<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Credential Harvesting</title><description>Cybersecurity articles tagged #Credential Harvesting on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Man Sentenced for Hacking 750 Snapchat Accounts via Phishing</title><link>https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</guid><description>Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.</description><pubDate>Fri, 24 Jul 2026 13:50:49 GMT</pubDate><category>Snapchat</category><category>Credential Harvesting</category><category>Identity Theft</category><category>Social Engineering</category></item><item><title>ARToken PhaaS Exposes EvilTokens&apos; M365 Phishing Toolkit</title><link>https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</link><guid isPermaLink="true">https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</guid><description>ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.</description><pubDate>Fri, 03 Jul 2026 17:28:05 GMT</pubDate><category>ARToken</category><category>EvilTokens</category><category>PhaaS</category><category>Phishing</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Credential Harvesting</category><category>Threat Intelligence</category></item><item><title>Metamask Phishing Campaign Targets Secret Recovery Phrases</title><link>https://runtimerebel.com/blog/metamask-phishing-campaign-targets-secret-recovery-phrases</link><guid isPermaLink="true">https://runtimerebel.com/blog/metamask-phishing-campaign-targets-secret-recovery-phrases</guid><description>Threat actors are targeting Metamask users with phishing emails designed to harvest Secret Recovery Phrases, leading to the total loss of cryptocurrency assets.</description><pubDate>Wed, 01 Jul 2026 09:23:12 GMT</pubDate><category>Metamask</category><category>Cryptocurrency</category><category>Phishing Campaign</category><category>Seed Phrase Theft</category><category>Credential Harvesting</category></item><item><title>FortiBleed: 110 Million Credentials Harvested via FortiGate Firewalls</title><link>https://runtimerebel.com/blog/fortibleed-110-million-credentials-harvested-via-fortigate-firewalls</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-110-million-credentials-harvested-via-fortigate-firewalls</guid><description>Russian-speaking threat actors harvest 110 million credentials from 430,000 FortiGate firewalls globally. Learn to detect and mitigate FortiBleed tactics.</description><pubDate>Tue, 23 Jun 2026 20:49:19 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Credential Harvesting</category><category>Initial Access Broker</category><category>Firewall Security</category></item><item><title>Fortinet FortiBleed Campaign: 86,000+ VPN Credentials Stolen</title><link>https://runtimerebel.com/blog/fortinet-fortibleed-campaign-86000-vpn-credentials-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-fortibleed-campaign-86000-vpn-credentials-stolen</guid><description>Fortinet addresses the FortiBleed campaign involving 86,000+ confirmed working credentials. Technical analysis and mitigation steps for security professionals.</description><pubDate>Mon, 22 Jun 2026 10:16:29 GMT</pubDate><category>Fortinet</category><category>Fortios</category><category>FortiBleed</category><category>Credential Harvesting</category><category>VPN Security</category></item><item><title>eBanking Phishing Using IPv4-Mapped IPv6 Addresses Detected</title><link>https://runtimerebel.com/blog/ebanking-phishing-using-ipv4-mapped-ipv6-addresses-detected</link><guid isPermaLink="true">https://runtimerebel.com/blog/ebanking-phishing-using-ipv4-mapped-ipv6-addresses-detected</guid><description>Analysis of a sophisticated eBanking phishing campaign targeting a major Belgian bank, leveraging IPv4-mapped IPv6 addresses for obfuscation.</description><pubDate>Fri, 19 Jun 2026 09:53:08 GMT</pubDate><category>Phishing</category><category>eBanking</category><category>IPv6</category><category>Email Spoofing</category><category>Credential Harvesting</category><category>Belgium</category></item><item><title>Credential Harvesting Heist Compromises 30K+ Fortinet Devices</title><link>https://runtimerebel.com/blog/credential-harvesting-heist-compromises-30k-fortinet-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-harvesting-heist-compromises-30k-fortinet-devices</guid><description>A widespread credential harvesting campaign has compromised over 30,000 Fortinet devices across 200 countries, enabling unauthorized access for threat actors.</description><pubDate>Wed, 17 Jun 2026 13:29:46 GMT</pubDate><category>Fortinet</category><category>Credential Harvesting</category><category>Cyberattack</category><category>Data Breach</category></item><item><title>Bluekit Phishing Kit: AI Integration and Automated Deployment</title><link>https://runtimerebel.com/blog/bluekit-phishing-kit-ai-integration-and-automated-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluekit-phishing-kit-ai-integration-and-automated-deployment</guid><description>The Bluekit phishing kit uses an AI assistant and automated domain registration to simplify credential harvesting against financial and logistics sectors.</description><pubDate>Sat, 02 May 2026 12:24:45 GMT</pubDate><category>Bluekit</category><category>Phishing Kit</category><category>AI Driven Attacks</category><category>Credential Harvesting</category><category>Social Engineering</category></item><item><title>Telegram tdata Credential Harvesting: Risks and Mitigation Strategies</title><link>https://runtimerebel.com/blog/telegram-tdata-credential-harvesting-risks-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/telegram-tdata-credential-harvesting-risks-and-mitigation-strategies</guid><description>Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.</description><pubDate>Wed, 22 Apr 2026 08:47:07 GMT</pubDate><category>Telegram Desktop</category><category>Credential Harvesting</category><category>Tdata Exploitation</category><category>Session Hijacking</category></item><item><title>McGraw Hill Data Breach: 13.5 Million Accounts Leaked by ShinyHunters</title><link>https://runtimerebel.com/blog/mcgraw-hill-data-breach-13-5-million-accounts-leaked-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/mcgraw-hill-data-breach-13-5-million-accounts-leaked-by-shinyhunters</guid><description>Threat actor ShinyHunters leaks 13.5 million McGraw Hill user records following a Salesforce environment breach. Includes password hashes and PII.</description><pubDate>Thu, 16 Apr 2026 12:33:08 GMT</pubDate><category>McGraw Hill</category><category>ShinyHunters</category><category>Salesforce Breach</category><category>Data Leak</category><category>Credential Harvesting</category></item><item><title>TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-from-credential-theft-to-payroll-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-from-credential-theft-to-payroll-fraud</guid><description>TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.</description><pubDate>Wed, 15 Apr 2026 16:30:57 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Credential Harvesting</category><category>Payroll Fraud</category><category>Financial Crime</category></item><item><title>APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting</title><link>https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</guid><description>China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.</description><pubDate>Mon, 13 Apr 2026 16:35:11 GMT</pubDate><category>APT41</category><category>Cloud Security</category><category>Credential Harvesting</category><category>AWS</category><category>Azure</category><category>Backdoor</category></item><item><title>Identity-Based Attacks: Why Breach Monitoring Fails to Stop Infostealers</title><link>https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-based-attacks-why-breach-monitoring-fails-to-stop-infostealers</guid><description>Infostealers are bypassing MFA by harvesting session cookies. Learn why traditional breach monitoring is insufficient and how to secure identity perimeters.</description><pubDate>Mon, 06 Apr 2026 16:21:46 GMT</pubDate><category>Infostealers</category><category>Session Hijacking</category><category>Credential Harvesting</category><category>MFA Bypass</category></item><item><title>Guardarian Users Targeted via 36 Malicious Strapi npm Packages</title><link>https://runtimerebel.com/blog/guardarian-users-targeted-via-36-malicious-strapi-npm-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/guardarian-users-targeted-via-36-malicious-strapi-npm-packages</guid><description>Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.</description><pubDate>Mon, 06 Apr 2026 12:24:18 GMT</pubDate><category>Strapi</category><category>NPM</category><category>Guardarian</category><category>Supply Chain Attack</category><category>Credential Harvesting</category></item><item><title>Dutch Police Phishing Breach Exposes Internal Contact Data</title><link>https://runtimerebel.com/blog/dutch-police-phishing-breach-exposes-internal-contact-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/dutch-police-phishing-breach-exposes-internal-contact-data</guid><description>The Dutch National Police (Politie) confirms a security breach after a phishing attack exposed work contact details for 65,000 police department employees.</description><pubDate>Fri, 27 Mar 2026 08:21:12 GMT</pubDate><category>Phishing</category><category>Politie</category><category>Credential Harvesting</category><category>Data Breach</category><category>Public Sector</category></item><item><title>Security Firm Executive Targeted via DKIM-Signed Phishing</title><link>https://runtimerebel.com/blog/security-firm-executive-targeted-via-dkim-signed-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-firm-executive-targeted-via-dkim-signed-phishing</guid><description>A sophisticated phishing campaign bypassed security filters using DKIM-signed emails and Cloudflare-protected landing pages to target a security executive.</description><pubDate>Mon, 16 Mar 2026 16:29:47 GMT</pubDate><category>Phishing</category><category>DKIM</category><category>Cloudflare</category><category>Executive Targeting</category><category>Credential Harvesting</category></item><item><title>Romanian National Pleads Guilty to Initial Access Brokerage Targeting Oregon State Infrastructure</title><link>https://runtimerebel.com/blog/romanian-national-pleads-guilty-to-initial-access-brokerage-targeting-oregon-state-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/romanian-national-pleads-guilty-to-initial-access-brokerage-targeting-oregon-state-infrastructure</guid><description>Catalin Dragomir admitted to harvesting and selling unauthorized administrative credentials for an Oregon state government network, highlighting the persistent threat…</description><pubDate>Mon, 23 Feb 2026 12:21:04 GMT</pubDate><category>IAB</category><category>Credential Harvesting</category><category>Initial Access Broker</category><category>Oregon State</category></item><item><title>SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft</title><link>https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</guid><description>Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…</description><pubDate>Mon, 23 Feb 2026 12:20:23 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Credential Harvesting</category><category>CI CD Security</category><category>JavaScript</category></item></channel></rss>