CyberSecurity News
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
AI summary
Cybercriminals are gaining unauthorized access to artificial intelligence user accounts by exploiting information stolen through malware such as Lumma Stealer or Vidar. This stolen information can include credentials, session tokens, and API keys, which are being used to create replayable tokens. These tokens can be used to bypass multi-factor authentication and gain access to tools from various model providers. The affected model providers include Google and Anthropic, among others. The stolen tokens essentially act as stolen keys, granting illicit access to these tools.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

