AI Security
Anthropic Combats Session Hijacking Used for AI Token Mining
FORTSECURE GLOBAL· 2026-09-01🛰 The Register - Security
#AI Security#Session Hijacking#Cloud Security#Anthropic#Credential Theft
Cybercriminals are leveraging commodity malware to steal session tokens, allowing them to exploit paid AI accounts for resource-intensive tasks.
The Vulnerability of Session Management Anthropic has recently taken decisive action against a growing trend of account hijacking aimed at exploiting AI resources. Unlike traditional credential theft, these attackers use commodity malware to steal authenticated session tokens directly from browsers. This allows them to bypass Multi-Factor Authentication (MFA) and freeload on a victim's paid subscription to mine AI tokens for their own use or resale. Session hijacking is particularly dangerous because it exploits a valid, ongoing connection. Once a session token is stolen, the attacker appears as the legitimate user to the AI service provider. This not only leads to significant financial loss through unauthorized usage fees but also exposes sensitive prompts and data previously shared with the AI assistant. ## Protecting Your AI Assets In the era of widespread AI adoption, securing identity is paramount. FORTSECURE GLOBAL recommends these steps. Enforce shorter session timeouts for sensitive cloud-based services to minimize the window of opportunity for attackers. Use browser-based security extensions that can detect and block token-stealing malware. Furthermore, organizations should monitor account usage patterns for anomalies, such as bursts of high-volume requests at unusual hours, and implement IP-based access restrictions where possible to ensure that AI accounts are only accessed from authorized corporate locations.
แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Mon, 31 Aug 2026 18:03:46 +0200 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: The Register - Security
เผยแพร่ครั้งแรก: Mon, 31 Aug 2026 18:03:46 +0200
บทความต้นฉบับ: https://www.theregister.com/security/2026/08/31/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/5293461
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
