DevOps / SRE / Platform · 31.08.2026, 14:17 UTC
Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | DevOps.com ↗ |
| Veröffentlicht | 31.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Bnei Brak, Israel, August 31st, 2026, CyberNewswire
New capability identifies, attributes and validates API keys, OAuth tokens and other machine credentials stolen from developer and employee endpoints Lunar Cyber today announced Token Exposure Monitoring, a new capability designed to identify, attribute and validate Non-Human Identities (NHI) and machine credentials inside infostealer logs, connect them to the affected organization, and determine which exposures require action. The rapid adoption of AI development tools, cloud platforms and automated infrastructure has put a new class of credentials on developer machines: API keys, OAuth tokens, personal access tokens, and other machine identities that provide direct access to valuable services. Security researchers have documented the theft and abuse of AI API credentials for attacks such as LLMjacking, where stolen keys are used to run expensive AI workloads through a victim’s account. Developer credentials can also provide access to source-code repositories, cloud infrastructure, SaaS platforms and corporate data. Lunar’s internal research found that modern infostealers actively collect the local files and application data where these credentials are frequently stored. Developers routinely authenticate to services such as AWS, GitHub, OpenAI, Anthropic, Slack, Okta and other cloud and development platforms from their workstations. Tokens can be stored in .env files, application configuration, CLI authentication files, shell history, browser data and local caches. Modern infostealers use file-grabber components to …