Advertisement
Grafana GitHub Token Compromise: Codebase Stolen via PAT
Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
Microsoft Edge: Hardening Against Cleartext Password Exposure
Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.
Compromised Checkmarx Jenkins Plugin Spreads Infostealer
Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.
JDownloader Site Compromise: Python RAT Distribution Analysis
Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.
Advertisement
PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery
PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.
PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments
PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.
ShinyHunters Defaces Canvas Login Portals in Extortion Campaign
ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.
PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access
New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.
Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.
Google Ads Phishing Campaign Targets GoDaddy ManageWP Users
A persistent phishing campaign leverages malicious Google Ads to steal GoDaddy ManageWP credentials, risking extensive WordPress site compromises.
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs
Researchers identify CloudZ RAT and the Pheno plugin exploiting Windows Phone Link to bypass MFA by stealing one-time passwords from synchronized devices.
Stealthy Quasar Linux (QLNX) Malware Targets Developers
New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.
AitM Phishing Attacks Target US Organizations with Conduct Reports
Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.
Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide
Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.
Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users
Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.
Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure
Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.
AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet
A Vietnamese-linked operation dubbed AccountDumpling used Google AppSheet as a phishing relay to compromise 30,000 Facebook accounts for illicit resale.
US Security Experts Sentenced in REvil Ransomware Conspiracy
Two US security professionals were sentenced to prison for selling corporate credentials to the REvil ransomware gang, highlighting insider threat risks.
PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain
Threat actors injected malicious code into PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI, enabling credential theft via a supply chain attack.
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.
Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack
Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.