Tag

#credential theft

68 stories taggedcredential theft · page 2 of 5.

A corporate network map with AI-driven attack pathways spreading rapidly through nodes in real-time, system compromises represented as cascading failures compre
Ransomware

AI-Assisted Ransomware Gang Tore Through a Corporate Network in Under 10 Hours

Unit 42 researchers watched attackers use AI agents to do in a single working day what normally takes criminal crews two weeks. The case is a signal, not an outlier.

4 min read
A hacker's workstation with multiple displays showing attack logs, credential theft timelines, and server breach patterns mapped across a digital interface, red
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow

A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

3 min read
Developer workspace with code repository access open on screens, API credentials visible in terminal windows, financial dashboards showing depleted cloud servic
Breaches

Attackers Drain $600,000 in AI Credits After Stealing METR API Key

The AI safety non-profit says intruders got into a staff laptop and a code repository, but no sensitive research data was taken.

3 min read
A banking website login screen displayed on a computer monitor with warning alerts visible, alongside banking documents and a mobile phone on a desk
Threat Intelligence

Three Banking Trojans Are Quietly Draining Accounts Across Two Continents

Manic, Grandoreiro, and ToxicPanda 2.0 are targeting bank customers in Latin America and Europe. Here is what each one does and what ordinary people should watch for.

3 min read
A computer monitor displaying a convincing Windows lock screen with an error message, while Microsoft Teams is visible in the background with a suspicious messa
Threat Intelligence

SynkLoader: The Fake IT Help Desk Trick Hiding Behind a Phony Windows Lock Screen

Attackers posing as internal IT are pushing a new modular malware through Microsoft Teams, complete with a convincing fake login prompt built to steal Windows passwords.

4 min read
A smartphone login screen showing multiple authentication methods and security badges, with a shadow figure's fingerprint attempting access in the background
Identity & Access

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets

A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

3 min read
A web browser window with a password manager extension visible in the toolbar, its icon displaying a warning indicator while credential fields are shown being a
Vulnerabilities

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored

A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

4 min read
A laptop screen showing a realistic job interview video call interface overlaid with a login pop-up window asking for Google credentials, with a job seeker's ha
Identity & Access

Fake Job Interviews Are Stealing Google and Facebook Logins

A phishing operation called RecruitTrap uses realistic pop-up windows to grab passwords and one-time codes from job seekers.

4 min read
Cybersecurity incident timeline chart on a large monitor showing the LiteLLM package compromise alongside the separate Trivy scanner vulnerability, with data da
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
A MacBook Pro on a desk with suspicious activity indicators on the screen, password manager notifications and browser tabs visible, representing credential thef
Threat Intelligence

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions

A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it's written in a programming language that makes it harder for security tools to catch.

3 min read
A computer screen displaying lines of code and network diagrams in the dark, with cascading error messages and system alerts visible, suggesting automated intru
Threat Intelligence

AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems

Researchers say a cluster of AI programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

4 min read
A web browser window displaying a convincing CCleaner download page clone, with system notification alerts appearing in the background suggesting malicious acti
Threat Intelligence

Fake CCleaner site turns Chrome into a spying and password-theft tool

Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

4 min read
A large dataset visualization showing 434,000 files being extracted from servers, PyPI package registry interface visible, stolen data flowing across network pa
Threat Intelligence

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations

CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

3 min read
A developer's workstation screen showing lines of code being examined under a magnifying glass, with warning symbols floating in the digital space around it, re
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
Multiple fake login pages loading rapidly across browser tabs, with blocklist databases shown as outdated in the taskbar
Threat Intelligence

Why Blocklists Can't Keep Up With AI-Built Phishing Sites

Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

4 min read
© 2026 Threat Vectr