Tag

#credential theft

68 stories taggedcredential theft · page 3 of 5.

A developer's code editor showing configuration files for an AI coding assistant, with hidden credential theft mechanisms embedded in what appears to be innocuo
AI Security

Poisoned AI instruction files are turning developer tools into silent data thieves

Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

5 min read
An email inbox with a fake Spotify payment failure notice prominently displayed, the user clicking through to a copycat login page, credit card input fields vis
Identity & Access

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers

Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

3 min read
A corporate office environment where a single login credential entry on a monitor suddenly grants access to multiple department folders and systems across the s
Identity & Access

SSO Is the New Skeleton Key. Criminals Have Noticed.

One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

4 min read
A hotel lobby Wi-Fi router mounted on a wall with digital visualization showing intercepted login credentials and passwords flowing from employee devices into a
Threat Intelligence

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details

Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

3 min read
A dark web marketplace interface displayed on multiple monitors, with malware builder tools and freshly packaged software packages arranged in an organized list
Threat Intelligence

Golden Chickens Malware Crew Returns With Four New Tools

The criminal group behind a long-running malware-as-a-service operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

4 min read
A cybercrime forum listing page for Dolphin X malware, displaying a scoring algorithm interface that ranks infected machines by financial value and net worth es
Threat Intelligence

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First

A remote access trojan sold on a cybercrime forum claims to score infected machines by their value, so criminals can go after the richest targets first.

4 min read
Portuguese bank statements and account records showing gradual unauthorized transfers, a computer screen displaying the same banking malware code that has remai
Threat Intelligence

A Six-Year-Old Brazilian Bank Fraud Tool Is Still Emptying Portuguese Accounts

Lampion has barely changed since 2019. It doesn't need to. Portugal keeps falling for it.

4 min read
Full-frame photoreal news-editorial image of a dimly lit security operations centre at night, rows of large curved monitors glowing blue and amber with abstract
Threat Intelligence

AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests

With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

4 min read
A computer user's inbox view displaying a convincing fake X login alert email among legitimate messages, with the email header and urgent language designed to t
Identity & Access

Fake X Login Alerts Are Being Used to Steal Your Password

Criminals are sending convincing 'new device login' emails to X users, hoping to harvest account credentials for follow-on fraud including crypto scams and phishing attacks.

3 min read
A computer screen showing a fake software update or security warning pop-up window overlaying a browser interface, with cursor hovering near a suspicious downlo
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
A machine learning platform dashboard with activity logs showing automated bot actions, system alerts, and forensic analysis tools running in real-time across m
AI Security

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.

The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

3 min read
Photoreal editorial image of a dimly lit server room with rows of glowing blue and amber indicator lights on rack-mounted machines, one open cabinet showing exp
AI Security

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems

The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server rack in a data centre, one panel glowing with a soft green status light, faint blue
AI Security

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys

A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks

Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

3 min read
Full-frame photoreal editorial shot of a laptop screen at night showing a generic blurred login form with a padlock icon, warm desk lamp light on one side, cold
Identity & Access

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages

Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

3 min read
© 2026 Threat Vectr