New "Storm" infostealer skips local decryption, sending browser data to attacker servers. Varonis shows how server-side decryption enables session hijacking, bypassing passwords and MFA.
Abstract: On the contemporary web, cookies are pervasive and serve as crucial instruments used by developers of websites, marketers, and companies to improve user experience and acquire useful data.