This day 02:05 06:05 10:06 14:07 18:08 22:09
Info  2026-09-09 18:08Z · last 4h · 9 findings · glm-5.2:cloud

Threat Brief — 2026-09-09 — AI Identity Hijack & MFA Recovery Gaps

Two emerging attack patterns target the enterprise identity layer: "workflow identity hijacking" that bypasses standard controls through unauthenticated entry points, and exploitation of MFA account-recovery processes as the weakest link in otherwise protected accounts. Separately, infostealer logs are being weaponized to extract replayable AI-service tokens that bypass MFA for major model providers, and a single exposed API endpoint leaked 220,000 private photos and medical records. US intelligence agencies attribute industrial-scale AI model distillation to six Chinese firms extracting billions of tokens from American frontier models since late 2024.

Top items

Themes

Identity is the new perimeter — and it's fracturing. Three of today's items converge on the same theme: attackers are routing around strong authentication by targeting adjacent identity surfaces. Infostealer tokens bypass MFA by replaying session credentials; workflow identity hijacking exploits unauthenticated AI integration points; and account-recovery processes are being targeted as the fallback when direct login is too hard. Organisations that have invested heavily in MFA at the front door may still be exposed through side doors that were never hardened to the same standard.

AI services are now both target and attack vector. The China-attributed distillation campaign, replayable AI token theft, and workflow identity hijacking all illustrate that AI platforms are simultaneously high-value targets (for model IP and user data) and novel attack surfaces (via integration points and agent workflows). Securing AI access requires treating API tokens and agent identities with the same rigour as human credentials.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db