Tag: credentials
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/
-
Identity Is Broken. Stop Trying to Fix It.
Tags: access, authentication, credentials, cryptography, data, identity, infrastructure, mfa, zero-trustFrom the earliest days of public-key cryptography and systems like Rivest-Shamir-Adleman (RSA), organizations have relied on identity and credentials to determine who can access IT environments, data, and applications. Over the decades, this infrastructure has undergone innovations like multi-factor authentication, single sign-on, identity providers, and zero-trust architectures. Then, there has been the emergence of various..…
-
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed unauthenticated attackers to execute commands on a GitHub-hosted runner and potentially steal internal Jira credentials. The vulnerability was discovered by Wiz Red Agent, an autonomous AI-powered security research tool, just five days after the vulnerable workflow was deployed. Snowflake…
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
Supply chain attack modelling using MITRE ATTCK
Supply chain risk is often discussed as a supplier problem, but for security teams it is better treated as an attack path problem. The practical question is not simply whether a supplier is trustworthy. It is how a compromise of that supplier, their software, their credentials, or their support channels could be used to reach……
-
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files First…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records across merchants in 42 countries, but available evidence indicates that Stripe’s own infrastructure was not breached. The dataset…
-
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
Tags: credentials, cve, cvss, cyber, data, exploit, extortion, hacker, ransomware, remote-code-execution, vulnerabilityThe Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus
Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it. Now, with artificial intelligence supercharging phishing campaigns and a hidden layer…
-
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Tags: ai, automation, cloud, credentials, exploit, flaw, intelligence, malicious, open-source, software, technology, vulnerabilityTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows – First seen on thehackernews.com Jump…
-
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/
-
Why Secrets Slip Through Every Layer of Your Security Stack
Your security stack is a set of specialists, each guarding one territory. Exposed credentials don’t respect the boundaries between them, and 64% of the ones found valid in 2022 were still valid four years later. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-secrets-slip-through-every-layer-of-your-security-stack/
-
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Tags: control, credentials, cybersecurity, framework, hacker, infrastructure, microsoft, network, serviceCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.”TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file First seen on thehackernews.com Jump to article:…
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
-
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure, according to watchTowr. This flaw affects MLflow versions before 3.15.0 and can expose cloud credentials, internal services, and other sensitive data to remote attackers. MLflow SSRF Flaw The vulnerability exists in MLflow’s model-registry…
-
Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/download-enzoic-2026-credential-risk-report/
-
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn First seen…
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…

