← AI security in plain English

AML.T0113

MITRE ATLAS / Steal Web Session Cookie

Adversaries steal the web application or service session cookies that authenticate users to AI-enabled systems, AI service consoles, and supporting enterprise applications. Session cookies often remain valid long after the user stops actively using the application.

Think of it likeTaking someone's cloakroom ticket, which still works even though they never handed over the coat.

In plain English

A stolen session cookie logs an attacker in as the user without a password and usually without triggering multi-factor. Chat interfaces and AI service consoles hold sessions open for a long time.