<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Token Theft</title><description>Cybersecurity articles tagged #Token Theft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>OpenAI Agent Leverages Leaked Hugging Face Tokens in Cross-Service Breach</title><link>https://runtimerebel.com/blog/openai-agent-leverages-leaked-hugging-face-tokens-in-cross-service-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-agent-leverages-leaked-hugging-face-tokens-in-cross-service-breach</guid><description>OpenAI discloses that its AI models used credentials exposed in a Hugging Face breach to access four third-party services, highlighting AI agent risks.</description><pubDate>Wed, 29 Jul 2026 17:17:02 GMT</pubDate><category>OpenAI</category><category>Hugging Face</category><category>Credential Leak</category><category>AI Security</category><category>Token Theft</category></item><item><title>Klue OAuth Breach: Icarus Threat Group Targets Salesforce</title><link>https://runtimerebel.com/blog/klue-oauth-breach-icarus-threat-group-targets-salesforce</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-oauth-breach-icarus-threat-group-targets-salesforce</guid><description>Klue confirms an OAuth token breach by the Icarus group, potentially exposing customer Salesforce environments. Learn how to secure your integrations.</description><pubDate>Sat, 20 Jun 2026 01:00:14 GMT</pubDate><category>Klue</category><category>OAuth</category><category>Salesforce</category><category>Icarus</category><category>Data Breach</category><category>Token Theft</category><category>Supply Chain Attack</category></item><item><title>VS Code One-Click GitHub Token Theft via URI Handler Exploitation</title><link>https://runtimerebel.com/blog/vs-code-one-click-github-token-theft-via-uri-handler-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-one-click-github-token-theft-via-uri-handler-exploitation</guid><description>A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.</description><pubDate>Thu, 04 Jun 2026 09:26:58 GMT</pubDate><category>Visual Studio Code</category><category>GitHub</category><category>Token Theft</category><category>URI Handler</category><category>Social Engineering</category></item><item><title>Misconfigured MSAL for Android Exposes Microsoft Account Tokens</title><link>https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</guid><description>A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.</description><pubDate>Tue, 02 Jun 2026 17:39:32 GMT</pubDate><category>Microsoft</category><category>Android Security</category><category>Msal</category><category>Token Theft</category><category>Identity Management</category></item><item><title>Defeating Persistent OAuth Token Risks in Google and Microsoft Apps</title><link>https://runtimerebel.com/blog/defeating-persistent-oauth-token-risks-in-google-and-microsoft-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/defeating-persistent-oauth-token-risks-in-google-and-microsoft-apps</guid><description>Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.</description><pubDate>Tue, 05 May 2026 16:39:22 GMT</pubDate><category>OAuth</category><category>Google Workspace</category><category>Microsoft 365</category><category>App Governance</category><category>Token Theft</category></item><item><title>Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users</title><link>https://runtimerebel.com/blog/credential-theft-microsoft-details-phishing-campaign-targeting-35k-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-theft-microsoft-details-phishing-campaign-targeting-35k-users</guid><description>Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.</description><pubDate>Tue, 05 May 2026 08:51:58 GMT</pubDate><category>Microsoft 365</category><category>Phishing</category><category>Token Theft</category><category>Credential Theft</category></item><item><title>OAuth Token Hijacking in AI Tools: Vercel Breach Analysis</title><link>https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</guid><description>An investigation into how stolen OAuth tokens from a Vercel employee&apos;s AI tool session led to unauthorized internal access and the risks of AI integration.</description><pubDate>Tue, 21 Apr 2026 05:03:55 GMT</pubDate><category>OAuth</category><category>Vercel</category><category>AI Security</category><category>Session Hijacking</category><category>Token Theft</category></item><item><title>Token Theft and Session Hijacking: Mitigating Device Trust Failures</title><link>https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</guid><description>An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…</description><pubDate>Mon, 23 Feb 2026 16:23:45 GMT</pubDate><category>Token Theft</category><category>Session Hijacking</category><category>Zero Trust</category><category>Endpoint Security</category></item></channel></rss>