CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6844

As cited

Copy frozen at (site build).

threat intel

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are harvesting artificial intelligence (AI) account credentials and session tokens from compromised systems using information stealer malware such as Lumma Stealer and Vidar. These stolen tokens can grant unauthorized access to AI services from providers including Google and Anthropic, potentially bypassing multifactor authentication (MFA) protections.

Why it matters: Organizations and individuals using AI platforms face account takeover risk if their systems are infected with information stealers; practitioners should enforce endpoint detection and response (EDR) monitoring, credential rotation policies, and application programming interface (API) token lifecycle management to limit exposure.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary