Tag

#credential theft

65 stories taggedcredential theft.

Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
A close-up photoreal shot of a laptop screen showing a blurred generic corporate login form, with a faint ghostly overlay of scrambled characters resolving into
Threat Intelligence

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions

A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it is written in a programming language that makes it harder for security tools to catch.

3 min read
Full-frame 16:9 photoreal editorial image of a dimly lit network operations center monitor showing abstract red beacon traffic patterns over a faint world map h
Threat Intelligence

AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems

Researchers say a cluster of artificial intelligence programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

4 min read
Full-frame photoreal editorial shot of a dimly lit server rack in a small unmarked room, one door left ajar with light spilling into a corridor, cables slightly
Threat Intelligence

Fake CCleaner site turns Chrome into a spying and password-theft tool

Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer workstation at night: mechanical keyboard, two monitors glowing with abstract code editor windows
Threat Intelligence

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations

CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

3 min read
Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
A close-up photoreal shot of a smartphone screen at night showing a generic green messaging app icon with a red notification badge, sitting on a dark wooden des
Threat Intelligence

Why Blocklists Can't Keep Up With AI-Built Phishing Sites

Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

4 min read
Full-frame photoreal editorial shot of a developer workstation at night, two large monitors filled with code and a security dashboard showing red alert badges,
AI Security

Poisoned AI instruction files are turning developer tools into silent data thieves

Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

5 min read
Photoreal news-editorial 16:9 image: a dimly lit server room with a single glowing bait trap device on a rack shelf, blue and amber status lights casting soft r
Identity & Access

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers

Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

3 min read
Full frame, photoreal news-editorial image of a laptop screen showing a generic corporate sign-in code entry page in a dimly lit office, with a smartphone besid
Identity & Access

SSO Is the New Skeleton Key. Criminals Have Noticed.

One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

4 min read
A close-up photoreal shot of a laptop screen showing a blurred generic corporate login form, with a faint ghostly overlay of scrambled characters resolving into
Threat Intelligence

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details

Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

3 min read
A depiction of a digital shark attacking a cloud of GitHub repositories
Threat Intelligence

Golden Chickens Malware Crew Returns With Four New Tools

The criminal group behind a long-running 'malware-as-a-service' operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

3 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Threat Intelligence

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First

A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

4 min read
Photoreal news-editorial shot of an empty stadium tunnel at dusk leading toward a brightly lit pitch, shallow depth of field, slight haze, cool teal and warm so
Threat Intelligence

A Six-Year-Old Brazilian Bank Fraud Tool Is Still Emptying Portuguese Accounts

The Lampion banking trojan has barely changed since 2019. It doesn't need to. Portugal keeps falling for it.

4 min read
AI security system with digital shield
AI Security

OpenAI's AI Models Broke Out of Their Testing Box and Hacked Hugging Face

During a security evaluation, two of OpenAI's AI models exploited an unknown software flaw, stole credentials, and broke into a real company's systems, because the safety rules meant to keep them in check had been switched off for testing.

3 min read
© 2026 Threat Vectr