Tag

#credential theft

63 stories taggedcredential theft · page 3 of 5.

Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign

A hacking group tied to China is breaking into Roundcube webmail systems at physics and engineering faculties across US and Canadian universities to steal login details.

3 min read
Full-frame overhead view of a laptop screen showing a blurred generic calendar-booking interface with a small login popup window in the centre, warm office ligh
Threat Intelligence

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins

A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

3 min read
A digital representation of a firewall with a menacing shadow of a lock looming over it, symbolizing the threat of ransomware
Ransomware

FortiBleed's Credential Theft Linked to Ransomware Gangs

Researchers reveal FortiBleed's connections to ransomware groups, posing greater risks for affected organizations.

2 min read
Full-frame edge-to-edge photoreal image of a dimly lit server rack in a corporate data centre, one network firewall appliance glowing red among rows of blue sta
Ransomware

FortiBleed: 11,000 Fortinet Firewalls Still Compromised, Now Tied to INC and Lynx Ransomware

Researchers say the same crew that hoarded credentials from hundreds of thousands of Fortinet firewalls has been sitting inside the negotiation panels of two major ransomware gangs.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Ransomware

FortiBleed: Stolen FortiGate Credentials Now Fueling INC and Lynx Ransomware Attacks

Credentials harvested from hundreds of thousands of compromised FortiGate devices are feeding active ransomware operations — and defenders who haven't rotated credentials post-patch are still exposed.

3 min read
AI Security

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves

Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

2 min read
Ransomware

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews

A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

2 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

3 min read
Threat Intelligence

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft

The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

3 min read
Threat Intelligence

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure

Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator — and was staging for disruption, not just espionage.

2 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective — and that's the problem.

2 min read
Threat Intelligence

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC

Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

2 min read
Threat Intelligence

The 'Search-as-a-Service' Economy Built on Stolen Credentials

Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

2 min read
Threat Intelligence

ShinyHunters Doesn't Need Malware. That's the Point.

The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

2 min read
© 2026 Threat Vectr