New "Man in the Browser" Attack Bypasses Banks' Two-Factor Authentication Systems
The attack, know as the Man in the Browser method, works like this. Malicious code is first introduced onto the victim's computer where it resides in the web browser. It will lay dormant until the victim visits a specific website—in this case, his bank's secure website. Once the user attempts to log in, the malware activates and runs between the victim and the actual website. Often the malware will request that the victim enter his password or other security pass into an unauthorized field, in order to "train a new security system." Once that happens, the attacker has full access to the account.
via gizmodo.com
Pretty nasty, but still only valid for that session.