A sophisticated cyber threat has come to light, where malicious actors are exploiting compromised login credentials to bypass multi-factor authentication (MFA) and gain unauthorized access to sensitive systems. The attack method involves using stolen AI tokens, which are essentially digital keys that can be replayed to authenticate a user, thereby sidestepping MFA protections.
The vulnerability arises from the use of “infostealer” malware, which is designed to harvest login credentials and other sensitive information from compromised devices. Once an attacker has gained access to these credentials, they can create AI tokens, which are typically used as a second form of authentication in addition to passwords or one-time passcodes (OTPs). These tokens contain encrypted data that can be decrypted by the authenticating system, providing seamless access to protected resources.
The key aspect of this attack is that the compromised AI tokens can be replayed, allowing the attacker to repeatedly gain unauthorized access to the targeted systems. This makes it challenging for security teams to detect and respond to such attacks, as they may not trigger any immediate alarms or logging activity. Furthermore, since MFA is bypassed, traditional detection methods may not pick up on these malicious activities.
The affected organizations include those that use AI tokens in conjunction with passwords or OTPs to secure their systems. The threat applies particularly to cloud-based services and applications, where AI tokens are often used for streamlined authentication processes. According to researchers, this vulnerability is not limited to a specific vendor or technology stack but can be exploited across various platforms.
The broader implication of this attack vector is that it exposes a critical weakness in the way modern security controls interact with AI-powered authentication systems. This highlights the need for enhanced security measures and protocols to counter such threats, particularly in high-risk environments where sensitive information is at stake.
So what can you do to protect yourself from this type of threat? It’s essential to ensure that your organization’s security posture includes multi-layered defenses against identity exposure and privilege escalation attacks. Regularly review and update your authentication processes, including the use of AI tokens, to identify potential vulnerabilities. Additionally, implement robust logging and monitoring tools to detect anomalies in user behavior, enabling swift response to any suspected threats.
Source: The Hacker News — 2026-09-09