credential-theft
163 articles with this tag
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
INFO
HIGH
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
Human attacker uses AI agents to breach enterprise network in under 10 hours
Fake bank websites play dead to evade security scanners
New Agent Tesla Malware Variant Boosts Evasion Capabilities
New Android banking Trojan ToxicPanda 2.0 expands victim targeting
New macOS malware turns stolen browsers into attacker-controlled sessions
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Attackers exploit AI skills registry for credential theft
Trojanized AI skills gain 1.7M installs in agent-targeted attack
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
New North Korean campaign uses fake coding interviews to steal developer credentials
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
Fake TTF files deliver stealthy malware in global phishing campaign
Modular macOS Stealer Uses Kill Loops to Force Password Entry
MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials
OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Phishing Attacks Targeted Facebook Users With Fake Verification Offer
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
BTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices
Defence Impairment Olympics
'Djinn' Stealer Targets Cloud, AI Credentials
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Risky Business #843 -- Fortibleed is kinda awesome, actually
Underground services offer targeted credential searches from infostealer data
FortiBleed campaign used custom FortiGate sniffer to steal credentials
A Glimpse into the “Search Your Target” Market for Stolen Credentials
Threat Brief: Mitigating Large-Scale Credential Attacks
FortiBleed: 86,000 Fortinet Device Credentials Compromised
OnyxC2 stealer sold as a service targets over 210 applications
Aged-domain acquisition: The tradecraft phishing operators are using to bypass your mail filter’s reputation score
Threat actors are recruiting the people who hold cloud logins
Infostealers Turn Millions of Devices Into Credential Theft Machines
Microsoft investigates breach of open-source projects after malware injection
Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
Toshiba and Muji warn of fake login screens from polyfill.io
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Pink is the latest goon squad to use fake helpdesk calls to steal creds
Typosquatted npm packages used to steal cloud and CI/CD secrets
Supply Chain Attack Hits 32 Red Hat NPM Packages
Red Hat npm packages compromised in new Mini Shai-Hulud malware wave
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Russian hacker used AI to run fraud scheme on MAGA Telegram channel
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
Typosquatted npm packages used to steal cloud and CI/CD secrets
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain
Why some security fixes never reach your vulnerability dashboard
How Storm-2949 turned a compromised identity into a cloud-wide breach
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
1 in 8 employees have sold company logins or know someone who has
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
New PCPJack worm steals credentials, cleans TeamPCP infections
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
ClickFix Removes Your Background but Leaves the Malware
Supply chain attack against SAP npm packages facilitates credential theft
Why You Must Check Your Password Manager Immediately | THREAT WIRE
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
New npm supply-chain attack self-spreads to steal auth tokens
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
New VENOM phishing attacks steal senior executives' Microsoft logins
There are too many stories to cover! - Threat Wire
Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
Hackers exploit React2Shell in automated credential theft campaign
You Patched LiteLLM, But Do You Know Your AI Blast Radius?
New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
New DeepLoad Malware Dropped in ClickFix Attacks
TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials
Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Venom Stealer Raises Stakes With Continuous Credential Harvesting
TeamPCP Moves From OSS to AWS Environments
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad Malware Combines ClickFix With AI-Generated Code to Avoid Detection
Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
EmEditor Supply Chain Analysis: Why "Publisher Authorization" isn't the silver bullet we think it is
More Attackers Are Logging In, Not Breaking In
2025 Identity Threat Landscape Report: Inside the Infostealer Economy: Credential Threats in 2025
Threat Actor Targeting VPN Users in New Credential Theft Campaign