AINewsnow

Infostealer Logs Expose AI Session Tokens That Bypass MFA

This story is from 2026-09-16. It is preserved in the archive; the latest stories are on the live feed.

Forensic Summary Cybercriminals are harvesting JWT session tokens and API keys from infostealer logs to replay authentication against major AI platforms including OpenAI, Anthropic, and Google, effectively bypassing MFA entirely. Analysis of a 7 GB stealer dump revealed 1,843 unexpired tokens targe…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-16 20:30 · DEV Community — AI
    Infostealer Logs Expose AI Session Tokens That Bypass MFA

More stories

  1. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  2. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  3. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  4. Google’s Gemini AI hacked into other companies, adding to ‘rogue’ AI incidents — Washington Post AI
  5. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  6. We need to talk about Irregular — r/singularity
  7. Gemini self-censors in a harmful, obscure way — r/GeminiAI
  8. I gave 6 different AIs the same 5 questions — r/AI_Agents

Get the daily brief of stories like this at 6:30 every morning →