Tag: theft
-
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]…
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place…
-
New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access
Abyssos, a modular C++ remote-access trojan that combines credential theft, browser-session hijacking, file exfiltration and hidden VNC control in a single post-compromise framework. Technical analysis from ThreatLabz indicates that Abyssos is designed for hands-on intrusion activity rather than opportunistic, single-purpose theft. The most concerning feature is its hidden VNC capability. The HVNC_START command opens a…
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Emergency Incident Response investigators found the group abusing legitimate forensic utilities, including Volatility3 and WinPmem, to acquire memory and extract credential material…
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
Crypto thieves increasingly using physical attacks for virtual currency theft
First seen on scworld.com Jump to article: www.scworld.com/brief/crypto-thieves-increasingly-using-physical-attacks-for-virtual-currency-theft
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
-
Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
Tags: ai, attack, automation, breach, cyber, flaw, google, openai, rce, remote-code-execution, supply-chain, theft, tool, vulnerabilitySecurity researchers have disclosed a vulnerability affecting AI coding-agent workflows from Anthropic, Google, and OpenAI. Their research highlights how an attacker-controlled issue or zero-privilege input can breach trust boundaries in an agent “harness”, which includes the permissions, tools, sandbox, filesystem, and automation surrounding the model, and result in code execution, secret theft, or workflow compromise.…
-
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
-
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/
-
Zenity Labs Finds Zero-Click Attack Chains Across Agentic Browsers
Zenity Labs released research at Black Hat USA 2026 showing zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. The attacks demonstrated paths to silent data theft, credential theft, account takeover and remote control of a victim’s machine. PleaseFix abuses the way agentic browsers combine information..…
-
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect’s on-chain analysis puts the measured theft across two sweeps since late May at a lower bound…
-
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
Tags: credentials, cyber, data, infrastructure, injection, oracle, rce, remote-code-execution, sql, theft, threatKHunt shows how a “routine” SQL injection against an Oracle”‘backed web app can be weaponized into SYSTEM”‘level remote code execution and credential theft by compiling a full post”‘exploitation toolkit directly inside the database engine. This incident materially shifts the Oracle threat model: the database itself becomes attacker infrastructure, not just a data store. Subsequent triage…
-
Violent Physical Crypto Thefts Surge to $30m in Losses
So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/violent-physical-crypto-thefts/
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting an estimated 100 million individuals worldwide. Canadian Hacker Pleads Guilty According to…
-
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at…
-
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
-
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake. First seen on therecord.media Jump to article: therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka
-
Beacon CRM, Widely Used by Charities, Suffers Data Breach
English National Ballet is Among the Confirmed Victims Notifying Supporters. Cloud-based customer relationship management software provider Beacon CRM said it’s suffered a security breach that likely led to the theft of customer data. Over 1,000 charities use the software, and English National Ballet and the Centre for Sustainable Energy report they’ve been affected. First seen…
-
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896…
-
Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming
Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month. First seen on cyberscoop.com Jump to article: cyberscoop.com/opm-breach-lifetime-identity-protection-bill/
-
Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft
A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-coldcard-rng-flaw-bitcoin-theft/

