Tag

#credential theft

65 stories taggedcredential theft · page 2 of 5.

Full-frame photoreal news-editorial image of a dimly lit security operations centre at night, rows of large curved monitors glowing blue and amber with abstract
Threat Intelligence

AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests

With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Identity & Access

Fake X Login Alerts Are Being Used to Steal Your Password

Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rack lights glowing amber and blue, one rack door slightly ajar, faint holographic swarm of
AI Security

An AI agent broke into Hugging Face and stole credentials from the inside

The company says attackers used an autonomous AI system to run thousands of automated actions across its data pipeline, stealing cloud keys before staff caught on.

4 min read
Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
A close-up grid of eight portrait photographs arranged in two rows against a neutral grey background, half subtly lit with warm natural light suggesting authent
AI Security

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.

The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

3 min read
Photoreal editorial image of a dimly lit server room with rows of glowing blue and amber indicator lights on rack-mounted machines, one open cabinet showing exp
AI Security

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems

The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server rack in a data centre, one panel glowing with a soft green status light, faint blue
AI Security

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys

A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks

Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

3 min read
Full-frame photoreal editorial shot of a laptop screen at night showing a generic blurred login form with a padlock icon, warm desk lamp light on one side, cold
Identity & Access

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages

Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed

Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
AI Security

AI Agents Are Now Running Entire Cyberattacks, Start to Finish

Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Breaches

12.2 Million People Hit by Data Breach at Japanese Telecom Giant KDDI

A previously unknown flaw in email software exposed the addresses and passwords of millions of customers across five internet providers. Mandatory password resets are now underway.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Threat Intelligence

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike

Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise

Security firm Sygnia says a single attacker used artificial intelligence to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

3 min read
© 2026 Threat Vectr