Tag: credentials
-
Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/
-
Hackers build AI frameworks for widescale credential theft
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
-
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server…
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clearfake-webdav-infection-chain/
-
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/
-
Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials. The incident affected the registry at registry.coder.com on August 31, 2026, between 07:35 UTC and…
-
Product showcase: Doppler secures secrets for humans, pipelines, and AI agents
Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/product-showcase-doppler-secrets-management-platform/
-
AI Created a Leaked Credentials Flood: Here’s How We’re Draining It
TL;DRThe exposure problem: AI-driven development pushed exposed credentials to 1.27 million last year, up 81%, and 64% of secrets confirmed valid in 2022 are still unrevoked as of January 2026.The fix: GitGuardian Public Secrets Monitoring now runs two AI agents… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-created-a-leaked-credentials-flood-heres-how-were-draining-it/
-
Beyond the Login: Detecting Brute-Force and Credential Abuse in the Cloud Era
How intelligent security monitoring can identify suspicious authentication activity before a failed login becomes a successful compromise The modern enterprise no longer has a single security perimeter. Employees, applications, cloud services, and remote-access platforms are connected from virtually anywhere in… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/beyond-the-login-detecting-brute-force-and-credential-abuse-in-the-cloud-era/
-
âš¡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.Elsewhere, a trusted software source delivered code that stole…
-
Berlin investigates new data leak after hackers publish stolen login credentials
Another trove of data from Berlin’s government has appeared online, authorities said. Germany’s information security agency separately warned about the Rhysida cybercrime group. First seen on therecord.media Jump to article: therecord.media/germany-berlin-second-data-breach-city-agencies
-
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
Tags: access, control, credentials, cyber, email, google, infrastructure, network, phishing, serviceA large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to…
-
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits allow attackers to take control of print management servers, steal credentials, and deploy Meterpreter payloads within enterprise networks. Analysts Jens Pose and Ross Phillips from Arctic Wolf reported that these intrusions progressed from remote command execution to…
-
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.”The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
-
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, enabling attackers to steal browser data, hijack sessions, manage files and execute shell commands on compromised endpoints. Unlike a conventional initial-access malware strain, PEEP requires attackers to already possess administrative privileges or code-execution access on a…
-
Is Hotel WiFi Safe?
Hotel Wi”‘Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/is-hotel-wifi-safe/
-
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat…
-
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.”Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,”…
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as First…
-
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
Tags: ai, attack, automation, breach, cloud, credentials, cyber, framework, hacker, infrastructure, intelligence, network, threatA threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credentials, and hijack cloud AI infrastructure in less than 10 hours. The investigation, documented by Palo Alto Networks Unit 42, highlights a significant shift in intrusion operations. AI-assisted automation compressed an attack that could otherwise demand several…
-
How Keeper Helps Enforce Zero Standing Privilege
Privileged accounts are standing invitations for attackers, with credentials to steal and permissions to misuse. When administrative rights are persistently active, whether or not they’re being used, privileged accounts significantly expand the attack surface. Zero Standing Privilege (ZSP) shrinks that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-keeper-helps-enforce-zero-standing-privilege/
-
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/
-
Coder Registry Compromise: Malicious Terraform Modules Explained
Coder’s compromised module registry served malicious Terraform modules that stole cloud, CI/CD, AI, and SSH credentials during a 14-hour attack window. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-coder-registry-malicious-terraform-modules/
-
Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials
Services Services Tailored consulting, engineering and managed security services to meet your unique needs. Application Security Ensure all software releases are secure Ensure all software releases are secure — www.guidepointsecurity.com/application-security/ Application Security Confidently use AI to fuel organizational success. –… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/attacking-and-defending-scom-management-server-relay-and-obtaining-run-as-credentials/
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic.…
-
A five-part inventory for your AI agent credentials
In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/ai-agent-credentials-video/
-
A five-part inventory for your AI agent credentials
In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/ai-agent-credentials-video/
-
Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign
A large-scale campaign dubbed Operation CameraSwarm compromised at least 14,530 Dahua IP cameras and related surveillance devices in just 35 days. Exposing how unpatched flaws, weak credentials, and cloud-connected P2P features can turn video-security infrastructure into a remotely accessible attack surface. Threat intelligence firm Hunt.io reconstructed the operation after discovering an unsecured HTTP directory belonging…

