Tag: credentials
-
LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking. FortiGuard Labs reported an incident involving Amazon Bedrock in which a leaked, long-lived AWS IAM access key with AdministratorAccess permissions was used to create a new identity, subscribe to foundation models, and run inference at…
-
How AI Agents Expand the Identity Security Attack Surface
Why Autonomous Tools Can Execute Requests Humans Would Recognize as Unsafe. Menlo Security CEO Bill Robbins said AI agents can combine their own identities with users’ delegated credentials, requiring enterprises to govern both agent access and human authority to prevent malicious prompts from enabling data theft or other harmful actions. First seen on govinfosecurity.com Jump…
-
Neue Phishing-Heimat Cyberkriminelle setzen verstärkt auf Fake-Websites mit *.vu-Endung
Bevor Cyberkriminelle eine erfolgreiche Phishing-Angriffskampagne starten können, müssen sie sich zum Abgreifen der Credentials, der Nutzer- und der Bankdaten ihrer Opfer eine Fake-Website zulegen und auf einer Domain zum Laufen bringen. Wird der Angriff dann entdeckt, treten Cybersicherheitsdienste und Unternehmen, deren Identität für die Fake-Website gekapert wurde, mit dem Host oder Registrar der […] First…
-
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have First seen…
-
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
Tags: access, breach, business, credentials, cyber, data-breach, encryption, hacker, infrastructure, network, ransomware, service, threatThe Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise…
-
Enterprise AI is quietly undoing a decade of credential hygiene
First seen on scworld.com Jump to article: www.scworld.com/perspective/enterprise-ai-is-quietly-undoing-a-decade-of-credential-hygiene
-
How Attackers Game Legacy Threat Feeds Aged Domains
Take a tour through almost any SOC. You’ll find dashboards filled with rules designed to block newly registered domains (NRDs). On paper, the logic feels bulletproof. When threat syndicates spin up infrastructure for a massive phishing wave or credential-harvesting campaign, they need digital… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-attackers-game-legacy-threat-feeds-aged-domains/
-
Wiz Finds Active LiteLLM and MCP Attacks Targeting AI Infrastructure
Wiz observed active attacks on LiteLLM and MCP servers, including credential theft, cryptomining, command execution, and prompt injection. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-litellm-mcp-server-attacks/
-
OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome
TL;DRCredentials are the multiplier: OWASP’s Top 10 CI/CD Security Risks cover ten distinct trust failures, but exposed or overprivileged credentials (CICD-SEC-6) make nearly every other risk more dangerous once attackers gain a foothold.Attacks are accelerating: Since 2025, worms like Shai-Hulud,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/owasp-top-10-ci-cd-security-risks-explained-why-credential-hygiene-decides-the-outcome/
-
BackSchool Cybersecurity
Credential Risk Deserves More Attention Back-to-school season brings a surge of activity across school networks. Students return, new accounts are created, faculty and staff reconnect, and users begin accessing email, learning platforms, administrative systems, and other applications. For IT and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/back-to-school-cybersecurity/
-
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
Tags: breach, control, credentials, cyber, edr, framework, group, hacker, healthcare, ransomware, technologyThe Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.…
-
The PAM Migration Trap: Modernizing Your Vault Doesn’t Modernize Privileged Access
PAM modernization should reduce standing privilege, not just move credentials into a newer vault. True progress means eliminating unnecessary privileged identities. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-pam-migration-trap-modernizing-your-vault-doesnt-modernize-privileged-access/
-
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as First seen…
-
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/
-
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign prioritizes long-term interactive access over direct cryptocurrency theft, combining hidden VNC, SOCKS proxying, file management and browser-data theft in an…
-
Anthropic: Attackers Using Infostealers to Hijack Claude Sessions
Anthropic is warning Claude users that attackers are using infostealer malware to compromise their login sessions and stealing usage to run their nefarious activities. It’s the latest demonstration of the shift by bad actors from credentials to session tokens and authentication cookies. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/anthropic-attackers-using-infostealers-to-hijack-claude-sessions/
-
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
-
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
-
Attacks Targeting Langflow AI Agent-Building Tool Surge
Tags: access, ai, attack, credentials, exploit, framework, ibm, intelligence, open-source, software, tool, vulnerabilityTool’s Access to Compute Resources, Keys and Credentials Make It a Repeat Target. Open-source framework Langflow, designed to build artificial intelligence agents and workflows, is under fire again, with attackers now wielding exploit code for a vulnerability first detailed in January. Outdated versions of the IBM-maintained software with known vulnerabilities appear to abound. First seen…
-
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Tags: ai, credentials, exploit, flaw, framework, open-source, openai, remote-code-execution, threat, vulnerabilityThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
-
Credential Security: What Endpoint Protection Really Means for Secrets
TL;DREndpoint protection means AV or EDR: The term “endpoint protection” almost always refers to antivirus or EDR. Antivirus started as signature-based malware detection; EDR added continuous behavioral monitoring and response. Both are designed to detect and stop malicious activity on… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credential-security-what-endpoint-protection-really-means-for-secrets/
-
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Tags: ai, attack, cloud, control, credentials, cve, cyber, exploit, flaw, hacker, rce, remote-code-execution, theft, threat, vulnerabilityThreat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2) functions. VulnCheck researchers have reported exploitation targeting CVE-2026-0768 in Langflow, a low-code platform for building AI-powered applications and automated workflows. This vulnerability…
-
Hackers Exploit Langflow RCE Flaw to Harvest OpenAI and AWS Credentials
Tags: ai, credentials, cve, cyber, exploit, flaw, hacker, openai, rce, remote-code-execution, threat, vulnerabilityThreat actors are actively exploiting a critical remote code execution vulnerability in Langflow, a low-code platform used for building AI-powered applications and automating workflows. This vulnerability, tracked as CVE-2026-0768, affects the code validator in Langflow’s custom component editor. According to Caitlin Condon, VP of Security Research at VulnCheck, the flaw allows unauthenticated remote code execution…
-
JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS
A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by some vendors as WEEVILPROXY or MeadowLocust, is not delivered as readable JavaScript. Instead, operators package the final payload as a .jsc file compiled V8 bytecode executed with a bundled Node.js runtime. This approach frustrates conventional JavaScript…
-
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS…
-
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.The vulnerabilities in question are listed below – CVE-2026-0768 (CVSS score: 9.8) – A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the…
-
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic’s Claude Opus 5. Instead a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation. The primary lure, branded “Claude Opus 5…
-
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload. On August 28, 2026, attackers published ten malicious versions across every maintained release branch of the OpenAPI-to-TanStack Query code generator, which records roughly 150,000 weekly downloads. The releases appeared in two publishing waves approximately…
-
From a Stolen Login to a Ransomware Leak Site: What Our Telemetry Shows About the Path Threat Actors Take
A ransomware disclosure and a credential package we track from an entirely separate source, read side by side, illustrate a pattern our research team sees again and again: the quiet theft of a single login can be the first domino… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/from-a-stolen-login-to-a-ransomware-leak-site-what-our-telemetry-shows-about-the-path-threat-actors-take/

