Skip to main content
IAMRoadmapIAMRoadmap
INDUSTRY TRENDS

IAM Week in Review: Oct 5 – Oct 11, 2026

The identity and access management stories that mattered in the week of Oct 5 – Oct 11, 2026: Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes; Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes; FBI Warns FortiBleed Remains Active After Amassing 86,644 For

7 min readOctober 7, 2026IAM Roadmap Team

Key Insight

The identity and access management stories that mattered in the week of Oct 5 – Oct 11, 2026: Fake ChatGPT, Gemini, and Claude Ad Portals Capture Cred...

Key Takeaways

The current identity landscape is facing a dual threat from sophisticated Adversary-in-the-Middle (AitM) phishing and critical vulnerabilities in edge infrastructure. Attackers are successfully bypassing legacy multi-factor authentication (MFA) by intercepting session tokens in real-time, specifically targeting high-value roles in the artificial intelligence (AI) sector.

Security teams must prioritize the transition to phishing-resistant credentials, such as FIDO2 security keys, and implement rigorous secret scanning to manage the expanding credential layer. Maintaining visibility over non-human identities and AI agent permissions is now a critical requirement for enterprise risk management.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Threat actors are deploying sophisticated phishing platforms that impersonate advertising products for major AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. These fraudulent portals claim to offer services such as campaign optimization, spend audits, and business-account connections to lure advertising account managers.

According to researchers, these sites utilize browser-in-browser (BiB) techniques to create a deceptive overlay that mirrors legitimate login prompts. This allows attackers to capture both primary credentials and multi-factor authentication (MFA) codes as they are entered by the user. Read more at The Hacker News and Bleeping Computer.

IMPORTANT

Traditional push-based or SMS-based MFA is no longer sufficient to stop modern AitM attacks. These methods do not verify the origin of the authentication request, allowing attackers to proxy the session token to their own infrastructure.

What To Do: Organizations should implement FIDO2/WebAuthn standards, which provide hardware-backed attestation and origin binding. This ensures that the authentication ceremony only succeeds if the user is on the legitimate, registered domain of the service provider.

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) have issued a joint warning regarding the "FortiBleed" campaign. This persistent threat targets internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways to harvest administrative and user credentials.

The campaign has successfully collected 86,644 credentials by exploiting reused or leaked data and the presence of legacy SHA-256 password storage (FBI/USSS 2026). These legacy storage mechanisms are more susceptible to offline cracking and credential stuffing attacks compared to modern hashing algorithms. Read more at The Hacker News.

WARNING

Edge devices are often the weakest link in the identity chain because they sit outside the primary identity provider's (IdP) direct control. If these devices use local databases for authentication, they may lack the modern security controls found in centralized IAM systems.

What To Do: Audit all Fortinet appliances for legacy password storage configurations and transition to external authentication via SAML or OIDC. This allows the organization to apply centralized Conditional Access policies and modern MFA to VPN and firewall access.

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

The China-nexus threat group TA419 is conducting targeted espionage against AI policy experts at U.S. think tanks, universities, and legal organizations. The attackers impersonate prominent economists, policymakers, and even employees from Anthropic to gain the trust of their targets.

These campaigns utilize Microsoft-themed AitM phishing kits to bypass standard authentication prompts. By capturing the session cookie during the login process, the attackers can maintain persistent access to the victim's productivity suite without needing to re-authenticate or know the password. Read more at The Hacker News.

TIP

Use "Continuous Access Evaluation" (CAE) to revoke sessions in real-time when a change in location or device compliance is detected. This limits the lifespan and utility of a stolen session cookie.

What To Do: Deploy device-based Conditional Access policies that require a managed, compliant device for all logins. This prevents attackers from using stolen cookies on unmanaged machines outside the corporate environment.

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released critical hotfixes for four vulnerabilities in its SMA1000 series appliances, which provide remote access to corporate networks. The most severe flaw is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability, rated 10.0 on the CVSS scale.

This flaw allows an attacker without a valid login to send requests through the appliance and reach internal functions or services. While SonicWall reports no evidence of active exploitation (SonicWall 2026), the severity of the flaw makes it a primary target for automated scanning. Read more at The Hacker News.

What To Do: Administrators should apply the vendor-provided hotfixes immediately. Additionally, restrict administrative access to the appliance to a dedicated management VLAN or an internal IP allowlist to prevent unauthenticated external access to management interfaces.

The Credential Layer Is Expanding Faster Than Security Teams Can See It

The "credential layer" represents the sum of all human, system, and AI identities used to connect modern enterprise services. This layer is expanding rapidly due to the proliferation of microservices, CI/CD pipelines, and automated AI agents.

Managing this expansion requires a three-pillar approach: Detect, Remediate, and Prevent (GitGuardian 2026). Organizations often struggle with "credential sprawl," where secrets are hardcoded in source code or stored in unencrypted configuration files across the development lifecycle. Read more at The Hacker News.

NOTE

Non-human identities (NHIs) often have broader permissions and longer-lived credentials than human users, making them a high-value target for lateral movement.

What To Do: Implement automated secret scanning in version control systems and CI/CD pipelines to catch credentials before they reach production. Use a centralized vaulting solution to manage secrets and rotate them automatically to reduce the impact of a potential leak.

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has patched a high-severity memory overflow vulnerability (CVE-2026-88779) in NetScaler ADC and Gateway. This zero-day vulnerability, with a CVSS score of 8.7, has already been exploited in targeted attacks to disrupt SAML-based authentication deployments.

The flaw can lead to service instability or potential session manipulation, effectively preventing legitimate users from accessing applications. Because NetScaler often acts as the primary gateway for enterprise SSO, an outage here can halt business operations entirely. Read more at The Hacker News.

What To Do: Prioritize patching for all internet-facing NetScaler instances. Review your "break-glass" authentication procedures to ensure that administrators can still access critical infrastructure if the primary SAML gateway is offline.

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI has disrupted a coordinated distillation campaign designed to illicitly extract protected reasoning from its AI models. This activity, which began in July 2026, has been attributed to individuals associated with Moonshot AI, a Chinese AI company.

While this campaign focuses on intellectual property theft, it highlights the risks associated with AI agent identities. If an attacker can compromise the identity of an authorized AI agent, they can perform large-scale data extraction or model manipulation under the guise of legitimate automated activity. Read more at The Hacker News.

What To Do: Apply the Principle of Least Privilege (PoLP) to all API keys and service accounts used by AI integrations. Monitor for anomalous traffic patterns, such as high-frequency reasoning queries, that may indicate a distillation or extraction attempt.

Identity Flow Logic

graph TD A["User Request"] -->|"MFA Challenge"| B["Edge Gateway"] B -->|"Validate Token"| C["Identity Provider"] C -->|"Phishing Resistance Check"| D["Access Granted"] subgraph SECURITY_LAYER ["Identity Security"] E["FIDO2 Binding"] --> F["Session Binding"] end D -->|"Contextual Evaluation"| E

What To Watch

  • Phishing Resilience: Expect a rapid shift toward FIDO2 as the standard for sensitive access, as traditional MFA becomes increasingly trivial to bypass via AitM.
  • Infrastructure Hardening: With the surge in vulnerabilities targeting VPN and ADC appliances, expect increased scrutiny on the security of edge network components that serve as identity enforcement points.
  • Non-Human Identity: The focus on AI reasoning extraction will likely lead to stricter governance and logging requirements for machine-to-machine (M2M) communications and AI agent identities.
Trend Topics
IAM newsidentity security newsweek in reviewThe Hacker NewsBleeping Computer
All Articles