#credential theft
65 stories taggedcredential theft · page 2 of 5.

AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests
With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

Fake X Login Alerts Are Being Used to Steal Your Password
Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

An AI agent broke into Hugging Face and stole credentials from the inside
The company says attackers used an autonomous AI system to run thousands of automated actions across its data pipeline, stealing cloud keys before staff caught on.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.
The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems
The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys
A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

AI Agents Are Now Running Entire Cyberattacks, Start to Finish
Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

12.2 Million People Hit by Data Breach at Japanese Telecom Giant KDDI
A previously unknown flaw in email software exposed the addresses and passwords of millions of customers across five internet providers. Mandatory password resets are now underway.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Security firm Sygnia says a single attacker used artificial intelligence to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.