Tag: password
-
Stolen passwords are exposing America’s water providers to hackers
Researchers say another looming threat hangs over some of America’s most important critical infrastructure. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/
-
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when…
-
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary First seen on thehackernews.com…
-
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/taskstomp-windows-backdoor/
-
FBI’s CJIS v6.1: What Security Teams Need to Know.
The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/
-
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installing malware, granting remote access, and stealing Windows credentials. These attacks exploit a simple vulnerability: employees tend to distrust suspicious emails but often do not apply the same caution to collaboration platforms like Teams. Attackers…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
-
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.”HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, First seen on thehackernews.com Jump to article:…
-
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links.Helpfeel said…
-
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/
-
Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/
-
RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designed to steal banking credentials, payment PINs, one-time passwords, device-unlock secrets, and other high-value data from infected Android devices.…
-
Enterprise Access Management ohne Passwort – Das Passwort bleibt der wunde Punkt der Multi-Faktor-Authentifizierung
First seen on security-insider.de Jump to article: www.security-insider.de/enterprise-access-management-passwortlose-mfa-a-0e694deae39034091492046cf8cd306f/
-
Credentials Are Still the Shortest Path In
How Brutus grew into an engine that finds your identities, tests them everywhere they’re accepted, and remembers what it confirms. An attacker rarely needs a novel exploit when a valid username and password pair is sitting in a breach dump,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credentials-are-still-the-shortest-path-in/
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Tags: access, authentication, cctv, cve, cyber, cybersecurity, flaw, infrastructure, network, password, vulnerabilitySecurity researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link…
-
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather…
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Detecting OAuth consent phishing in Microsoft 365 audit logs
OAuth consent phishing is a practical identity attack that abuses the trust users place in application consent prompts. Instead of stealing a password directly, the attacker persuades a user to grant a malicious app access to mailbox data, profile information,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-oauth-consent-phishing-in-microsoft-365-audit-logs/
-
NextGen Mirth Connect Flaws Expose Downstream System Logins
Attackers Could Steal Credentials Used to Reach Connected Hospital Systems. Three high-severity NextGen Connect flaws can expose administrator data, plain-text connector passwords and server files, potentially giving attackers credentials for databases, clinical endpoints and other downstream healthcare systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789

