Business news

Defending Non-Human Identities: Why Machine Credentials Demand a New Security Playbook

Modern cyberattacks no longer rely solely on stolen passwords and hijacked session cookies. As engineering workflows migrate to automated pipelines and cloud platforms, infostealer malware targets high-value machine credentials—including API keys, cloud tokens, and AI platform secrets. When these credentials leak, attackers bypass conventional perimeter controls and gain immediate, programmatic access to core infrastructure. Traditional internal scanners catch hardcoded secrets in code repositories, but they offer zero visibility once malware extracts active tokens directly from an endpoint.

To tackle this blind spot, Ran Geva, Founder and CEO of Webz.io and a leader behind Lunar Cyber, is reshaping how organizations respond to credential theft. By coupling Webz.io’s extensive data collection infrastructure with specialized threat intelligence, Lunar Cyber delivers external visibility into tokens that have already been compromised. In this executive Q&A, Geva discusses the operational shift toward monitoring machine identities, the limitations of conventional defenses, and how security teams can neutralize token exposure before attackers weaponize access.

Q: Infostealer malware has historically targeted passwords and session cookies. Why have threat actors shifted their focus toward machine credentials like API keys and developer tokens?

Ran Geva: Attackers follow access and money. A developer’s machine can hold tokens and secrets for cloud infrastructure, private code repositories, payment services, and AI platforms. Depending on its permissions, a single stolen key can give an attacker access to systems that would otherwise require several steps to compromise.

These keys are also scattered across configuration files, command histories, and local projects. Infostealers can collect them through broad file theft, even when the malware wasn’t specifically looking for that service. Lunar’s research.

What makes this dangerous is that API access often operates independently of a person’s login. Resetting the employee’s password or requiring MFA may leave a stolen API key working. That gap needs to be part of every response to an infected developer machine.

Q: Many organizations already use repository secret scanning and secrets management tools. Where do those solutions stop, and where does endpoint-focused credential intelligence become necessary?

Ran Geva: Repository scanning detects secrets in the material it covers, including code and commit history. It’s valuable, and organizations should use it. But an access token can stay out of the repository and still be stolen from a local configuration file on a developer’s laptop. 

Secrets managers reduce exposure by controlling storage, access, and credential lifetimes. Once an authorized application retrieves a secret, though, its protection also depends on the environment where it’s used.

External credential intelligence addresses what happened after theft. It can identify a credential in collected infostealer data and connect it to the affected device and service. That gives the security team evidence of exposure to act on, alongside its internal controls.

Q: With the rapid adoption of AI tools, how are AI credentials changing the risk profile for engineering teams, and what makes these tokens uniquely attractive to attackers?

Ran Geva: AI keys and tokens give attackers a direct way to spend the victim’s money. A stolen key can let someone run model requests against the company’s account, consume its quota, or resell access. They can profit without first stealing a database or deploying ransomware. This kind of abuse is already documented as LLMjacking. 

For engineering teams, the concern grows as AI experiments become production services. A key created for a prototype needs a clear owner, restricted permissions, and a defined lifetime.

The risk also depends on what the key actually authorizes. Access to model inference, stored resources, and an agent’s connected systems are different permissions. Security teams need to establish that scope. For AI services, unusual usage and spending should also trigger a security investigation.

Q: You mentioned that once an endpoint is compromised, teams must find, validate, and rotate exposed credentials. What operational bottlenecks usually slow this incident response process down?

Ran Geva: Ownership and dependencies are major bottlenecks. Finding a key is only the beginning. Someone has to establish which account it belongs to, what it can access, and which applications depend on it. If nobody knows what will break when it’s revoked, the response slows down.

The stolen data creates another problem. Secrets can be buried in large collections of files, mixed with incomplete strings and old credentials. File paths, device details, and account information help investigators connect a finding to the right team. 

Validation helps prioritize, but an inconclusive check shouldn’t delay action on a confirmed exposure. Teams need a prepared process for revoking the old credential, deploying its replacement, containing the infected endpoint, and investigating possible misuse. Creating a new key while leaving the stolen one active doesn’t close the incident.

Q: How does Lunar Cyber leverage Webz.io’s underlying data collection infrastructure to identify compromised tokens before they lead to downstream breaches?

Ran Geva: Webz.io provides the collection infrastructure behind Lunar, including access to infostealer sources, underground forums, and breach-sharing channels. That gives us material from outside the customer’s environment to examine for stolen credentials.

We scan the collected logs for secret formats, extract the tokens and secrets, and identify the associated services. We connect findings to available evidence, including the original file path, device information, and accounts found on the compromised machine. Where supported, we check the credential against its issuing service and include the verification result and available account or permission details. 

That context helps a team identify the owner, prioritize the exposure, and revoke access. The goal is to shorten the time a stolen credential remains usable. Detection can’t guarantee an attacker hasn’t already used it, so investigating activity remains part of the response.

Q: As non-human identities continue to outnumber human users in modern enterprise environments, what fundamental changes must CISOs make to their credential-defense strategy over the coming year?

Ran Geva:  Every production machine identity should have an accountable owner, a defined purpose, and a documented way to remove its access. Security teams should know which applications depend on it before an incident forces them to find out.

Organizations should also reduce the credentials that can be stolen and reused. That means temporary credentials wherever supported, narrowly scoped permissions, and removal of unused keys. Those are established practices that need consistent implementation. 

Finally, the infostealer response playbook must cover machine credentials alongside passwords and sessions. Connect external exposure findings with internal inventories and service logs, and rehearse revocation with engineering teams. I would measure how quickly the organization can identify an exposed credential’s owner and disable its access. An alert only helps if someone can act on it.

Securing enterprise infrastructure requires security leaders to treat machine credentials with the same urgency as human access points. As infostealers evolve to siphon tokens and keys straight from developer workstations, relying exclusively on internal controls leaves organizations vulnerable to silent intrusions. Proactive visibility into compromised credentials outside the network perimeter enables incident response teams to rapidly validate exposure, revoke active tokens, and contain potential fallout before critical systems are breached.

Looking ahead, the rapid expansion of automated pipelines and AI-driven services will only accelerate the growth of non-human identities. Organizations that fail to monitor external exposures risk handing attackers persistent, privileged access to their most sensitive environments. By implementing continuous compromised-credential intelligence and streamlining rotation workflows, security leaders can stay ahead of infostealer campaigns and safeguard their technical infrastructure against automated exploitation.

To learn more, visit lunarcyber.com

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This