<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Tokens on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-tokens/</link><description>Recent content in Ai-Tokens on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 09 Sep 2026 15:05:56 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-tokens/index.xml" rel="self" type="application/rss+xml"/><item><title>Infostealer Logs Expose Replayable AI Tokens That Bypass MFA</title><link>https://curasec.metacog.co.kr/insights/2026-09-09-infostealer-logs-expose-replayable-ai-tokens-that-can-bypass/</link><pubDate>Wed, 09 Sep 2026 15:05:56 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-09-infostealer-logs-expose-replayable-ai-tokens-that-can-bypass/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Infostealers harvesting AI API keys and session tokens from developer machines and CI/CD environments is a real exposure vector; audit all AI service credentials (Google, Anthropic, etc.) in your pipelines, rotate long-lived API keys, and enforce short token TTLs where providers allow it.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Lumma and Vidar are well-established infostealer families with known detection signatures; build or tune endpoint detections for these stealers specifically to flag AI service token harvesting, and add a hunt for anomalous AI API calls originating from unusual geolocations or IPs in recent logs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> As enterprise AI tool adoption grows, stolen replayable tokens become a meaningful account-takeover vector that sidesteps MFA; use this quarter to inventory which AI platforms your org uses, establish an API key governance policy, and confirm vendor support for token revocation and audit logging.&lt;/li>
&lt;/ul></description></item></channel></rss>