This week's breach and leak round-up includes stolen session cookies used to bypass MFA. For organisations of every size, the lesson is consistent: assume exposure, rotate credentials, enforce MFA and monitor for suspicious activity. For steps you can take today, see the knowledgebase guidance on credentials, MFA and monitoring.