#token-theft
- News · Sep 9, 2026Okta found 1,843 unexpired AI session tokens sitting in a single infostealer dump
Okta analysed a 7GB infostealer dump from 5,871 machines and found 44,791 JWTs, 1,843 of them still unexpired on release day, plus 24 live API keys for Gemini, OpenAI, Groq and OpenRouter. Replaying them skips MFA entirely.
- News · Aug 13, 2026SharePoint JWT bypass went from proof of concept to exploitation in under 48 hours
Rapid7 published a working PoC for CVE-2026-55040 in mid-August. Exploitation telemetry spiked from one attempt to eight the following day, from eight IPs across five countries. Microsoft patched it in July.
- News · Jul 30, 2026OWAReaper keeps Exchange mailbox access after credential rotation and re-imaging
Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.
- News · Jul 23, 2026A Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Management servers, then use it with full administrative privileges. Check Point confirmed exploitation against a handful of customers.
- News · Jul 23, 2026A Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, that pulled 90 days of mail, browser-saved passwords, and two-factor recovery codes from an authenticated session.
- News · Jul 14, 2026A SharePoint JWT validation bug let unauthenticated attackers become any user, including admins
CVE-2026-55040 (CVSS 9.1) let a remote, unauthenticated attacker who knows a target's Active Directory SID or user principal name forge a valid session as that user in Microsoft SharePoint, no password or MFA involved at all.
- News · Jun 12, 2026Forged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining privileged technician access and bypassing MFA entirely. Arctic Wolf found it already being used to harvest credentials at scale.