<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Session-Hijacking on CuraSec</title><link>https://curasec.metacog.co.kr/tags/session-hijacking/</link><description>Recent content in Session-Hijacking on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 30 Aug 2026 15:19:58 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/session-hijacking/index.xml" rel="self" type="application/rss+xml"/><item><title>Infostealer malware hijacks Claude sessions to drain usage</title><link>https://curasec.metacog.co.kr/insights/2026-08-30-anthropic-warns-infostealer-malware-is-hijacking-claude-sess/</link><pubDate>Sun, 30 Aug 2026 15:19:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-30-anthropic-warns-infostealer-malware-is-hijacking-claude-sess/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Infostealers targeting developer AI-tool sessions is a realistic threat on dev machines. Audit active Claude API keys and session tokens for anomalous usage, and confirm your endpoint protection covers current infostealer families.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Confirms infostealers (T1539) are expanding targeting to AI platform sessions, broadening the credential-theft surface. No IOCs or specific malware families disclosed, so no immediate detection action is possible.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Signals that AI tools are now routine infostealer targets, meaning compromised employee devices could expose corporate AI usage. No breach at a specific vendor; file as context for AI-tool acceptable-use and endpoint hygiene policy reviews.&lt;/li>
&lt;/ul></description></item></channel></rss>