Tag: theft
-
University of Illinois Chicago affected by ransomware attack on medical school
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers. First seen on therecord.media Jump to article: therecord.media/ransomware-university-illinois-chicago
-
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
Tags: access, ai, authentication, credentials, cyber, flaw, open-source, theft, update, vulnerabilityAWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0. AWS announced these issues in Security Bulletin…
-
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/
-
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64. All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and…
-
Iranian accused of hacking American universities extradited from Montenegro
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro. First seen on therecord.media Jump to article: therecord.media/iran-montenegro-hacker-extradition
-
The Cyber Express Weekly Roundup: Renfe Confirms Breach, Australia Warns of Hijacked AI Keys, and Europol Sounds the Alarm on AI-Driven Crime
This weekly roundup covers a customer data breach at Spain’s national rail operator, an Australian government warning about attackers hijacking corporate AI services, a patient data theft from a Polish medical software platform, phishing campaigns that turn legitimate remote management tools against their victims, and a gathering of Europe’s police leaders focused on how AI…
-
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.”Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker First seen on thehackernews.com Jump to…
-
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler First seen on thehackernews.com Jump…
-
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure.By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud First seen on thehackernews.com…
-
Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
Tags: access, credentials, cyber, exploit, hacker, malware, monitoring, phishing, software, theft, tool, vulnerability, windowsThe phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on Windows systems. The campaign demonstrates a recurring operational trend: rather than exploit a vulnerability or deploy obvious custom malware, attackers are abusing trusted administrative platforms already designed to execute commands, transfer files, deploy applications, and…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the ShinyHunters cybercrime group. This development marks a significant step forward in an international investigation into a widespread data theft and extortion operation. The suspect was arrested on September 15,…
-
US Air Force members given over 6 years in prison for cyber theft of more than $2 million
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June. First seen on therecord.media Jump to article: therecord.media/us-air-force-members-given-6-year-sentence-cyber
-
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France’s tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July.Neither the tax administration nor France’s national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on…
-
Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover
Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments that use HTTP transport and includes vulnerable SDK releases from versions 1.9.1 to 2.1.1. Research from Cycode…
-
New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Tags: ai, api, botnet, control, credentials, cyber, ddos, infrastructure, intelligence, malware, service, theft, threat, windowsA newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-control infrastructure, and an “AI API drain” capability designed to exhaust victims’ paid artificial-intelligence service credits. Qrator Research Labs identified the previously undocumented malware platform during threat hunting. They traced its sale to an operator…
-
Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Tags: api, attack, cloud, credentials, cyber, data-breach, exploit, identity, infrastructure, malware, theft, threatInfostealer malware is increasingly becoming the bridge between a compromised developer workstation and an enterprise cloud environment, with Lumma, RedLine, and Vidar emerging as major threats to credentials, API keys, and active browser sessions. Identity, rather than exposed infrastructure, remains the most valuable cloud attack surface. Attackers no longer need to exploit a public-facing server…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Ex-US soldier gets 70 months for role in ATT, Snowflake data thefts
A former U.S. Army soldier who was part of a group that stole data from telecom companies, including ATT, has been sentenced to 70 months in prison. Cameron John … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/us-army-soldier-snowflake-breaches-extortion/
-
North Korean hackers suspected in $351M crypto theft, the largest so far this year
The $351 million theft from crypto exchange Bitget is the latest in a string of high profile hacks targeting the crypto sector. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Ghost Service Accounts Enable M365 Data Theft in Chile
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization’s entire M365 environment. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chile
-
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
The theft of agents’ personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
-
Looking Back Over 14 Years of Identity Theft Scams
Retiring ITRC CEO Eva Velasquez on Identity Crime, Victim Recovery, the Work Ahead. After 14 years leading the Identity Theft Resource Center, Eva Velasquez will retire as CEO in January 2027. She reflects on the organization’s growing reach, identity crime trends and why victim support is crucial in the evolving threat landscape. First seen on…

