• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Kaspersky warns of the looming threat of web session hijacking

by CXO Staff
September 3, 2025
in Future, News, Tech

A new Kaspersky report reveals that 87% of randomly surveyed websites display cookie notifications, yet most users remain unaware of the serious threats posed by these small data file

Kaspersky warns of the looming threat of web session hijacking

A new Kaspersky report reveals that 87% of randomly surveyed websites display cookie notifications, yet most users remain unaware of the serious threats posed by these small data files. Cookies are text files stored by browsers to enhance website functionality and track user activity, and they sometimes become targets for cyberattacks. One such threat, session ID hijacking, involves attackers gaining unauthorised access to users’ active sessions on websites. This could potentially give attackers access to sensitive data or the ability to perform actions on a victim’s behalf, like setting up unauthorised transactions. With global regulations like GDPR and others mandating transparency in data collection, the report emphasises the critical need for robust cookie management to protect personal and corporate information from exploitation.

Depending on the website’s configuration, cookie files can store a variety of data including browsing preferences, personal details such as phone numbers or payment information, and even login credentials. Attackers can steal these cookies to hijack a user’s session on a website. For instance, with a session sniffing technique, attackers might intercept a user’s session ID on public Wi-Fi, or if the site uses HTTP protocol instead of HTTPS. Cross-site scripting (XSS) allows attackers to inject malicious scripts into a website, which are executed in a user’s browser to steal session IDs or other cookie data. Session fixation is used by attackers to trick victims into using a pre-set session ID, allowing access to their account after authentication.

In a real-life scenario, if an attacker intercepts a user’s session ID while the user is logged into an online store, the attacker can, for instance, get the shipping address or access the user’s payment credentials if the session grants access to the account’s payment settings. Thus, session ID hijacking can lead to privacy breaches, financial loss, as well as account compromise or even identity theft. The user may also face reputational damage if the attacker misuses their account to send fraudulent messages or make unauthorised posts.

“Cookies are the backbone of seamless online experiences, enabling everything from personalised settings to streamlined logins, but they’re also a target for hackers if not handled with care. Without proper safeguards, attackers can exploit session IDs to hijack user accounts, steal sensitive data, or even manipulate website interactions, making it imperative for developers to prioritise security measures and for users to stay proactive in protecting their digital footprint,” comments Natalya Zakuskina, Senior Web Content Analyst at Kaspersky.

To counter these threats, Kaspersky recommends users the following:

  • Avoid browsing HTTP-based websites and should never input any sensitive information on these websites as it is easily intercepted. Users should also avoid sharing sensitive or confidential information when using public Wi-Fi networks without virtual private network (VPN).
  • Opt for minimal cookie acceptance when possible. Remember to clear browser’s cookies and cache regularly.
  • Enable two-factor authentication, avoid clicking on suspicious links, and regularly clear browser data.

Website developers should enforce HTTPS, use HttpOnly and Secure flags, implement CSRF tokens, and adopt cryptographically secure session ID generation.

Tags: Kasperskyreport
ShareTweet

Related Posts

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit
Banking and Finance

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

December 5, 2025

Covoro YouCloud, a strategic joint venture formed to accelerate digital tax transformation across the GCC, announced its participation as a...

EQUATE and Kyndryl extend partnership to strengthen global IT systems
Business

EQUATE and Kyndryl extend partnership to strengthen global IT systems

December 4, 2025

EQUATE Group announced the renewal and expansion of its five-year managed infrastructure services partnership with Kyndryl. The renewed agreement reinforces...

Discussion about this post

Latest Issue

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

Covoro YouCloud unveils Agentic AI UAE E-Invoicing solution at Tax Technology Summit

December 5, 2025
EQUATE and Kyndryl extend partnership to strengthen global IT systems

EQUATE and Kyndryl extend partnership to strengthen global IT systems

December 4, 2025
CIS partners with Cequence & Astrix to help enterprises secure AI and Agentic systems

CIS partners with Cequence & Astrix to help enterprises secure AI and Agentic systems

December 4, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.