Tag: credentials
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user…
-
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai’s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…
-
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and extensive persistence into a single Windows-focused payload. Marketed by a user known as “RemoteX” in March 2026, the kit gives operators a parallel Win32 desktop where they can browse, run tools, and interact with hijacked sessions…
-
Attackers turn to AI for help identifying files worth stealing
AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/
-
OpenAI Workload Identity Federation: Aembit Brings Secretless Access to the OpenAI API
3 min readAembit already covers a lot of ground when it comes to securing AI workload access. For OpenAI’s ChatGPT, workloads can authenticate to the ChatGPT API using static API key injection, with the Aembit proxy handling direct access transparently. Today, we’re extending that coverage with the introduction of the OpenAI Workload Identity Federation Credential…
-
SafePal Says 39,798 Customers Hit by Data Breach
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026,…

