Tag

#credentials

7 stories taggedcredentials.

A developer's machine with folder structure expanding across the screen, credential stealer malware scanning through 469 different storage locations simultaneou
Identity & Access

Shai-Hulud Worm Now Hunts 469 Places for Developer Secrets

A self-spreading credential thief has more than doubled the hiding spots it checks on developer machines, from 189 to 469.

4 min read
An office environment with an employee at a computer appearing to provide unauthorized access credentials to someone off-screen, with sensitive network diagrams
Identity & Access

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door

Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

4 min read
A security professional reviewing documentation and checklists on a desk, with a laptop displaying OWASP guidelines and AI security frameworks on the screen
AI Security

OWASP Publishes First Security Watchlist for AI Agent 'Skills'

A real attack in July exposed more than 300,000 users to stolen credentials through fake AI skills. Now the group behind the web's most-used security checklists has named the top ten risks, and 'malicious skills' sits at number one.

4 min read
An email inbox displayed on a screen with one suspicious message standing out among legitimate emails—its sender address slightly off, urgency language emphasiz
Threat Intelligence

What is phishing and how do you spot a phishing email?

Phishing is the most common way attackers steal credentials and money. Here is what the attack looks like and how to catch it before you click.

5 min read
Photoreal editorial photograph of a dimly lit industrial control room in a water treatment facility, rows of monitors showing SCADA dashboards, a single unatten
Identity & Access

Why Stolen Logins Keep Opening the Door to Power Grids and Water Plants

Attackers rarely need fancy exploits when a valid password and an unchecked laptop will do. A look at why device trust is the missing half of Zero Trust in critical infrastructure.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Ransomware

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In

A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

3 min read
Threat Intelligence

Harvest Now, Decrypt Later: Why Credentials Are the First Casualty of Q-Day

Captured ciphertext today becomes plaintext tomorrow. Credentials sit at the top of the target list.

3 min read
© 2026 Threat Vectr