Tag: credentials
-
Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestra workflow orchestration environments to steal model-provider credentials, establish persistence, access backend data, and deploy cryptominers. The appeal is clear. AI gateways often centralize OpenAI, Azure, Anthropic, Gemini, and other provider API keys; retrieval platforms hold…
-
Kalender-Phishing: Wie Angreifer .ics-Dateien für Credential Harvesting missbrauchen
Kriminelle nutzen vertrauenswürdige Kalendereinladungen und .ics-Dateien, um E-Mail-Filter zu umgehen und Zugangsdaten zu stehlen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/kalender-phishing-2
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
AnonyMousKIT phishing service targets Apple credentials and Activation Lock
First seen on scworld.com Jump to article: www.scworld.com/brief/anonymouskit-phishing-service-targets-apple-credentials-and-activation-lock
-
AnonyMousKIT phishing service targets Apple credentials and Activation Lock
First seen on scworld.com Jump to article: www.scworld.com/brief/anonymouskit-phishing-service-targets-apple-credentials-and-activation-lock
-
Fake recruiter scams target corporate credentials on mobile devices
First seen on scworld.com Jump to article: www.scworld.com/brief/fake-recruiter-scams-target-corporate-credentials-on-mobile-devices
-
ASOS Account Takeover Attack Exposes Data of 138,828 Customers
ASOS says attackers used credentials stolen elsewhere to access customer accounts, exposing personal data belonging to an estimated 138,828 people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-asos-account-takeover-138828-customers/
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/recruitment-scam-corporate-passwords-mobile/
-
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a basic web server misconfiguration can turn source code history into an immediate cloud access risk. The research, published by attack-surface management firm Intruder, examined 3.5 million live HTTP hosts selected from…
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
Agentic AI Security: Credentials and Permissions Define the Blast Radius
Prompt injection can’t be patched away. Three 2026 agentic AI incidents show that credentials and permissions decide the damage. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/agentic-ai-security-credentials-and-permissions-define-the-blast-radius/
-
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from…
-
Fake Recruiter Scams Target Corporate Credentials on Mobile
RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-recruiter-scams-corporate/
-
Can You Hear Me Now? Show Me Your Papers
The FCC’s proposed phone-service KYC rules could reduce fraud but also turn mobile numbers into identity-linked credentials with major privacy implications. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/can-you-hear-me-now-show-me-your-papers/
-
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey…
-
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but instead deliver the Vidar information stealer. The campaign targets browser credentials, session cookies, and other profile data that can let attackers access accounts even after victims change their passwords. The…
-
Thousands of Leaked AWS Access Keys Are Still Active
Truffle Security found 9,308 leaked AWS keys still active, including 768 corporate credentials with full administrative control of cloud accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-leaked-aws-access-keys-still-active/
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
Map What Your Agent Can Reach Before It Deletes It FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 24, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…
-
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There’s a chance that you have just handed a complete stranger access to your savings. First seen on bitdefender.com Jump to article:…
-
Attackers Exploit Critical Flaw in MLflow, an AI Platform Downloaded 30M Times Monthly
The MLflow SSRF flaw CVE-2026-64849 can let unauthenticated attackers access internal services and cloud metadata, potentially exposing sensitive credentials and secrets. First seen on hackread.com Jump to article: hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
ToxicPanda 2.0 Targets 349 Financial Apps and Steals Android Lock Credentials
ToxicPanda 2.0 is going after Android users in 16 countries, stealing banking and unlock credentials while taking control of devices through Wireless Debugging. First seen on hackread.com Jump to article: hackread.com/toxicpanda-2-0-app-steals-android-lock-credentials/
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…
-
Does AI Create New Cybersecurity Risks? What Actually Changes
<div cla AI does not create new attack vectors. It accelerates the ones that already dominate most risk registers. Code exploitation, injection, credential and identity abuse, phishing, and misconfiguration are the same vectors security teams tracked before generative AI reached the enterprise. What changed is how quickly they can be found and exploited, and the…

