Tag: credentials
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device. First seen on therecord.media Jump to article: therecord.media/florida-shiny-hunters-motor-vehicle
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
Your Newest Privileged Identity Is An AI Agent
Agentic AI turns software into an actor with credentials, tools and reach. Security programs built around human and service-account assumptions need a new identity model. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-newest-privileged-identity-is-an-ai-agent/
-
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Tags: access, authentication, cisco, control, credentials, cve, exploit, firewall, flaw, group, ransomware, threatThree threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run…
-
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September…
-
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed…
-
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking…
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Tags: attack, authentication, cisco, credentials, cve, exploit, firewall, flaw, ransomware, software, threat, vulnerabilityCisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass First seen on…
-
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws. Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793
-
NextGen Mirth Connect Flaws Expose Downstream System Logins
Attackers Could Steal Credentials Used to Reach Connected Hospital Systems. Three high-severity NextGen Connect flaws can expose administrator data, plain-text connector passwords and server files, potentially giving attackers credentials for databases, clinical endpoints and other downstream healthcare systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789
-
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Tags: access, ai, authentication, cloud, credentials, cyber, data-breach, hacker, Internet, theft, vulnerabilityNearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted…
-
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials…
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a…
-
How to build a continuous pentesting program
IntroductionAn unpatched flaw is now the most common entry point for a breach, at 31%, ahead of stolen credentials at 13%, and the median time to fix one has crept up to 43 days (Verizon’s 2026 DBIR). So an annual… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-build-a-continuous-pentesting-program/
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/product-showcase-gitguardian-honeytoken-decoy-service/
-
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-phishing-credential-theft-screenconnect/
-
Google Warns Hackers Are Turning AI Agents Into Attack Tools
Google warns that hackers are using AI agents to automate attack stages, harvest credentials, and accelerate cyberattacks with less human direction. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-google-hackers-ai-agents-attack-tools/
-
220 Million Travel Records Exposed Through Default Credentials
Researchers found 220.8 million passenger and crew records exposed through default credentials in a Vietnam-linked database containing sensitive travel data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-220-million-travel-records-default-credentials-apac-vietnam/
-
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-adobe-commerce-cve-2026-75650-stylesmuggler/
-
Service Account Credential Rotation: The Blast-Radius Checklist
TL;DRThe problem: Service account credentials pile up with no clear owner, and teams avoid rotating them for fear of breaking production dependencies nobody has mapped.The checklist: Answer eight questions before rotating: validity, exposure, access scope, consumers, vault location, duplicate copies,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/service-account-credential-rotation-the-blast-radius-checklist/
-
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI First seen on thehackernews.com…

