Skip to main content
← All Articles

Tag

#credential-theft

32 articles

Advertisement

2025 Identity Threat Report: Analyzing the Infostealer Economy
HIGH
Identity & Access

2025 Identity Threat Report: Analyzing the Infostealer Economy

Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.

Runtime Rebel Intel
3 min read·Mar 16, 2026
TH
MEDIUM
Threat Intel

Phishing Credential Exfiltration via EmailJS and React Frameworks

Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.

Runtime Rebel Intel
3 min read·Mar 13, 2026
FortiGate NGFW Exploitation Leads to Service Account Credential Theft
HIGH
Vulnerabilities

FortiGate NGFW Exploitation Leads to Service Account Credential Theft

Threat actors are exploiting FortiGate devices to extract configuration files and steal service account credentials, facilitating lateral movement in networks.

Runtime Rebel Intel
3 min read·Mar 10, 2026
TH
HIGH
Threat Intel

LastPass Phishing Campaign Targets Master Passwords via Fake Alerts

LastPass warns of a new phishing campaign using fraudulent security alerts to steal master passwords. Learn how to identify and mitigate these vault threats.

Runtime Rebel Intel
4 min read·Mar 4, 2026
DA
HIGH
Data Breach

Canadian Tire Data Breach Impacts 38 Million Accounts

Canadian Tire confirms a massive data breach affecting 38 million customer accounts, exposing PII and encrypted passwords. Analysis of security risks.

Runtime Rebel Intel
4 min read·Feb 28, 2026
Malicious StripeApi.Net NuGet Package Targets Financial API Tokens
HIGH
Supply Chain

Malicious StripeApi.Net NuGet Package Targets Financial API Tokens

Researchers identify a typosquatting NuGet package, StripeApi.Net, designed to mimic official Stripe libraries and exfiltrate sensitive financial API keys.

Runtime Rebel Intel
4 min read·Feb 26, 2026
TH
HIGH
Threat Intel

Starkiller Phishing-as-a-Service: Technical Analysis of Adversary-in-the-Middle Frameworks

An examination of the Starkiller phishing platform, which employs transparent reverse proxy techniques to relay authentication traffic and capture multi-factor authentication (MFA) tokens in real-time.

Runtime Rebel Intel
2 min read·Feb 23, 2026
MA
MEDIUM
Malware

Arkanix Stealer: Analysis of AI-Assisted Infostealer Development Patterns

A technical evaluation of the Arkanix Stealer operation, highlighting its AI-driven code characteristics and credential-harvesting capabilities.

Runtime Rebel Intel
2 min read·Feb 23, 2026