thehackernews.com 30 Sept 2026, 11:58 UTC

Six Browser Attacks Let Hackers Bypass MFA and Hijack Sessions

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Tycoon2FA

SIX browser-centric attack techniques dominate the threat landscape in 2026, the article argues, with most breaches now unfolding entirely within a browser session. The most exposed vector is phishing for credentials and sessions, where reverse-proxy AiTM kits such as Tycoon2FA, Sneaky2FA and Evilginx relay credentials and session tokens in real time, effectively bypassing MFA.

Phishing content now travels beyond email, delivered via instant messaging, social media, SMS, ads and in-app messaging, with roughly half of attacks occurring outside email and many phishing domains remaining active for under two days.

The piece highlights Malicious copy-and-paste (ClickFix) as a rising initial access technique. Since late 2024, attackers entice users to copy and run malicious commands under the guise of fixing issues, often via fake CAPTCHAs. Four in five ClickFix payloads come from compromised search engines or malvertising, bypassing email security. Authorization phishing is another growing class, abusing OAuth consent grants, device code flows and token exchanges to obtain access tokens without triggering MFA.

The report also warns about malicious browser extensions—where 46.76% of extensions have permission sets enabling account takeover with no user interaction, and where unauthorised AI extensions are common in corporate environments.

The remaining techniques cover credential stuffing and ghost logins, as well as session hijacking, which can defeat phishing-resistant controls by replaying stolen session tokens. The article notes evidence from Push Security, the Verizon DBIR, and Cloudflare’s 2026 Threat Report, and suggests security teams prioritise browser-focused monitoring, strict extension controls, and heightened vigilance around auth and session management to mitigate these browser-based attack chains.

View full article

Article by CyberSIXT