Tag: theft
-
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access. First seen on hackread.com Jump to article: hackread.com/taskstomp-windows-backdoor-document-theft/
-
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/shinyhunters-claim-hack-of-clop/
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
RatHat Turns Android Accessibility Into an Attack Weapon
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is…
-
What Recent AI-Powered Attacks Mean for Your Identity Security
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/what-recent-ai-powered-attacks-mean-for-your-identity-security/
-
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity was observed in August 2026 and reflects a significant evolution…
-
AI Agent Carries Out Multi-Stage Data Theft Attack
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/
-
BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks
Tags: ai, attack, control, credentials, cyber, cyberattack, cybercrime, data-breach, hacker, Internet, phishing, theftA French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Ukraine moves to crack down on scam call centers after corruption scandal
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations. First seen on therecord.media Jump to article: therecord.media/ukraine-call-center-scam-crackdown
-
NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/nist-cisa-cloud-token-security-guidance/
-
NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled >>Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for…
-
OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
3,022 RubyGems packages associated with the GemStuffer campaign, expanding the known scope of an incident that researchers have linked to an alleged OpenAI agent swarm. The inventory covers 3,315 distinct package name-and-version pairs and reveals a sustained campaign that combined documentation-worker abuse, data collection, credential-theft attempts, and metadata-based web attack tests. When a documentation worker…
-
Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps
A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the…
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance,…
-
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device. First seen on therecord.media Jump to article: therecord.media/florida-shiny-hunters-motor-vehicle
-
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial First seen on thehackernews.com Jump…
-
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September…
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate various stages of the cyber kill chain, including reconnaissance, phishing, exploitation, persistence, and bulk data theft. Anthropic reported disrupting multiple such operations between December 2025 and August 2026, involving groups suspected to be linked to…
-
Quantum’s Bigger Threat: Forged Identities, Not Data Theft
Applied Quantum’s Marin Ivezic on Why Forged Signatures Beat Stolen Data as a Risk. Data theft dominates quantum risk planning, but a quieter threat could prove even worse. Marin Ivezic, CEO at Applied Quantum, says quantum computers used to forge digital signatures at some point in the future could undermine trust across IT and OT…
-
Cryptohack Roundup: Trezor’s Phishing Warning
Also: ‘White-Hat’ Hackers Withdraw $320M From Liquid. Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Trezor warns customers after email provider breach, Liquid pauses network after $320 million Bitcoin withdrawal, man pleads guilty in $245 million theft and India targets 15 crypto platforms over compliance failures. First seen on govinfosecurity.com Jump…

