Tag: theft
-
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
First seen on scworld.com Jump to article: www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records
-
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
-
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Tags: ai, attack, cloud, control, credentials, cve, cyber, exploit, flaw, hacker, rce, remote-code-execution, theft, threat, vulnerabilityThreat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2) functions. VulnCheck researchers have reported exploitation targeting CVE-2026-0768 in Langflow, a low-code platform for building AI-powered applications and automated workflows. This vulnerability…
-
Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme
Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States. The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense…
-
Berlin refuses to be blackmailed after network breach
Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/berlin-data-breach-rhysida-ransomware/
-
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
-
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic’s Claude Opus 5. Instead a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation. The primary lure, branded “Claude Opus 5…
-
From a Stolen Login to a Ransomware Leak Site: What Our Telemetry Shows About the Path Threat Actors Take
A ransomware disclosure and a credential package we track from an entirely separate source, read side by side, illustrate a pattern our research team sees again and again: the quiet theft of a single login can be the first domino… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/from-a-stolen-login-to-a-ransomware-leak-site-what-our-telemetry-shows-about-the-path-threat-actors-take/
-
McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. First seen on cyberscoop.com Jump to article: cyberscoop.com/mckesson-data-theft-extortion-attack-shinyhunters/
-
ShinyHunters Threatens to Leak Millions of McKesson Records
Medical Products Supplier Reports Hack to SEC as Tuesday Data Leak Deadline Looms. Medical product and pharmaceutical distributor McKesson is the latest healthcare sector supplier responding to a recent data theft incident. Extortion gang ShinyHunters is threatening to leak 284 million records of sensitive McKesson data, including patient information, unless a ransom is paid. First…
-
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-thefts
-
How vulnerable are single sign-on systems to modern credential attacks
Secure your SSO with phishing-resistant MFA and continuous monitoring. Learn to mitigate risks like session theft and credential sprawl to protect identity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-vulnerable-are-single-sign-on-systems-to-modern-credential-attacks-2/
-
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
-
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-side checkout theft with EtherHiding, allowing attackers to conceal and rotate skimmer infrastructure through Ethereum’s Sepolia testnet. Because the malicious code is…
-
New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams
A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted development, browser credential theft, and aggressive persistence designed to survive incomplete remediation. The toolkit’s most unusual feature is its ability to collect evidence of how defenders removed its visible access and send that information back…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole…
-
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Tags: ai, cloud, credentials, cyber, data-breach, exploit, framework, infrastructure, injection, rce, remote-code-execution, service, theftAttackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,…
-
Breach Roundup: A Call for Cyber Defense Collective Action
e=4>This week: a call for cyber defense, OpenAI banned Russian ChatGPT accounts, critical Gitea flaw, U.K. airport passenger data theft, North Korean remote workers, Barcelona police data, Norway services hit by DDoS, Taiwan charged 9 over AI server exports and Nigeria advanced a sovereign cloud push. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. >>Two West…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/

