Tag: theft
-
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here’s a tip for any budding cybercriminals out there. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/anne-hathaway-245-million-crypto-theft-nightclubs-watches-luxury-cars
-
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Tags: access, ai, authentication, cloud, credentials, cyber, data-breach, hacker, Internet, theft, vulnerabilityNearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted…
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/
-
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/product-showcase-gitguardian-honeytoken-decoy-service/
-
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake >>leaked<< copies of the hotly anticipated game. GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an…
-
‘White hat’ hackers take $47 million bounty after $320 million crypto theft
Public negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most, but not all, of what they took. First seen on therecord.media Jump to article: therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward
-
A hacker stole $340M in a crypto heist, then returned most of it
The latest heist is one of the largest thefts of cryptocurrency to date. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/08/a-hacker-stole-340m-in-a-crypto-heist-then-returned-most-of-it/
-
Hackers build AI frameworks for widescale credential theft
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clickfix-moves-into-the-browser/
-
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.The activity, which mainly singles out directors, vice presidents, and other executive staff First seen on thehackernews.com Jump to…
-
JSCeal Hides Crypto Malware in V8 Bytecode
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest…
-
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea’s Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
-
Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC
The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds, but only after the vulnerability that enabled the exploit is fixed across the network. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/liquid-network-security-incident/
-
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. The post CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-owncloud-nuclear-data-breach-apac-philippines/
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as First…
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
Dark Web Service Nexus Sells 153M+ Driver’s Licenses
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New…
-
How AI Agents Expand the Identity Security Attack Surface
Why Autonomous Tools Can Execute Requests Humans Would Recognize as Unsafe. Menlo Security CEO Bill Robbins said AI agents can combine their own identities with users’ delegated credentials, requiring enterprises to govern both agent access and human authority to prevent malicious prompts from enabling data theft or other harmful actions. First seen on govinfosecurity.com Jump…
-
AI safety organization METR reports API key theft and credit misuse
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-safety-organization-metr-reports-api-key-theft-and-credit-misuse
-
METR discloses 2 security incidents, including $600,000 model credit theft
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-model-testing-org-discloses-two-security-incidents-including-600000-credit-theft
-
It sure looks like hackers breached a major ID card verification service
An identity theft search site claimed to have more than 150 million driver’s license photos stolen from an ID verification service. The crime site has now shut down. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-verification-service/
-
Wiz Finds Active LiteLLM and MCP Attacks Targeting AI Infrastructure
Wiz observed active attacks on LiteLLM and MCP servers, including credential theft, cryptomining, command execution, and prompt injection. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-litellm-mcp-server-attacks/
-
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign prioritizes long-term interactive access over direct cryptocurrency theft, combining hidden VNC, SOCKS proxying, file management and browser-data theft in an…

