AI Weekly Malaysia

Back to items Summaries

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

ID
22825
Status
summarized
Published
09 Sep 2026, 10:23 PM
Fetched
10 Sep 2026, 12:03 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
10 Sep 2026, 12:05 AM
Tags
Audience
developersai_agent_userssaas_founders

What happened

Okta analyzed a 7GB infostealer dump from a Telegram channel (Aug 2, 2026) covering 5,871 infected machines across 162 countries, finding 44,791 unique JWTs of which 555 were tied to AI service authentication and 1,843 JWTs/JWEs were still unexpired on release day. Stolen session tokens and API keys from services like Google, Anthropic, OpenAI, Cursor, Notion, and others can be replayed to bypass username/password and MFA entirely, giving attackers direct account access.

Why it matters

If you build or use AI services that rely on JWTs or session tokens (especially OpenAI's NextAuth.js-based JWEs), MFA will not save you if an infostealer like Lumma or Vidar harvests tokens from a compromised machine. Rotate and shorten token lifetimes, add server-side session revocation, and treat endpoint hygiene as part of your AI service security posture—not just credential hygiene.

Discussion angle

For founders shipping AI-powered SaaS: are you setting short-lived tokens and implementing real session revocation, or are you assuming MFA is enough? Cursor and Notion tokens appearing in stealer logs means your own users' compromised laptops can become your breach.

Top