Tag: credentials
-
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, and workflows without exposing long-lived credentials or bypassing access controls. This release addresses a significant security challenge for enterprises: while agents need access to business data and tools to be effective, conventional API keys…
-
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison pages.…
-
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
Tags: credentials, cyber, data, infrastructure, injection, oracle, rce, remote-code-execution, sql, theft, threatKHunt shows how a “routine” SQL injection against an Oracle”‘backed web app can be weaponized into SYSTEM”‘level remote code execution and credential theft by compiling a full post”‘exploitation toolkit directly inside the database engine. This incident materially shifts the Oracle threat model: the database itself becomes attacker infrastructure, not just a data store. Subsequent triage…
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
Too many credential leaks, too little context? SOCRadar connects the dots
First seen on scworld.com Jump to article: www.scworld.com/news/too-many-credential-leaks-too-little-context-socradar-connects-the-dots
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Aembit Adds Workload Identity Federation Support for the Claude API
5 min readToday, we’re announcing the Aembit Claude Workload Identity Federation Credential Provider, the latest addition to Aembit’s growing Claude support. Aembit already covers a lot of ground with Claude: workloads can authenticate to the Claude API using static API key injection, Claude Web and the Claude App are supported as Client Workloads, direct API…
-
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services. First seen on hackread.com Jump to article: hackread.com/im-allowed-hackers-use-claims-bypass-ai-guardrails/
-
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for…
-
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896…
-
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks. The research, titled >>Zero Day Provisioning,<< was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada…
-
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-russian-hackers-hotel-wifi/
-
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
-
Worm Targets More Than 2,000 npm Package Versions
Attackers Compromised Keyv and Cacheable Source or Release Credentials. A self-replicating npm worm linked by tradecraft to Shai-Hulud has compromised more than 2,000 versions of 444 packages, stealing cloud and CI credentials and using exposed publisher tokens to spread through trusted dependencies. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
-
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time. First seen on hackread.com Jump to article: hackread.com/shai-hulud-npm-worm-poisoning-1280-packages/
-
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.”Greatness supports AiTM [adversary-in-the-middle] credential and First seen on thehackernews.com…
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack
A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/github-account-breach-fuels-shai-hulud-npm-supply-chain-attack/
-
Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines
Tags: credentialsCredential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/credential-harvesting-explained-how-attackers-collect-secrets-from-developer-machines/
-
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian’s research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-agentic-ai-workflows-in-n8n-from-leaked-api-keys-to-encryption-key-compromise/
-
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
Tags: apple, credentials, cyber, data-breach, exploit, google, group, intelligence, iphone, login, risk, threatDarkSword’s leaked iOS exploit chain is now powering a fast”‘moving server cluster that marries one”‘click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to…
-
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026.SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported…
-
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that…
-
How Vulnerable Are Single Sign-On Systems to Modern Credential Attacks?
SSO credential attacks explained: how vishing, MFA resets, stale OAuth tokens and admin takeover break SSO, and the controls that stop each one. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-vulnerable-are-single-sign-on-systems-to-modern-credential-attacks/
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels

