Tag

#credential theft

65 stories taggedcredential theft · page 4 of 5.

Threat Intelligence

The 'Search-as-a-Service' Economy Built on Stolen Credentials

Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

2 min read
Threat Intelligence

ShinyHunters Doesn't Need Malware. That's the Point.

The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

2 min read
Vulnerabilities

Gravity SMTP Flaw Under Active Exploitation, Leaks API Keys and OAuth Tokens

CVE-2026-4020 lets unauthenticated attackers pull secrets from roughly 100,000 WordPress installs running the mail plugin.

2 min read
Threat Intelligence

Fortibleed: How 75,000 FortiGate Firewalls Ended Up on an Attacker's Credential List

Configuration files. Legacy SHA-256 hashes. Automation at scale. The Fortibleed campaign is a slow-burn credential harvest that perimeter defenders are still catching up to.

3 min read
Identity & Access

MFA Alone Won't Save You: What Modern Attackers Know That Defenders Don't

A practitioner-focused webinar examines how threat actors sidestep conventional detection controls and why single-layer authentication assumptions are failing organizations.

2 min read
Threat Intelligence

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer

Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary — with an eBPF rootkit waiting if it gets root.

2 min read
Threat Intelligence

OnyxC2 Stealer: $250/Month Buys You Encrypted Payloads and 200+ App Targets

A commodity infostealer is punching well above its price point. OnyxC2 brings DLL sideloading and in-memory execution to anyone with a credit card.

2 min read
Identity & Access

Infostealers Are Now the Front Door for Ransomware Gangs

Credential theft at industrial scale has made exploit-based initial access look quaint. Here's why stolen session tokens are reshaping the attack chain.

2 min read
AI Security

Attackers Are Wrapping Old Phishing Tricks in AI Branding. It's Working.

Microsoft and Google both dropped advisories this week documenting how threat actors are dressing up familiar credential theft and malware campaigns as ChatGPT, Copilot, and DeepSeek experiences. The technique is not new. The success rate is.

2 min read
Vulnerabilities

Second Windows URI Handler Bug Leaks NTLMv2 Hashes — Still Unpatched

Researchers flag a search: URI handler flaw that mirrors the recently patched ms-screensketch issue. Microsoft hasn't shipped a fix.

2 min read
Vulnerabilities

Miasma Campaign Infects Red Hat npm Packages

Latest supply chain attack reveals persistent threat of credential theft

2 min read
Vulnerabilities

Miasma Attack Targets Red Hat Packages

Supply chain breach deploys credential-stealing worm through compromised npm packages.

2 min read
Threat Intelligence

Malicious npm Package codexui-android Pulls 29K Weekly Downloads, Targets OpenAI Codex Tokens

A package posing as a remote web UI for OpenAI Codex is harvesting developer credentials. It's still live on npm and GitHub.

2 min read
Threat Intelligence

GlassWorm Is Down. The Repository Problem Isn't.

CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

3 min read
Identity & Access

MokN Banks $15M to Turn Phishing Infrastructure Against Attackers

The startup's decoy access-point platform tries to catch credential thieves in the act — before stolen logins get used.

2 min read
© 2026 Threat Vectr