Tag: credentials
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Tags: ai, attack, credentials, exploit, jobs, network, ransomware, rce, remote-code-execution, threatSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a…
-
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.”An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment First seen on thehackernews.com Jump to…
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is simple and effective: newly disclosed high-severity CVEs create urgency for fast PoC and scanner module development. Adversaries create seemingly legitimate PoC repositories that include…
-
Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz
An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe to run OS reconnaissance such as whoami, and then deployed an extensive defence-impairment script (i.bat) that prefaced a credential-dump…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
FortiBleed credential-theft campaign linked to Lynx ransomware
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/
-
Langflow Flaws Exposed AI Servers to Takeover
Rubrik Decries Lack of Fundamental Cybersecurity in AI Platforms. Rubrik Zero Labs found four vulnerabilities in Langflow, including flaws that allowed unauthenticated attackers to execute code, read sensitive files and steal credentials under specific conditions. The open-source AI orchestration platform patched the vulnerabilities between February and May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/langflow-flaws-exposed-ai-servers-to-takeover-a-32125
-
Fluentd Security Flaws Enable Remote Code Execution, SSRF, DoS, and Credential Exposure
Tags: credentials, cyber, data, dos, flaw, github, open-source, remote-code-execution, service, vulnerabilityFluentd, a widely used open-source data collector for unified logging, has reported several high-impact vulnerabilities that could enable attackers to achieve remote code execution (RCE), server-side request forgery (SSRF), denial-of-service (DoS), and the exposure of sensitive credentials. These issues, documented in multiple GitHub Security Advisories, affect Fluentd versions up to 1.19.2 and have been resolved…
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE…
-
Critical flaw in SimpleHelp exploited in attacks targeting sensitive credentials
Researchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-flaw-simplehelp-exploited-attacks-credentials/824105/
-
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user’s credentials and sending them to an attacker.The targets included OpenAI’s ChatGPT Atlas, Perplexity’s Comet,…
-
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user’s credentials and sending them to an attacker.The targets included OpenAI’s ChatGPT Atlas, Perplexity’s Comet,…
-
‘Djinn’ Stealer Targets Cloud, AI Credentials
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/djinn-stealer-targets-cloud-ai-credentials
-
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/amazon-q-vs-extension-flaw-leads-cloud-credential-theft
-
StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
Microsoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever malicious extension campaigns it’s ever documented. The operation, named StegoAd, ran 119 extensions on the Edge Add-ons store, racked up roughly 2.6 million installs,…
-
Why Post-Quantum Cryptography Starts With Credentials
Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break elliptic curve cryptography or RSA, quantum hardware is advancing rapidly and will inevitably change how organizations protect their data. Ciphertext and credentials…
-
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud.The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat…
-
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2.libssh2…
-
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
UNC1151 tracked by many as Ghostwriter or FrostyNeighbor has advanced a credential-phishing technique that uses a real-time WebSocket relay to defeat SMS and OTP-based multi-factor authentication (MFA). The method was observed in a recent campaign that targeted Belarusian politician Yury Hubarevich and multiple Ukrainian portals, and Censys pivots show the infrastructure spans dozens of domains…
-
Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
Rokarolla, a sophisticated Android banking trojan distributed via malicious websites that masquerade as trusted applications such as TikTok, Google Chrome and even Google Play Protect. Unlike simple credential stealers, Rokarolla is a multi-functional fraud platform that targets at least 217 banking and cryptocurrency apps and combines Accessibility Service abuse, phishing overlays, SMS interception, keylogging, screenshot…
-
Amazon Q Developer extension vulnerability could have exposed cloud credentials
First seen on scworld.com Jump to article: www.scworld.com/brief/amazon-q-developer-extension-vulnerability-could-expose-cloud-credentials
-
Five nines and the SaaSpocalypse: Why credential security survives the AI reset
First seen on scworld.com Jump to article: www.scworld.com/perspective/five-nines-and-the-saaspocalypse-why-credential-security-survives-the-ai-reset
-
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the U.S.The systematic cyber attacks aimed at stealing sensitive First seen…
-
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories
A critical security flaw discovered in the Amazon Q Developer Extension for Visual Studio Code (VS Code) left developers vulnerable to arbitrary code execution and cloud credential theft. Tracked as CVE-2026-12957 and CVE-2026-12958, these high-severity vulnerabilities highlight significant risks in how AI coding assistants manage trust boundaries. The root cause of this vulnerability lies in…
-
Weak Access Controls Leave Enterprise Networks at Risk
Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/
-
Weak Access Controls Leave Enterprise Networks at Risk
Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/

