Infostealer Logs Expose AI Session Tokens That Bypass MFA
This story is from 2026-09-16. It is preserved in the archive; the latest stories are on the live feed.
Forensic Summary Cybercriminals are harvesting JWT session tokens and API keys from infostealer logs to replay authentication against major AI platforms including OpenAI, Anthropic, and Google, effectively bypassing MFA entirely. Analysis of a 7 GB stealer dump revealed 1,843 unexpired tokens targe…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-16 20:30 · DEV Community — AI
Infostealer Logs Expose AI Session Tokens That Bypass MFA