ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
SOCRadar tied 5,434 infostealer records for AI tools to 1,500 corporate email addresses at 482 large enterprises. The report says those AI accounts belong under the same sign-on and session controls as a company's identity provider and code repositories.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+35
- Incentives85
- Confidence40
SOCRadar found captured ChatGPT sessions at 358 of the 482 companies whose AI accounts turned up in 90 days of infostealer logs. The firm ties the spread to shadow AI, with employees opening work-email accounts that IT never sees.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence45
Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.
Perspective Coverage
7 publishers
- Builder
- Builder 19%
- Operator
- Operator 72%
- Investor
- Investor 9%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
Check Point's deobfuscation of 23 compiled V8 bytecode samples shows JSCeal replaying stolen cookies inside the victim's own browser profile, then stuffing local credentials at any password prompt until it holds a fresh OAuth token.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives45
- Confidence63
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.
Reality
- Evidence55
- Adoption58
- Hype gap+12
- Incentives72
- Confidence56
Prophet Security investigated every alert in its customers' environments from May through July and found account takeovers turned on how the intruder arrived, with stolen passwords usually stopped and stolen sessions running for weeks.
Reality
- Evidence34
- Adoption30
- Hype gap+18
- Incentives82
- Confidence52
The figure comes from a vendor selling stealer-log monitoring, and no methodology is stated, but it lands on the awkward half of the response: containment on hardware the employer does not own, while the session cookie circulates.
Reality
- Evidence26
- Adoption
- Insufficient
- Hype gap+38
- Incentives88
- Confidence44
Vidar, LummaC2, RedLine and Atomic Stealer are pulling session material that authenticates without a login prompt, so the usual reset-and-enroll response can leave the intruder inside and spending the victim's paid usage.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+18
- Incentives44
- Confidence36
A passing MFA event proves someone controls an authenticator. SecurityWeek argues the processes that bind authenticators to people are where attackers work, and where assurance is never measured.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+12
- Incentives52
- Confidence38
CVE-2026-71368 affects F-RevoCRM 7.3.0 through 8.0.3 and runs attacker script inside the CRM's own origin. JVN rates it Medium; the published remedy is a version bump.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+8
- Incentives28
- Confidence55
Jamf Threat Labs describes a Rust stealer that copies Chromium profiles and drives them over Chrome DevTools Protocol. Password rotation does not revoke what it exports.
Reality
- Evidence64
- Adoption18
- Hype gap+14
- Incentives52
- Confidence58