정보 탈취 로그로 AI 토큰이 유출되어 MFA를 우회할 수 있는 위험이 증가하고 있다.
사이버 범죄자들이 정보 탈취 로그를 통해 인공지능 사용자 계정을 탈취하고 있습니다. 이들은 Google, Anthropic 등의 모델 제공업체 도구에 무단 액세스할 수 있는 '도난된 키'를 생성하고 있습니다. Lumma Stealer나 Vidar와 같은 정보 탈취기는 손상된 시스템에서 자격 증명, 세션 토큰, API 키 등을 수집할 수 있습니다.
Info-stealer logs are leaking AI tokens that can bypass MFA, increasing security risks.
Cybercriminals are hijacking AI user accounts via information stealer logs, creating 'stolen keys' that allow unauthorized access to tools from providers like Google and Anthropic. Info stealers, such as Lumma Stealer and Vidar, are capable of harvesting various data from compromised systems, including credentials, session tokens, and API keys. This significant security risk highlights the importance of protecting sensitive information.