Skip to main content
← All Articles

Tag

#Credential Theft

173 articles

Advertisement

Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
HIGH
Data Breach

Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws

Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.

Runtime Rebel Intel
3 min read · Sep 2, 2026
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
INFO
Threat Intel

Threat Actors Prefer Repeatable Playbooks Over Novel Exploits

Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.

Runtime Rebel Intel
3 min read · Sep 1, 2026
LOW
Threat Intel

Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws

Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.

Runtime Rebel Intel
3 min read · Sep 1, 2026
HIGH
Threat Intel

Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets

Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Infostealers Target Anthropic Claude Users via Session Theft
HIGH
Data Breach

Infostealers Target Anthropic Claude Users via Session Theft

Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
MEDIUM
Threat Intel

ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing

ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.

Runtime Rebel Intel
4 min read · Aug 25, 2026

Advertisement

SynkLoader Multitool Malware Employs Screen Hijacking
MEDIUM
Malware

SynkLoader Multitool Malware Employs Screen Hijacking

SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.

Runtime Rebel Intel
2 min read · Aug 24, 2026
MEDIUM
Malware

ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.

Runtime Rebel Intel
3 min read · Aug 23, 2026
Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage
MEDIUM
Threat Intel

Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage

Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.

Runtime Rebel Intel
3 min read · Aug 23, 2026
MEDIUM
Threat Intel

iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence

Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.

Runtime Rebel Intel
3 min read · Aug 23, 2026
HIGH
Malware

SynkLoader Malware Steals Credentials in Microsoft Teams Phishing

New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.

Runtime Rebel Intel
4 min read · Aug 22, 2026
HIGH
Cloud Security

Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts

Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.

Runtime Rebel Intel
3 min read · Aug 21, 2026
Identity Abuse and Phishing via Enterprise Collaboration Platforms
MEDIUM
Threat Intel

Identity Abuse and Phishing via Enterprise Collaboration Platforms

Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.

Runtime Rebel Intel
3 min read · Aug 20, 2026
MEDIUM
Threat Intel

Russian Threat Clusters Target Academia and Government via Auth Abuse

Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.

Runtime Rebel Intel
3 min read · Aug 20, 2026
HIGH
Threat Intel

SSRF Scans Target Cloud Metadata Service for Credential Access

Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.

Runtime Rebel Intel
4 min read · Aug 19, 2026
Mitigating Large-Scale Credential Attacks and Password Spraying
HIGH
Threat Intel

Mitigating Large-Scale Credential Attacks and Password Spraying

Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.

Runtime Rebel Intel
2 min read · Aug 19, 2026
HIGH
Data Breach

Threat Actor Claims 3.6 Million Azure Account Records Stolen

A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.

Runtime Rebel Intel
3 min read · Aug 18, 2026
HIGH
Threat Intel

Public Wi-Fi DNS Hijacking: Credential Theft Risk

Criminals are actively manipulating public Wi-Fi DNS settings to redirect users to fake login pages, stealing sensitive credentials. Learn how to protect yourself.

Runtime Rebel Intel
4 min read · Aug 17, 2026
Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft
HIGH
Malware

Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft

Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.

Runtime Rebel Intel
3 min read · Aug 17, 2026
MEDIUM
Malware

Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays

A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.

Runtime Rebel Intel
3 min read · Aug 15, 2026
MEDIUM
Data Breach

Data Analyst Sentenced to Prison for Extorting Brightly Software

A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.

Runtime Rebel Intel
4 min read · Aug 14, 2026
Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise
INFO
Threat Intel

Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise

Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.

Runtime Rebel Intel
3 min read · Aug 14, 2026
JWR Phishing Framework: Real-time Data Theft via PhaaS
HIGH
Malware

JWR Phishing Framework: Real-time Data Theft via PhaaS

The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Data Breach

City-Forum Data Theft Targets Salesforce and ServiceNow Portals

City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.

Runtime Rebel Intel
3 min read · Aug 13, 2026