Skip to main content

Tag: credential theft

181 articles

Cluttered software development workspace with laptop and monitor displaying GitHub page.

Malicious Ruby Gems, Go Modules Exploit CI Pipelines for Credential Theft

Malicious actors are targeting developers and CI pipelines with fake Ruby Gems and Go Modules, masquerading as familiar libraries to steal credentials. The campaign, linked to the GitHub account BufferZoneCorp, poses a significant threat to software supply chains.

Analyst 207
Windows computer terminal on office desk with paperwork and pen in a government setting.

CISA Orders Federal Agencies to Patch Exploited Windows Flaw

Federal agencies are on high alert: a critical Windows vulnerability, CVE-2026-32202, must be patched by May 12 to prevent zero-click credential theft via malicious LNK files. CISA has ordered all Federal Civilian Executive Branch agencies to secure their Windows endpoints and servers within two weeks.

Analyst 207
Large, empty development environment with rows of code on sleek computer screens against a neutral background.

Checkmarx GitHub Data Leaked by LAPSUS$ Hackers

Checkmarx confirmed that hackers from the LAPSUS$ group breached its GitHub repository on March 23, 2026, and published stolen data on April 22, after a series of supply-chain and credential-theft events. The attackers used the access to publish malicious code to certain artifacts, compromising the integrity of Checkmarx's software development process.

Analyst 207
Cluttered developer workstation with laptop, monitors, and notes in a bright office setting.

Supply-Chain Attack Targets Security, Dev Tools with Credential Theft

Malicious hackers are exploiting the very tools developers rely on, including security scanners and password managers, to steal sensitive credentials and gain unauthorized access. This latest supply-chain attack has already hit major players like Checkmarx, compromising their GitHub repository and potentially putting customer data at risk.

Analyst 207
Developer workstation with laptop and terminal, surrounded by notes and coffee cups, with a blurred cityscape in the…

Malware Targets Developers with Worm-Like Npm Supply Chain Attack

Malware is targeting developers through a sneaky npm supply chain attack, executing malicious code the moment a package is installed, and harvesting sensitive data to spread across ecosystems. Over 6,700 weekly downloads of one affected package show just how widespread the threat could be.

Analyst 207
Helpdesk worker sits at cluttered desk, staring at computer screen with password reset page.

Password Resets Expose Vulnerability in Corporate Security

Did you know that password resets can cost companies a whopping $70 each, and with stolen credentials involved in nearly 45% of breaches, it's clear that corporate security is vulnerable to attack.

Analyst 207
Cluttered developer workstation with multiple monitors, laptop, and coding materials under bright fluorescent lighting.

npm Worm Targets Dev Environments, Exploits Supply Chain

A newly discovered npm malware attack has infected multiple packages, using sneaky tactics like install-time execution and credential theft to compromise developer environments and spread through the supply chain. This self-propagating malware strain appears to be targeting specialized developer workflows, putting a spotlight on vulnerabilities in the software development process.

Analyst 207
Broken lock on a door with scattered ID cards, passports, and a smartphone, with a subtle shadow of a person in the…

Stolen Credentials Empower Attackers in Identity-Based Breaches

While security teams obsess over complex threats, attackers often find it easier to simply walk in with stolen credentials - the quickest and most reliable way into networks. By focusing on sophisticated threats, we might be overlooking the front door, which is wide open with a copy of the keys in the wrong hands.

Analyst 207
Person in dark room with scattered papers and broken locks, surrounded by shadows with a laptop and smartphone displaying…

Adaptavist Group Breach Sparks Imposter Email Scams

When security breaches strike, even the most trusted names can be compromised - and The Adaptavist Group is the latest example, with hackers using stolen credentials to gain access and now sending fake emails that could put your data at risk.

Analyst 207
Shattered robot head with exposed circuitry amidst broken smartphone fragments in a dimly lit, abandoned server room.

Vercel Breach Exposes Customer Data Theft via AI Tool Compromise

A single compromised AI tool has led to a massive breach at Vercel, exposing customer data and raising serious questions about trust and security. An attacker exploited a third-party AI tool used by an employee to steal sensitive credentials and OAuth tokens, gaining access to multiple services and customer data.

Analyst 207
Raccoon in actor disguise types on keyboard amidst scattered papers with passwords.

Raccoon Actor Targets Help Desks in Password Breach Spree

When help desks, meant to be a trusted source of support, become the easiest target for attackers, what can we do to protect ourselves? A recent surge in breaches, including a password breach spree by a Raccoon-linked actor, has left technologists, policymakers, and everyday users scrambling for answers.

Analyst 207
Person sitting in dimly lit room with laptop and smartphone, faces obscured by shadows and fake login page.

North Korea Exploits Social Engineering to Target macOS Users

Beware of a sneaky new scam where North Korean hackers trick macOS users into handing over their credentials and cryptocurrency by posing as a fake Zoom update. They're using social engineering to get you to do the work for them, making it a low-cost but hard-to-stop threat.

Analyst 207
Dimly lit hospital room with laptop screen glowing amidst scattered medical files and broken equipment.

AgingFly Malware Targets Ukraine Govt, Hospitals in Data Heist

A newly discovered malware called AgingFly is targeting Ukraine's government and hospitals, stealing sensitive online identity keys and putting public services at risk. This fresh threat siphons authentication data from popular web browsers and messaging apps, sparking urgent concern.

Analyst 207
Person in hoodie sits at laptop with chatbot interface, surrounded by papers and shadowy figures, hinting at cyber threat.

GitHub AI Agents Exposed to Credential Theft via Prompt Injection

Security researchers have uncovered a shocking vulnerability in popular GitHub AI agents, demonstrating how a simple prompt injection technique can be exploited to steal sensitive credentials, leaving users alarmingly exposed. The findings highlight a disturbing lack of transparency from vendors, putting automation and service access at risk.

Analyst 207
Person in a mask sits in dimly lit room with laptop, surrounded by papers with code, with cityscape at dusk in background.

Impersonator Exploits Slack to Target Linux Developers

A clever impersonator tricked Linux developers on Slack by posing as a trusted official, leading them to click a link that seemed harmless but actually handed over their credentials and development environment. This sneaky attack used Google-hosted pages to disguise a bogus root certificate, catching developers off guard.

Analyst 207
Moss-covered stone sphere sits on worn wood, moss unraveling, with blurred figure of hooded person typing in background.

Marimo Flaw Exploited for Credential Theft in Active Attacks

A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

Analyst 207
Padlock secures cookie jar amidst shattered glass and crumbs, with eerie laptop glow in background.

Google Chrome Bolsters Defenses Against Session Cookie Theft

Google Chrome just got a major security boost with the introduction of Device Bound Session Credentials (DBSC) protection, designed to block info-stealing malware from harvesting session cookies and putting your online credentials at risk. This move is a key step in the ongoing cat-and-mouse game between defenders and cyber threats.

Analyst 207
APT28 Hijacks Routers to Steal Credentials via Malicious DNS Servers

APT28 Hijacks Routers to Steal Credentials via Malicious DNS Servers

Beware of invisible hands rerouting your online traffic: a state-linked Russian hacking group, APT28, has been hijacking routers to intercept credentials by manipulating DNS servers, putting your online security at risk. This stealthy tactic allows them to capture user authentication data, compromising your digital identity.

Analyst 207
Credential Theft Evolves, Outpaces Breach Monitoring Defenses

Credential Theft Evolves, Outpaces Breach Monitoring Defenses

Imagine the keys to your online kingdom being quietly copied and stolen before you even notice - that's the alarming reality of credential theft, where infostealers are harvesting sensitive info at scale, often bypassing traditional defenses. Simple breach monitoring just can't keep up with this modern threat.

Analyst 207
Hackers Exploit React2Shell in Widespread Credential Theft Drive

Hackers Exploit React2Shell in Widespread Credential Theft Drive

Hackers are on the prowl, exploiting the React2Shell flaw (CVE-2025-55182) to steal sensitive credentials from vulnerable Next.js applications on a massive scale. With a single vulnerability, they can wreak havoc - the question is, how many credentials will be compromised before a patch is applied?

Analyst 207
Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns

Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns

Meet Venom, a sneaky new phishing platform that's putting top executives in its crosshairs, threatening to drain their credentials and wreak havoc on corporate boardrooms. This automated threat is scaling up credential theft like never before, making it a high-risk concern for senior leaders and their organizations.

Analyst 207
Storm Infostealer Decrypts Credentials to Evade Detection

Storm Infostealer Decrypts Credentials to Evade Detection

Meet Storm, a sneaky new infostealer that's taking password theft to the next level by remotely decrypting stolen credentials, allowing hackers to slip past security defenses undetected. This game-changing tactic lets stolen passwords be used immediately, bypassing local security controls that would normally sound the alarm.

Analyst 207
Venom Stealer Platform Automates Data Theft with ClickFix Tactics

Venom Stealer Platform Automates Data Theft with ClickFix Tactics

Imagine a silent thief lurking in the shadows of your digital life, quietly siphoning off sensitive info - and now, cybercriminals can easily access this capability with Venom Stealer, a new malware-as-a-service tool that automates data theft with alarming ease. This menacing platform is poised to revolutionize cybercrime, making it simpler than ever for attackers to steal credentials, cookies, and cryptocurrency assets.

Analyst 207
Person sitting in dimly lit room surrounded by screens with a smartphone in center, and a ghostly figure lurking in shadows.

TikTok Phishing: Alarming AiTM Campaign Targets Business Accounts

Beware of a sneaky new phishing campaign targeting TikTok Business accounts, using clever AiTM tactics to steal login credentials. Don't get caught out - stay vigilant and protect your account from these cunning cyber threats!

Analyst 207