Connect with us

News

Kaspersky Warns Of Rising Cookie Hijacking Threat

A new report highlights how session hijacking through cookies could expose users to identity theft, financial loss, and account compromise.

Published

on

kaspersky warns of rising cookie hijacking threat

Cookies are a familiar part of modern browsing, powering everything from saved logins to personalized settings. But according to a new Kaspersky report, they’re also a growing security risk. The study found that 87% of surveyed websites display cookie notifications, yet most users remain unaware of how these files can be exploited by attackers through a process known as session hijacking.

Cookies are small text files stored in browsers, often containing preferences, personal data, or even login credentials. If compromised, attackers can steal a user’s session ID and gain access to active accounts. Once inside, they could perform unauthorized actions such as retrieving payment information, placing fraudulent orders, or sending malicious communications.

Attackers have several methods to exploit cookie data. On unsecured HTTP sites or public Wi-Fi networks, session sniffing can intercept IDs in real time. Cross-site scripting (XSS) injects malicious code into a site to extract cookie data directly from the browser. Session fixation tricks users into authenticating with a pre-set session ID, allowing attackers to gain control after login. In practical terms, this could expose sensitive details such as shipping addresses, payment settings, or even lead to full account takeover.

“Cookies are the backbone of seamless online experiences, enabling everything from personalized settings to streamlined logins, but they’re also a target for hackers if not handled with care,” said Natalya Zakuskina, Senior Web Content Analyst at Kaspersky. “Without proper safeguards, attackers can exploit session IDs to hijack user accounts, steal sensitive data, or even manipulate website interactions, making it imperative for developers to prioritize security measures and for users to stay proactive in protecting their digital footprint”.

Also Read: KAUST Mathematical Model Tackles 5G Interference With Aircraft

Kaspersky advises users to avoid entering sensitive data on HTTP-based sites, minimize cookie acceptance, and regularly clear cookies and cache. Additional precautions include using VPNs on public Wi-Fi, enabling two-factor authentication, and steering clear of suspicious links.

With cookies underpinning so much of the digital economy, Kaspersky warns that ignoring these vulnerabilities could result not only in financial losses but also long-term reputational damage for individuals and businesses alike.

Advertisement

📢 Get Exclusive Monthly Articles, Updates & Tech Tips Right In Your Inbox!

JOIN 23K+ SUBSCRIBERS

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Syria Just Got Its First Super App Featuring Built-In Digital Payments

Built by UAE-based Syrian founders with the Ministry of Tourism’s backing, My Syria lands as visitor numbers more than double.

Published

on

syria just got its first super app featuring built-in digital payments

For most of the past decade, paying for anything in Syria with an international card was effectively impossible. Sanctions, a collapsed banking sector, and years of isolation left the country running on cash. That is what makes the launch of My Syria — the country’s first super app — more than a routine product announcement.

Developed by 121 Living, a company founded by four UAE-based Syrian entrepreneurs — Rami Kaiem, Feras Kaiem, Waseem Qudmani, and Kinan Madi — the app launched in Damascus on July 30 under the patronage of Minister of Tourism Mazen Al-Salhani. It bundles hotels, restaurants, transport, attractions, food delivery, and other lifestyle services into a single platform, currently offering eight services with plans to expand to more than 40 verified tourism and hospitality providers across the country.

Although the app already sounds enticing, the headline feature is its built-in payments. My Syria is the first platform in Syria to support cross-border digital payments through Apple Pay, Google Pay, Visa, Mastercard, and American Express — familiar tools for international visitors, and a route into the digital economy for local businesses that have long operated outside it.

my syria super app launch event

The launch rides on a sharp rebound for the troubled country. Syria’s tourism sector recorded 3.52 million visitor arrivals in the first half of 2026, a 111 percent increase over the 1.67 million during the same period in 2025 — a mix of returning expatriates, regional visitors, and international tourists.

Also Read: This UAE Platform Wants To Replace Fashion Photo Shoots With AI

The Ministry of Tourism, which supported and supervised the app’s development, frames the launch as proof of concept for a wider strategy. “Digital transformation is one of the Ministry’s strategic priorities because it enables us to build a more competitive, connected and investment-ready tourism sector,” Al-Salhani said, inviting technology companies “globally, regionally and locally” to explore opportunities across the wider economy.

For 121 Living, this is phase one, with additional services and expanded geographic coverage planned. Whether a super app can flourish in a market still rebuilding its infrastructure is an open question, but for the first time in years, a visitor to Damascus can pay for dinner with their phone.

Continue Reading

#Trending