Okta TI: infostealer logs expose replayable AI session tokens and API keys
Okta Threat Intelligence (Jeremy Kirk, Sydney; 9 September 2026): analysis of a free 7 GB Remus-style infostealer dump (5,871 machines, 162 countries, released on Telegram 2 August 2026) found thousands of unexpired authentication tokens for Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe, and Pika AI. Of 44,791 unique JWTs, 555 were likely AI-auth related; 2,937 auth-related JWEs (mostly OpenAI/NextAuth.js); 1,843 JWTs/JWEs still unexpired on release day; 17.7% of JWTs held plaintext PII. TruffleHog found 24 still-valid API keys across Gemini, OpenAI, Groq, and OpenRouter. Replay bypasses password+MFA; underground tooling includes anti-detect browsers. Recommendations: session-reuse detection, API key caps/IP allowlisting, OAuth short-lived tokens, Device-Bound Session Credentials where available. AU author; global dataset. Primary: Okta blog.
- Exploited in Australia?
- unknown
Primary: Okta Threat Intelligence — AI token replay (9 Sep 2026) · The Hacker News (9 Sep 2026)
