Threat Briefing: September 11, 2026

Threat Briefing Cybersecurity

September 11, 2026

Threat Intel Update

Threat Intel Update

Cybercriminals are blending social engineering, identity abuse, and AI exploitation to compromise accounts. Enterprise impersonation scams, including fake IT calls and fraudulent M&A schemes, continue targeting credentials and financial transfers.

AI ecosystems face new risks: stolen session tokens bypassing MFA, black markets for premium AI access, and a ChatGPT prompt-injection flaw leaking connected-app data. Separately, DoppelCart’s 119,000+ fake shopping sites show fraud operations scaling fast.

Bottom line: stronger identity controls, tighter verification, and vigilance against social engineering are critical.

Cybersecurity News

  • AI Login Tokens Found Exposed in Massive Infostealer Leak – Okta found 1,843 valid JWTs and 24 active API keys for AI services (Gemini, OpenAI, Groq, OpenRouter) in a 7GB infostealer dump posted to Telegram. The data, pulled from 5,871 infected machines in 162 countries, also included tokens for Anthropic, Microsoft, Amazon, Cursor, and Character.ai. The Hacker News
  • ChatGPT Flaw Let Attackers Secretly Exfiltrate Gmail Data – Check Point showed a planted prompt could make ChatGPT quietly read a user’s Gmail and leak it to an attacker’s account via a shared internal Artifactory instance. OpenAI has taken the service offline; no user action needed. The Hacker News
  • DoppelCart Scam Network Runs 119,000 Fake Online Stores – Nebty uncovered DoppelCart, a fraud network running 119,000+ fake shop domains (105,000+ still live) impersonating 44,182 brands, the largest known fake-shop cluster by domain count. BleepingComputer
  • Attackers Pose as IT Staff to Hijack Microsoft 365 Accounts – Since May 2026, attackers have been calling/texting employees’ personal phones posing as IT staff, using AiTM phishing or device-code flows to steal M365 credentials, then registering their own MFA to maintain access and exfiltrate SharePoint, OneDrive, and Exchange data. Help Net Security
  • Fake M&A Deals Used to Con Employees Into Wiring Millions – The ‘Phantom Deal’ campaign impersonates executives and advisory firms to pressure employees into wiring large sums under cover of confidential M&A deals. Targets include Gen (Norton/Avast) and at least four other firms across PE, industrial finance, sales, mining, and energy. Dark Reading

Sign Up

To receive Threat Briefings by email.

Sign Up Now

Share

About the Author
CampusGuard Logo

CampusGuard Threat Intel Team