Advertisement
FortiBleed: FortiGate Firewalls Used as Credential Stealers
Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.
MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…
Phantom Stealer: Fileless Credential Theft & Evasion
Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.
FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation
The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.
Infostealers: Millions of Devices Compromised for Credential Theft
Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.
Python-Based Infostealer Masked as PDF Targets Browser Credentials
Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.
Advertisement
Toshiba and Muji Impacted by Polyfill Supply Chain Attack
Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.
2026 Verizon DBIR Analysis: Securing the Browser Against Phishing
The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.
FIFA World Cup 2026 Phishing: Fake Domains and Banking Malware
The FBI and security researchers warn of FIFA World Cup 2026 scams involving thousands of lookalike domains and banking malware in pirate streaming apps.
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.
Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials
Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.
Miasma Supply Chain Attack: Defending Red Hat npm Environments
Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.
Romanian Hacker Sentenced for Breach of Oregon Government Networks
Adrian-Tiberiu Oprea sentenced to 56 months for a multi-year cyber campaign targeting Oregon government systems and dozens of U.S. organizations.
Ajax Football Club Hack: Suspect Arrested in Almere Data Breach
Dutch police arrested a 35-year-old suspect linked to the AFC Ajax data breach involving the theft of sensitive personal data of players and staff.
Megalodon Malware: GitHub Repo Compromise & Secret Theft
Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets.
ACR Stealer Distributed via Fake Claude AI Desktop Site
Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.
Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.
Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags
Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.
Canadian Man Arrested for Kimwolf Botnet Operations
Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.
GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension
GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.
DBIR 2026: Vulnerability Exploitation Now Top Breach Vector
Verizon's 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft.
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.