Skip to main content
← All Articles

Tag

#Credential Theft

40 articles

Advertisement

SU
HIGH
Supply Chain

Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories

Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.

Runtime Rebel Intel
3 min read·May 25, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read·May 20, 2026
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
HIGH
Vulnerabilities

OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence

Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks. Patching guidance

Runtime Rebel Intel
4 min read·May 19, 2026
SU
HIGH
Supply Chain

Compromised Checkmarx Jenkins Plugin Spreads Infostealer

Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data. Immediate uninstallation and credential

Runtime Rebel Intel
4 min read·May 12, 2026
MA
HIGH
Malware

PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments

PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.

Runtime Rebel Intel
3 min read·May 8, 2026
TH
HIGH
Threat Intel

ShinyHunters Defaces Canvas Login Portals in Extortion Campaign

ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.

Runtime Rebel Intel
5 min read·May 8, 2026
TH
HIGH
Threat Intel

Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

A persistent phishing campaign leverages malicious Google Ads to steal GoDaddy ManageWP credentials, risking extensive WordPress site compromises.

Runtime Rebel Intel
4 min read·May 7, 2026
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs
HIGH
Threat Intel

CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Researchers identify CloudZ RAT and the Pheno plugin exploiting Windows Phone Link to bypass MFA by stealing one-time passwords from synchronized devices.

Runtime Rebel Intel
4 min read·May 6, 2026
TH
MEDIUM
Threat Intel

Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure

Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.

Runtime Rebel Intel
4 min read·May 4, 2026
SU
HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read·Apr 23, 2026
MA
CRITICAL
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and

Runtime Rebel Intel
5 min read·Apr 16, 2026
DA
HIGH
Data Breach

Basic-Fit Data Breach: 1 Million Members Impacted by Credential Theft

Europe's largest gym chain, Basic-Fit, confirms a data breach impacting 1 million members. Attackers accessed names, DOBs, and IBANs via automated scripts.

Runtime Rebel Intel
3 min read·Apr 14, 2026