credential-theft
145 articles with this tag
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
INFO
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
LOW
MEDIUM
MEDIUM
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
New North Korean campaign uses fake coding interviews to steal developer credentials
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
Fake TTF files deliver stealthy malware in global phishing campaign
Modular macOS Stealer Uses Kill Loops to Force Password Entry
MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials
OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Phishing Attacks Targeted Facebook Users With Fake Verification Offer
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
BTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices
Defence Impairment Olympics
'Djinn' Stealer Targets Cloud, AI Credentials
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Risky Business #843 -- Fortibleed is kinda awesome, actually
Underground services offer targeted credential searches from infostealer data
FortiBleed campaign used custom FortiGate sniffer to steal credentials
A Glimpse into the “Search Your Target” Market for Stolen Credentials
Threat Brief: Mitigating Large-Scale Credential Attacks
FortiBleed: 86,000 Fortinet Device Credentials Compromised
OnyxC2 stealer sold as a service targets over 210 applications
Aged-domain acquisition: The tradecraft phishing operators are using to bypass your mail filter’s reputation score
Threat actors are recruiting the people who hold cloud logins
Infostealers Turn Millions of Devices Into Credential Theft Machines
Microsoft investigates breach of open-source projects after malware injection
Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
Toshiba and Muji warn of fake login screens from polyfill.io
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Pink is the latest goon squad to use fake helpdesk calls to steal creds
Typosquatted npm packages used to steal cloud and CI/CD secrets
Supply Chain Attack Hits 32 Red Hat NPM Packages
Red Hat npm packages compromised in new Mini Shai-Hulud malware wave
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Russian hacker used AI to run fraud scheme on MAGA Telegram channel
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
Typosquatted npm packages used to steal cloud and CI/CD secrets
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain
Why some security fixes never reach your vulnerability dashboard
How Storm-2949 turned a compromised identity into a cloud-wide breach
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
1 in 8 employees have sold company logins or know someone who has
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
New PCPJack worm steals credentials, cleans TeamPCP infections
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
ClickFix Removes Your Background but Leaves the Malware
Supply chain attack against SAP npm packages facilitates credential theft
Why You Must Check Your Password Manager Immediately | THREAT WIRE
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
New npm supply-chain attack self-spreads to steal auth tokens
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
New VENOM phishing attacks steal senior executives' Microsoft logins
There are too many stories to cover! - Threat Wire
Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
Hackers exploit React2Shell in automated credential theft campaign
You Patched LiteLLM, But Do You Know Your AI Blast Radius?
New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
New DeepLoad Malware Dropped in ClickFix Attacks
TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials
Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Venom Stealer Raises Stakes With Continuous Credential Harvesting
TeamPCP Moves From OSS to AWS Environments
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad Malware Combines ClickFix With AI-Generated Code to Avoid Detection
Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
EmEditor Supply Chain Analysis: Why "Publisher Authorization" isn't the silver bullet we think it is
More Attackers Are Logging In, Not Breaking In
2025 Identity Threat Landscape Report: Inside the Infostealer Economy: Credential Threats in 2025
Threat Actor Targeting VPN Users in New Credential Theft Campaign
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Attackers use AiTM phishing kit, typosquatted domains to hijack AWS accounts
Fake LastPass support email threads try to steal vault passwords
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
Attacker gets into France's database listing all bank accounts, makes off with 1.2 million records
Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Data breach at French bank registry impacts 1.2 million accounts
Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets
How infostealers turn stolen credentials into real identities
Data on 1.2 million French bank accounts accessed in registry breach
Starkiller: New ‘Commercial-Grade’ Phishing Kit Bypasses MFA
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware
Job scam uses fake Google Forms site to harvest Google logins
Red Team | Looting Credentials from Modern Browsers
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
Poland arrests suspect linked to Phobos ransomware operation