Token Theft

This tag tracks the emerging trend of session hijacking and credential-less attacks. Coverage includes the theft of OAuth tokens, API keys, developer certificates, and service account credentials — vectors that allow threat actors to bypass Multi-Factor Authentication (MFA) and gain persistent access to high-value environments.