#credential theft
66 stories taggedcredential theft · page 4 of 5.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

12.2 Million People Hit by Data Breach at Japanese Telecom Giant KDDI
A previously unknown flaw in email software exposed the addresses and passwords of millions of customers across five internet providers. Mandatory password resets are now underway.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Incident-response firm Sygnia says a single attacker used AI to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets
A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign
A hacking group tied to China is exploiting a critical flaw in Roundcube webmail to steal login credentials from physics and engineering faculties at US and Canadian universities.

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins
A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews
A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers
Researchers at LayerX got six AI browsers and assistants, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, to exfiltrate user logins by framing the attack as a game.

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure
Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator and was staging for disruption, not just espionage.

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages
The self-propagating supply chain campaign tied to Miasma and Hades has spread again, abusing GitHub Actions workflows and now reaching Go modules.

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door
Not elite. Not cinematic. Just effective, and that's the problem.