<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AppSec Science - Blog</title><description>Read my latest blog posts</description><link>https://appsec.science/</link><item><title>The Infostealer Era and Why Device Bound Sessions Change the Math</title><link>https://appsec.science/blog/infostealers-and-dbsc/</link><guid isPermaLink="true">https://appsec.science/blog/infostealers-and-dbsc/</guid><description>Infostealers have turned stolen session cookies into a commodity that walks straight past MFA. Device Bound Session Credentials break that economy, and our open DBSC implementation helps services adopt it today.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>infostealers</category><category>session-security</category><category>dbsc</category><category>authentication</category><category>platform-security</category></item></channel></rss>