Skip to main content
← All Articles

Tag

#Credential Theft

173 articles

Advertisement

FortiBleed: FortiGate Firewalls Used as Credential Stealers
HIGH
Malware

FortiBleed: FortiGate Firewalls Used as Credential Stealers

Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.

Runtime Rebel Intel
4 min read · Jun 23, 2026
MongoBleed: Unauthenticated Credential Theft via Server Memory
HIGH
Vulnerabilities

MongoBleed: Unauthenticated Credential Theft via Server Memory

Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…

Runtime Rebel Intel
4 min read · Jun 17, 2026
Phantom Stealer: Fileless Credential Theft & Evasion
HIGH
Malware

Phantom Stealer: Fileless Credential Theft & Evasion

Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.

Runtime Rebel Intel
5 min read · Jun 17, 2026
MEDIUM
Threat Intel

FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation

The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.

Runtime Rebel Intel
4 min read · Jun 14, 2026
HIGH
Malware

Infostealers: Millions of Devices Compromised for Credential Theft

Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.

Runtime Rebel Intel
4 min read · Jun 11, 2026
HIGH
Malware

Python-Based Infostealer Masked as PDF Targets Browser Credentials

Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.

Runtime Rebel Intel
4 min read · Jun 9, 2026

Advertisement

MEDIUM
Supply Chain

Toshiba and Muji Impacted by Polyfill Supply Chain Attack

Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.

Runtime Rebel Intel
4 min read · Jun 6, 2026
INFO
Threat Intel

2026 Verizon DBIR Analysis: Securing the Browser Against Phishing

The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.

Runtime Rebel Intel
3 min read · Jun 5, 2026
FIFA World Cup 2026 Phishing: Fake Domains and Banking Malware
HIGH
Threat Intel

FIFA World Cup 2026 Phishing: Fake Domains and Banking Malware

The FBI and security researchers warn of FIFA World Cup 2026 scams involving thousands of lookalike domains and banking malware in pirate streaming apps.

Runtime Rebel Intel
3 min read · Jun 5, 2026
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
HIGH
Supply Chain

IronWorm: Rust-Written Malware Hits npm Supply Chain Developers

Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.

Runtime Rebel Intel
5 min read · Jun 5, 2026
HIGH
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read · Jun 2, 2026
Miasma Supply Chain Attack: Defending Red Hat npm Environments
HIGH
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read · Jun 1, 2026
HIGH
Threat Intel

Romanian Hacker Sentenced for Breach of Oregon Government Networks

Adrian-Tiberiu Oprea sentenced to 56 months for a multi-year cyber campaign targeting Oregon government systems and dozens of U.S. organizations.

Runtime Rebel Intel
4 min read · May 28, 2026
MEDIUM
Data Breach

Ajax Football Club Hack: Suspect Arrested in Almere Data Breach

Dutch police arrested a 35-year-old suspect linked to the AFC Ajax data breach involving the theft of sensitive personal data of players and staff.

Runtime Rebel Intel
4 min read · May 27, 2026
Megalodon Malware: GitHub Repo Compromise & Secret Theft
HIGH
Supply Chain

Megalodon Malware: GitHub Repo Compromise & Secret Theft

Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets.

Runtime Rebel Intel
4 min read · May 26, 2026
HIGH
Malware

ACR Stealer Distributed via Fake Claude AI Desktop Site

Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.

Runtime Rebel Intel
4 min read · May 26, 2026
HIGH
Supply Chain

Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories

Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.

Runtime Rebel Intel
4 min read · May 25, 2026
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
HIGH
Supply Chain

TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks

The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Supply Chain

Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags

Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.

Runtime Rebel Intel
4 min read · May 24, 2026
MEDIUM
Threat Intel

Canadian Man Arrested for Kimwolf Botnet Operations

Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.

Runtime Rebel Intel
4 min read · May 22, 2026
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read · May 20, 2026
HIGH
Threat Intel

DBIR 2026: Vulnerability Exploitation Now Top Breach Vector

Verizon's 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.

Runtime Rebel Intel
4 min read · May 20, 2026
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
HIGH
Supply Chain

GitHub Actions Supply Chain Attack: actions-cool/issues-helper

Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
3 min read · May 19, 2026
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
HIGH
Vulnerabilities

OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence

Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.

Runtime Rebel Intel
4 min read · May 19, 2026