Tag: credentials
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
AiTM phishing overtakes credential theft as top threat to law firms
First seen on scworld.com Jump to article: www.scworld.com/brief/aitm-phishing-overtakes-credential-theft-as-top-threat-to-law-firms
-
BSidesSF 2026 The Great Credential Caper: How To Perform And Then Defend Against The (Nearly Impossible) To Defend
Tags: credentialsPresenter: Christo Roberts, Dan Hollinger Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-the-great-credential-caper-how-to-perform-and-then-defend-against-the-nearly-impossible-to-defend/
-
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurrency wallets. The attack begins when victims search Google for >>how to install Claude on a Mac<< and click a sponsored…
-
Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networks
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
-
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.Tengu supports 25 distributed denial-of-service (…
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens. First seen on hackread.com Jump to article: hackread.com/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts/
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel…
-
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.That model is changing.Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting First seen on thehackernews.com Jump to article:…
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data,…
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover
-
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/
-
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. First…
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. First seen on hackread.com Jump to article: hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator mark a clear architectural evolution in the group’s malware-as-a-service (MaaS) ecosystem, signaling a shift…
-
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential First seen…
-
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646180/Why-embodied-AI-security-extends-beyond-the-robot
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
The best-funded companies open the most phishing attachments
An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/

