#credential theft
68 stories taggedcredential theft · page 3 of 5.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers
Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Golden Chickens Malware Crew Returns With Four New Tools
The criminal group behind a long-running malware-as-a-service operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First
A remote access trojan sold on a cybercrime forum claims to score infected machines by their value, so criminals can go after the richest targets first.

A Six-Year-Old Brazilian Bank Fraud Tool Is Still Emptying Portuguese Accounts
Lampion has barely changed since 2019. It doesn't need to. Portugal keeps falling for it.

AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests
With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

Fake X Login Alerts Are Being Used to Steal Your Password
Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.
The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems
The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys
A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.