- An attack in which an attacker steals authentication tokens after all factors have been validated. These tokens, which can include cookies but also bearer tokens as well as JWTs (JSON Web Tokens), are then used to perform session hijacking.
- Previous term: Pascal case
- Next term: Passkey
- Random term: Responsibility assignment matrix