The Cookie-Bite attack is an advanced evolution of Pass-the-Cookie exploits. This tactic bypasses Multi-Factor Authentication (MFA) by leveraging stolen authentication cookies”, such as Azure Entra ID’s ESTSAUTH and ESTSAUTHPERSISTENT”, to impersonate users.
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2025/05/understanding-the-cookie-bite-mfa-bypass-risk/
![]()

