#credential theft
68 stories taggedcredential theft.

Who Is Running Up Your AI Bill at 3am
Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

CLOSEDQUORUM Runs Its Own Attack Without Asking Anyone
Cisco Talos has identified what it calls the first fully autonomous command-and-control implant: malware that polls a panel of AI models to decide its next move and never checks back with its operator.

Attackers Are Logging In, Not Breaking In
AI has cut the time between a stolen password and a full-blown intrusion. The fix isn't another login screen, it's checking the device too.

Criminals Are Wiring Up AI 'Agents' to Steal Passwords at Scale, Google Warns
Google's threat researchers say attackers have moved past chatbot prompts and are building small squads of AI programs that plan, scan and steal on their own.

Phishing Pages Built Inside Your Browser: How Attackers Are Using Microsoft's Own Tools Against You
A new phishing technique assembles fake login pages directly inside the victim's browser, using legitimate Microsoft services so there is no suspicious website for security tools to find and block.

A Self-Destruct Button for Stolen API Keys
A new proposal wants any leaked API key automatically cancelled within sixty seconds of discovery. Here is why that matters, and why it is harder than it sounds.

2.47 Million Simulated Attacks Suggest We're Measuring the Wrong Things in Phishing Training
New research points out a gap between what most companies track (who clicked a fake link) and what actually matters (whether stolen passwords are being spotted and staff are reporting suspicious emails).

Malicious Twitch Extension Siphoned Login Tokens From 31,000 Viewers
A browser add-on marketed as a Twitch viewer tool quietly forwarded OAuth tokens to servers linked to a Russian bot-for-hire service.

Why knowing about a threat isn't the same as stopping it
Attackers are turning fresh leaks and new bug disclosures into working break-ins faster than most defenders can read the alert.

N0va phishing kit hunts logins across US and EU businesses
A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

JetBrains Says Attackers Broke Into Its Cadence Cloud Through an Unpatched TeamCity Server
Customers of the build service are being told to rotate every credential after criminals exploited a critical flaw in JetBrains' own software.

Hackers Exploit PaperCut Bugs to Steal Logins From Schools and Universities
Researchers say attackers are chaining two fresh flaws in the popular print management software to break into education networks across the US and Europe.

Attackers Hijacked Coder's Cloudflare Setup to Push Poisoned Terraform Modules
For 14 hours on August 31, some developers pulling from Coder's official registry got credential-stealing code instead of the real thing.

When an Employee's Password Shows Up in a Stealer Log, the Session Cookie Is the Real Problem
Infostealer malware grabs more than passwords. It grabs live logins, and that's what lets attackers walk past multi-factor prompts.