون جديدة لتعزيز العلاقات التجارية والاستثمارية "فيوز Fuze" تفتتح مقرها الرئيسي الجديد في "مدينة إكسبو دبي" وزير الإسكان يتابع مستجدات إنشاء وحدة "الإيجار والسكن البديل" مان إيست تفتتح المقر الرئيسي وصالة عرض متكاملة لعلامة سو إيست في الشيخ زايد اقتصادية قناة السويس توقع عقد مشروع "شوانفينج" الصينية للملابس الجاهزة بالقنطرة غرب وزارة الصحة تغلق 12 مركزًا غير مرخص لعلاج الإدمان في كرداسة إنفيديا تمكّن الطلاب من أحدث أدوات الذكاء الاصطناعي عبر أجهزة الكمبيوتر المحمولة GeForce RTX 50 Seri...