Hackers Don’t Need to Break Into the Cloud When They Can Steal the Keys
Wiz says Lumma, RedLine, and Vidar stealers are harvesting cloud, code, and AI credentials.
A Wiz report says infostealers infect employee or developer devices through phishing, deceptive downloads, or poisoned dependencies, then steal browser data, API keys, and active sessions trusted by cloud services. Lumma, RedLine, and Vidar accounted for 85.7 percent of detected incidents. AWS secrets represented 46 percent of compromised secrets, Google Cloud 13 percent, GitHub tokens about 10 percent, and AI platform secrets 5 percent. Stolen session tokens can impersonate an already authenticated user, so Wiz advises revoking sessions and rotating credentials from a clean device.