Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

A newly uncovered vulnerability in identity exposure management systems has exposed replayable AI tokens that can bypass even the most robust multi-factor authentication (MFA) protocols. This critical flaw, discovered through a series of real-world attacks, allows malicious actors to exploit AI-powered login tokens and gain unauthorized access to sensitive networks.

The issue lies in the way modern identity exposure management systems handle cross-domain privilege escalation, which is meant to prevent lateral movement within compromised networks. However, a cleverly crafted attack can manipulate these systems into issuing replayable AI tokens that can be used to bypass even MFA-protected accounts. This means that once an attacker gains access to one account, they can use the same token to log in to other accounts on the network, essentially giving them free rein.

The affected parties are numerous and widespread, with several prominent organizations confirming that their systems have been compromised. A quick analysis of publicly available logs reveals a pattern of attacks where attackers exploit this vulnerability by inserting malicious code into identity exposure management systems. This code is then used to extract AI tokens, which can be replayed across the network to gain access to multiple accounts.

The AI token bypassing MFA mechanism relies on a clever manipulation of session IDs and authentication protocols. In essence, an attacker can manipulate the system’s understanding of what constitutes a valid session ID, allowing them to reuse a single login token to access multiple accounts. This is made possible by the way modern authentication systems rely on session-based tokens, which are typically used in conjunction with MFA to provide additional security.

The implications of this vulnerability are severe, as it allows attackers to move laterally within compromised networks without being detected. This can lead to significant data breaches and unauthorized access to sensitive systems. Furthermore, the use of AI-powered login tokens adds an extra layer of complexity, making it increasingly difficult for organizations to detect and respond to these types of attacks.

To mitigate this vulnerability, organizations must implement robust identity exposure management practices that prioritize session ID validation and authentication protocol enforcement. Additionally, implementing advanced threat detection tools that can identify anomalous login behavior will help prevent attackers from exploiting this vulnerability. By taking proactive measures to secure their systems, organizations can minimize the risk of a devastating breach.


Source: The Hacker News — 2026-09-09