Tag: credential theft
181 articles

DeepLoad Malware Poses Critical Threat with Advanced Evasion Tactics
A new and highly sophisticated malware threat, DeepLoad, has emerged with advanced evasion tactics that blur the lines between human psychology and digital security, putting sensitive information at risk. This powerful malware loader uses social engineering and AI-assisted obfuscation to evade detection, making it a critical threat that demands immediate attention.

Phishing Surges with Alarming New Tactics This Tax Season
Tax season is here, and with it, a surge in phishing attacks that could leave you vulnerable to identity theft and financial loss. Don't wait until it's too late - stay ahead of cybercriminals and protect your sensitive info from their alarming new tactics.

Shai-Hulud-Like Worm: Exclusive Critical npm Threat
What if the npm packages you trust were actually malicious? Researchers uncovered a Shai‑Hulud‑like, self‑replicating worm hidden in npm packages that runs at install time to steal developer and CI secrets, hijack AI tooling, and spread across the registry.

Chrome extensions Exclusive: Malicious AI steal API keys
Before you add that shiny AI assistant to Chrome, pause: researchers found 30+ extensions secretly siphoning API keys, emails and other sensitive data from hundreds of thousands of users. What promised convenience turned into a fast track for credential theft and account takeover.

pkr_mtsi Reveals Stunning, Dangerous Payloads
Think of pkr_mtsi as a benign-looking packer that attackers have turned into a slick delivery system—using malvertising and social lures to slip credential stealers, covert coin‑miners, and backdoors onto victims’ PCs. By running loaders in memory and staging payloads, it keeps infections quiet while letting criminals squeeze ongoing profit from compromised machines.

n8n flaw Exclusive: Critical bug lets attackers run servers
A critical unauthenticated RCE in n8n lets attackers run arbitrary code and seize control of servers. If you run n8n, patch now to protect your workflows, credentials, and sensitive data across potentially 100,000 installs.

LinkedIn Job Scams: Exclusive Tips to Avoid Costly Fraud
When a recruiter asks for your LinkedIn password, it’s not hiring—it’s a trap. Learn simple, practical ways to spot fake job offers, protect your credentials, and keep your career and accounts safe from sophisticated scammers.

630M Passwords Stolen: Stunning, Alarming Credential Cost
Some 630 million passwords have been leaked to criminal marketplaces — a stark reminder that passwords are no longer sacred. Now’s the moment to stop reusing credentials, enable MFA, and push for faster detection and smarter defenses.

After Email Hacking, Campus Faces Stunning Costly Breach
The University of Pennsylvania breach began with an Oct. 31 email hack that quickly escalated into a far costlier intrusion, leaving students and staff scrambling and officials grappling with steep financial and operational fallout. Its a stark reminder that a single compromised inbox can cascade into widespread harm for campuses everywhere.

Coupang Breach: Stunning Damage Hits 34M, Leaders React
Coupang breach jolted roughly 34 million customers after attackers used vishing and compromised vendor channels to steal—and then extort—sensitive data; here’s what went wrong and what customers and companies need to do next.

Russian Phishing Campaign: Exclusive ISO Stealer Threat
Exclusive: a Russian phishing campaign is circulating a stealthy ISO stealer — learn how it works and quick, practical steps to keep your data safe.

Lapsus$ Hunters Pose Dangerous, Exclusive Threat to Zendesk
Patchable missteps meet crowd‑powered coercion: Scattered Lapsus$ Hunters are resurfacing with new phishing domains and social‑engineering tricks aimed at support tools like Zendesk. Compromised help‑desk credentials can give attackers an exclusive backdoor into customer and corporate data—so small lapses can have big consequences.

London Councils Hit by Serious Exclusive Cyber Incidents
At least three London boroughs are battling a serious cyber incident that’s disrupted services and shown how ageing council IT can turn targeted attacks into city-wide crises. As teams scramble to contain the breach and keep vital functions running, this episode highlights a worrying UK trend: fewer incidents, but far greater damage.

Hackers Hijack Blender Assets: Exclusive StealC V2 Threat
Beware: malicious .blend files on popular asset marketplaces are silently deploying StealC V2 to steal credentials and tokens the moment you open them. Artists and studios should vet downloads, update tools, and treat free assets with caution.

Scam USPS Alerts: Exclusive Guide to Avoiding Costly Fraud
Think that text really came from the USPS? Modern phishing kits let crooks spin up convincing alerts and fake sites in minutes, turning routine delivery notices into money-stealing traps — this guide shows the clear red flags so you don’t get fooled.

Half of Ransomware Access: Exclusive Critical VPN Threat
Think your VPN keeps the bad guys out? Q3 data show compromised VPN credentials were the top initial access vector for ransomware, so it’s time to rethink perimeter defenses, identity hygiene, and incident response.

Google Files Lawsuit Against Lighthouse Kit Exclusive Blow
Google just went to court to take apart a sprawling smishing operation it says was run by 25 people tied to a Chinese cyber collective, accusing them of using deceptive texts to spread malware, recruit botnets, and sell stolen credentials. The company is seeking asset freezes and third-party cooperation — pairing legal muscle with technical takedowns to short-circuit the infrastructure behind SMS-based attacks.

Qilin Ransomware Exclusive: Damaging Surge Hits Small Firms
Qilin ransomware has evolved into a commercialized threat that turns simple security lapses—phishing, weak credentials or exposed remote access—into crippling double‑extortion attacks on small and mid-sized firms. With affiliates and leak sites amplifying its reach, now’s the time for SMBs to shore up the basics before opportunistic criminals profit.

Cybercriminals Targeting Payroll Sites Exclusive Warning
Imagine your paycheck landing in a strangers account—criminals are targeting payroll systems with social‑engineering scams that hijack credentials and reroute direct deposits. Simple fixes like multi‑factor authentication, tighter admin privileges, and out‑of‑band approvals can stop them before paychecks disappear.

Identity Exclusive: Cloud’s Worst Security Risk
Identity is the single biggest cloud security risk — but with smarter access controls and a few practical fixes, you can shut down the weakest link fast.

Google Removes 3,000 Malicious YouTube Videos—Stunning Win
Google removed roughly 3,000 malicious YouTube videos, dismantling a “ghost network” that lured users into downloading password‑stealing malware disguised as cheats and cracked software. It’s a practical win for online safety—fewer traps and fewer stolen credentials.

Google Bold Crackdown Removes 3,000 Malicious YouTube Clips
Google just wiped about 3,000 seemingly harmless YouTube tutorials after researchers exposed the “Ghost Network” that used those clips to spread password-stealing malware. If a video pushes cracked software or cheats, pause and double-check the source—your passwords and payment info are worth the extra caution.

Google Nukes 3,000 YouTube Videos in Stunning Malware Raid
Think that handy YouTube tutorial is safe? Ghost Network hid password‑stealing malware inside thousands of fake how‑tos and cracked‑software walkthroughs — Google pulled roughly 3,000 videos after researchers traced the campaign funneling victims to trojanized installers.

Google Nukes 3,000 Malware YouTube Videos in Stunning Sweep
Google just nuked 3,000 malware YouTube videos that used believable tutorials and “cracked” installers to sneak in a credential‑stealing payload—learn the red flags so curiosity doesn’t cost you your accounts.