Risk: Compromised user identity and session management. Includes weak passwords, session fixation, and poor credential recovery.
Implement strong authentication with proper password hashing, MFA, and robust session management.
Harden authentication flows, add MFA, and fix session vulnerabilities.
Session rotation, secure cookies, throttling, and anomaly detection.