LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ai

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

zeroday.news ·

A recent report indicates that threat actors are leveraging information stealer logs to obtain replayable AI tokens, which can then be used to bypass multi-factor authentication (MFA) and gain unauthorized access to AI user accounts. These "stolen keys" are reportedly being used to access tools provided by major AI model providers, including Google and Anthropic.

The mechanism involves common information stealer malware, such as Lumma Stealer and Vidar, which are designed to exfiltrate a broad spectrum of sensitive data from compromised systems. This harvested data typically includes traditional credentials, but critically, also encompasses session tokens and API keys. It is these session tokens and API keys, specifically those associated with AI services, that are being identified as replayable and capable of bypassing MFA.

When a user interacts with an AI service, a session token or API key is often generated to maintain authenticated access without requiring repeated credential entry. If an information stealer compromises a system, it can harvest these active tokens. The replayability of these tokens means that a threat actor can use them from a different location or device to impersonate the legitimate user, effectively bypassing any MFA prompts that would normally challenge a new login attempt.

This class of attack highlights a persistent challenge in cybersecurity: the protection of active session material. While MFA significantly strengthens initial authentication, its effectiveness can be diminished if active session tokens are compromised and are not sufficiently bound to specific user environments or invalidated upon suspicious activity. Products in the AI service category, like many cloud-based platforms, rely on these tokens for seamless user experience, making their secure handling paramount.

The scope of this issue is potentially broad, given the widespread use of information stealer malware and the increasing adoption of AI tools across various industries. Any organization or individual using AI services from providers like Google and Anthropic, whose systems might be susceptible to information stealer infections, could be at risk.

Mitigation strategies for this type of threat typically involve a multi-layered approach. Users should employ robust endpoint security solutions to prevent information stealer infections, practice good cyber hygiene, and be wary of phishing attempts. For organizations, implementing strong access controls, monitoring for anomalous login patterns, and ensuring that session tokens have appropriate expiration times and are invalidated upon suspicious activity are crucial. Additionally, where possible, binding session tokens to specific device identifiers or IP addresses can reduce their replayability.

This incident underscores the evolving threat landscape where traditional credential theft is now augmented by the compromise of session and API tokens, particularly in the context of emerging technologies like artificial intelligence. It serves as a reminder that security measures must continuously adapt to protect not just initial authentication, but also the ongoing authenticated sessions that power modern digital services.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]