Tag

#credential theft

66 stories taggedcredential theft · page 4 of 5.

Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Breaches

12.2 Million People Hit by Data Breach at Japanese Telecom Giant KDDI

A previously unknown flaw in email software exposed the addresses and passwords of millions of customers across five internet providers. Mandatory password resets are now underway.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Threat Intelligence

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike

Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise

Incident-response firm Sygnia says a single attacker used AI to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

3 min read
Full-frame overhead photo of a developer's dark wooden desk lit by warm lamplight, showing an open laptop with generic blurred code on screen, a small stack of
Threat Intelligence

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets

A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

4 min read
A close-up photoreal shot of a laptop screen showing a blurred generic corporate login form, with a faint ghostly overlay of scrambled characters resolving into
Threat Intelligence

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim

The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

3 min read
Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign

A hacking group tied to China is exploiting a critical flaw in Roundcube webmail to steal login credentials from physics and engineering faculties at US and Canadian universities.

3 min read
Full-frame overhead view of a laptop screen showing a blurred generic calendar-booking interface with a small login popup window in the centre, warm office ligh
Threat Intelligence

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins

A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

3 min read
AI Security

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves

Researchers show how poisoned context fed to AI-driven browser agents causes them to drop safety guardrails and quietly exfiltrate stored credentials.

3 min read
Ransomware

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews

A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

3 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants, including ChatGPT Atlas, Perplexity's Comet and Anthropic's Claude extension, to exfiltrate user logins by framing the attack as a game.

3 min read
Threat Intelligence

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft

The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

3 min read
Threat Intelligence

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure

Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator and was staging for disruption, not just espionage.

2 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again, abusing GitHub Actions workflows and now reaching Go modules.

3 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective, and that's the problem.

3 min read
© 2026 Threat Vectr