Research noteTI-2026-0414
Infostealer logs feed almost every other campaign
Commodity credential theft on personal devices is the input to targeted intrusion.
SeverityHigh
5 minThreat Intelligence
Session cookies and saved credentials harvested from unmanaged personal machines end up in bulk markets, where they are filtered for corporate domains and resold.
The control that works is session binding and short lifetimes. Password rotation does nothing against a stolen live session.