Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

The $200 Popcorn Popper That Keeps Selling Out

October 1, 2026

Challenged Athletes Foundation Receives Rings of Gold Award from U.S. Olympic & Paralympic Committee

October 1, 2026

CleanChoice Energy Closes Approximately $166M in Project Financing and Tax Equity for Two Solar Projects

October 1, 2026

Fabletics Launches Fabletics Reserve Credit Card, Expanding Value and Loyalty Perks to Its More than 2.7 Million Members

October 1, 2026

First Merchants Bank CEO Mark Hardwick to retire at the end of 2026 and President Mike Stewart to become President and CEO

October 1, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials
Press Release

Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials

By News RoomAugust 31, 20264 Mins Read
Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials
Share
Facebook Twitter LinkedIn Pinterest Email

New capability identifies, attributes and validates API keys, OAuth tokens and other machine credentials stolen from developer and employee endpoints

BNEI BRAK, Israel, Aug. 31, 2026 (GLOBE NEWSWIRE) — Lunar Cyber today announced Token Exposure Monitoring, a new capability designed to identify, attribute and validate Non-Human Identities (NHI) and machine credentials inside infostealer logs, connect them to the affected organization, and determine which exposures require action.

The rapid adoption of AI development tools, cloud platforms and automated infrastructure has put a new class of credentials on developer machines: API keys, OAuth tokens, personal access tokens, and other machine identities that provide direct access to valuable services.

Security researchers have documented the theft and abuse of AI API credentials for attacks such as LLMjacking, where stolen keys are used to run expensive AI workloads through a victim’s account. Developer credentials can also provide access to source-code repositories, cloud infrastructure, SaaS platforms and corporate data. Lunar’s internal research found that modern infostealers actively collect the local files and application data where these credentials are frequently stored.

Developers routinely authenticate to services such as AWS, GitHub, OpenAI, Anthropic, Slack, Okta and other cloud and development platforms from their workstations. Tokens can be stored in .env files, application configuration, CLI authentication files, shell history, browser data and local caches. Modern infostealers use file-grabber components to collect exactly this type of endpoint data.

The growing use of AI development tools has expanded that exposure. Persistent API and OAuth credentials are increasingly used by AI APIs, command-line agents and developer environments, placing valuable machine credentials directly on endpoints targeted by malware.

“Developer tokens have become valuable credentials in their own right,” said Ran Geva, Founder and CEO of Webz.io. “A stolen AI key can be converted into compute almost immediately. A GitHub token can provide access to source code, and a cloud credential can open infrastructure. Security teams need visibility into these credentials at the moment they appear in an infostealer log, with enough context to understand who they belong to and what needs to be revoked.”

From an Anonymous Token to an Actionable Incident
Machine credentials create a different intelligence problem from traditional compromised passwords. An exposed corporate email address carries its organizational identity inside the credential. An API token generally appears as an opaque string with little indication of who owns it.

Lunar analyzes the surrounding infostealer data to solve that attribution problem. The platform associates exposed secrets with the compromised employee or organizational endpoint, identifies the service and credential type, and retains forensic evidence showing where the secret appeared.

For supported credentials, Lunar also checks their validation state. Analysts can distinguish between findings based on service, credential type, severity and validation status rather than treating every token-like string as an equivalent alert.

The Token Exposure interface provides access to the exposed credential, affected employee, service, internal file path, original log context, malware metadata and other information collected from the compromised endpoint. Analysts can search and filter exposures by service, employee, token type, breach date, severity and validation state.

Frame_2138882868_1788180020QoREqIaqVJ

Extending infostealer response beyond passwords and sessions
Most infostealer response processes center on cleaning the infected endpoint, resetting passwords and invalidating browser sessions. Machine credentials introduce another remediation path because API keys, PATs, OAuth tokens and other secrets frequently follow independent authentication lifecycles and can remain usable until they are rotated or revoked.

Tokens_Exposure_1788180005kaSYmOvBnS

Lunar Token Exposure Monitoring adds machine credential discovery to that response process. Once an affected token is identified, security teams can rotate or revoke the credential and investigate activity within the corresponding service.

The capability complements repository secret scanning, secrets management and NHI security products. Those systems help organizations control machine identities internally, while Lunar provides intelligence about credentials that have already been extracted from an endpoint by malware.

“Passwords and cookies have been at the center of infostealer response for years,” Geva said. “Developer tokens now deserve the same treatment. If the malware took the credential, the incident response process needs to find it, validate it and rotate it.”

Token Exposure Monitoring is available in Lunar Essential & PRO Tiers.

About Lunar Cyber
Lunar Cyber provides compromised-credential intelligence that helps organizations identify and investigate employee exposure originating from data breaches and infostealer malware. Lunar combines Webz.io’s collection infrastructure with forensic context, validation and response workflows to help security teams identify compromised access and respond quickly.

For more information, users can visit lunarcyber.com.

Contact

CEO
Ran Geva
Webz.io LTD
[email protected] 

Photos accompanying this announcement are available at:

https://www.globenewswire.com/NewsRoom/AttachmentNg/3679f292-ef5a-446b-9d85-622148a6664e

https://www.globenewswire.com/NewsRoom/AttachmentNg/0f2c10cf-105c-4d54-a064-5729ad4163f5

https://www.globenewswire.com/NewsRoom/AttachmentNg/e177d2dc-6589-40eb-a890-3c54793be63d

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

The $200 Popcorn Popper That Keeps Selling Out

Challenged Athletes Foundation Receives Rings of Gold Award from U.S. Olympic & Paralympic Committee

CleanChoice Energy Closes Approximately $166M in Project Financing and Tax Equity for Two Solar Projects

Fabletics Launches Fabletics Reserve Credit Card, Expanding Value and Loyalty Perks to Its More than 2.7 Million Members

First Merchants Bank CEO Mark Hardwick to retire at the end of 2026 and President Mike Stewart to become President and CEO

Primech Holdings (Nasdaq: PMEC) Unveils Primech Vision, Integrating a Multi-Robot Facility Fleet and Workforce on One Platform; Live Customer Demonstrations Begin October 2026

Easy Environmental Solutions Ships First Commercial EasyFEN™ System to Kenya

The News Forum Presents Aftershock: The World After October 7, 2023

BloFin returns as TOKEN2049 Singapore title sponsor, opens its “NEXT WHALE ERA” chapter with 3rd anniversary afterparty

Editors Picks

Challenged Athletes Foundation Receives Rings of Gold Award from U.S. Olympic & Paralympic Committee

October 1, 2026

CleanChoice Energy Closes Approximately $166M in Project Financing and Tax Equity for Two Solar Projects

October 1, 2026

Fabletics Launches Fabletics Reserve Credit Card, Expanding Value and Loyalty Perks to Its More than 2.7 Million Members

October 1, 2026

First Merchants Bank CEO Mark Hardwick to retire at the end of 2026 and President Mike Stewart to become President and CEO

October 1, 2026

Latest News

Primech Holdings (Nasdaq: PMEC) Unveils Primech Vision, Integrating a Multi-Robot Facility Fleet and Workforce on One Platform; Live Customer Demonstrations Begin October 2026

October 1, 2026

Police seek answers in crash that killed 2 elders, hurt 2 others on BC First Nation

October 1, 2026

An AI agent tried to hack Canadian government website, researchers say

October 1, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version