Tag: theft
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/25/that-fake-grand-theft-auto-vi-demo-is-actually-just-malware/
-
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey…
-
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but instead deliver the Vidar information stealer. The campaign targets browser credentials, session cookies, and other profile data that can let attackers access accounts even after victims change their passwords. The…
-
AnMed Confirms Data Theft, Warns Patients of Criminal Scams
Ransomware Gang Gentlemen Says It Stole 6TB of Sensitive Patient Info. Nonprofit health system AnMed has confirmed cybercriminals stole information in a July cyberattack that disrupted its IT environment and patient services for several weeks. The organization is also warning patients not to fall for potential fraud, payment and other scams by criminals. First seen…
-
Tricky ‘SynkLoader’ Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear, screen hijacking, for effective password theft, along with a slew of novel features. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware
-
US Charges 17 Iranian Hackers Over Theft of 31.5TB of Academic Data
US prosecutors charge 17 Iranians hackers over an alleged campaign that stole 31.5TB of research and targeted universities, companies and government agencies worldwide. First seen on hackread.com Jump to article: hackread.com/us-charges-iranian-hackers-theft-31b-academic-data/
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Hardening GitHub Actions against pwn requests and token theft
GitHub Actions is a useful automation layer for build, test, release, and operational tasks, but it also creates a new trust boundary. If a workflow is too permissive, an attacker who can influence a pull request, a third-party action, or a runner environment may be able to steal tokens, read secrets, or alter build outputs….…
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructions as AES-encrypted ciphertext and tricking the model into decrypting them inside its own code execution runtime.…
-
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
Tags: access, cloud, corporate, credentials, cyber, data, data-breach, iam, infrastructure, risk, theftA large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed…
-
MLflow Flaw Opens a Path to Cloud Credentials Theft
CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation. Attackers are exploiting a flaw in exposed MLflow servers to reach systems that are normally closed to the internet. The bug may reveal cloud credentials without requiring a login. CISA has not disclosed the victims, attackers or results of the intrusions. First seen on govinfosecurity.com…
-
Critical Patches, AI-Driven Attacks, and Data Theft Define the Week in August 2026
Weekly summary of Cybersecurity Insider newsletters in August 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/critical-patches-ai-driven-attacks-and-data-theft-define-the-week-in-august-2026/
-
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children, which was hit in a ransomware incident in 2022 that disabled some of its systems, released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application. First seen on therecord.media Jump to article: therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Network of 77 Firefox extensions linked to crypto theft uncovered
First seen on scworld.com Jump to article: www.scworld.com/brief/network-of-77-firefox-extensions-linked-to-crypto-theft-uncovered
-
Cryptohack Roundup: Harmony’s Post-Exploit Blockchain Rollback
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero. First…
-
Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/machine-speed-credential-abuse-what-the-chaindrop-npm-worm-changes/
-
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate, and supporters say it could help fight cybercrime. First seen on cyberscoop.com Jump to article: cyberscoop.com/corca-retail-theft-bill-ice-surveillance/
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as >>CRLF-Powered Desync Attacks.<< This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to full account takeovers, theft of HTTPOnly cookies, and even the creation of self-propagating desync worms.…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed…
-
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/
-
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that…
-
US charges 17 Iranian hackers over 31-terabyte academic data theft
The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/us-iranian-hackers-mabna-institute-charged/
-
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application encrypts it locally. The activity is part of a larger operation, provisionally tracked as “Offside Wallet Theft Factory,” which links 77 Firefox extension identities through cloned code, reused infrastructure, deceptive listings, stable add-on IDs,…

