Because browsers auto-send cookies, a malicious site can make your browser fire an authenticated request to your bank (Cross-Site Request Forgery). Defenses: SameSite cookies (block cross-site sends), anti-CSRF tokens (a secret the attacker can't know), and checking the Origin/Referer. Token-based (Authorization header) APIs are largely immune since the header isn't auto-sent.