Skip to main content
← All Articles

Tag

#credential-harvesting

10 articles

Advertisement

TH
MEDIUM
Threat Intel

Bluekit Phishing Kit: AI Integration and Automated Deployment

The Bluekit phishing kit uses an AI assistant and automated domain registration to simplify credential harvesting against financial and logistics sectors.

Runtime Rebel Intel
3 min read·May 2, 2026
TH
HIGH
Threat Intel

Telegram tdata Credential Harvesting: Risks and Mitigation Strategies

Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.

Runtime Rebel Intel
3 min read·Apr 22, 2026
DA
HIGH
Data Breach

McGraw Hill Data Breach: 13.5 Million Accounts Leaked by ShinyHunters

Threat actor ShinyHunters leaks 13.5 million McGraw Hill user records following a Salesforce environment breach. Includes password hashes and PII.

Runtime Rebel Intel
4 min read·Apr 16, 2026
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
HIGH
Supply Chain

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud

TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.

Runtime Rebel Intel
4 min read·Apr 15, 2026
ID
HIGH
Identity & Access

Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers

Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.

Runtime Rebel Intel
3 min read·Apr 6, 2026
SU
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read·Apr 6, 2026
TH
MEDIUM
Threat Intel

Dutch Police Phishing Breach Exposes Internal Contact Data

The Dutch National Police (Politie) confirms a security breach after a phishing attack exposed work contact details for 65,000 police department employees.

Runtime Rebel Intel
4 min read·Mar 27, 2026
TH
MEDIUM
Threat Intel

Security Firm Executive Targeted via DKIM-Signed Phishing

A sophisticated phishing campaign bypassed security filters using DKIM-signed emails and Cloudflare-protected landing pages to target a security executive.

Runtime Rebel Intel
3 min read·Mar 16, 2026
TH
HIGH
Threat Intel

Romanian National Pleads Guilty to Initial Access Brokerage Targeting Oregon State Infrastructure

Catalin Dragomir admitted to harvesting and selling unauthorized administrative credentials for an Oregon state government network, highlighting the persistent threat of Initial Access Brokers (IABs).

Runtime Rebel Intel
2 min read·Feb 23, 2026
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
HIGH
Supply Chain

SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft

Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private cryptocurrency keys.

Runtime Rebel Intel
2 min read·Feb 23, 2026