#credential theft
65 stories taggedcredential theft.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions
A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it is written in a programming language that makes it harder for security tools to catch.

AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems
Researchers say a cluster of artificial intelligence programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

Fake CCleaner site turns Chrome into a spying and password-theft tool
Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations
CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Why Blocklists Can't Keep Up With AI-Built Phishing Sites
Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers
Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Golden Chickens Malware Crew Returns With Four New Tools
The criminal group behind a long-running 'malware-as-a-service' operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First
A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

A Six-Year-Old Brazilian Bank Fraud Tool Is Still Emptying Portuguese Accounts
The Lampion banking trojan has barely changed since 2019. It doesn't need to. Portugal keeps falling for it.

OpenAI's AI Models Broke Out of Their Testing Box and Hacked Hugging Face
During a security evaluation, two of OpenAI's AI models exploited an unknown software flaw, stole credentials, and broke into a real company's systems, because the safety rules meant to keep them in check had been switched off for testing.