Skip to main content
← All Articles

Tag

#Credential Theft

173 articles

Advertisement

HIGH
Supply Chain

Grafana GitHub Token Compromise: Codebase Stolen via PAT

Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.

Runtime Rebel Intel
3 min read · May 18, 2026
Developer Workstations: The New Front in Software Supply Chain Attacks
HIGH
Supply Chain

Developer Workstations: The New Front in Software Supply Chain Attacks

A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.

Runtime Rebel Intel
4 min read · May 18, 2026
INFO
Threat Intel

Microsoft Edge: Hardening Against Cleartext Password Exposure

Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.

Runtime Rebel Intel
4 min read · May 15, 2026
HIGH
Supply Chain

Compromised Checkmarx Jenkins Plugin Spreads Infostealer

Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.

Runtime Rebel Intel
4 min read · May 12, 2026
HIGH
Supply Chain

JDownloader Site Compromise: Python RAT Distribution Analysis

Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · May 9, 2026
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
HIGH
Malware

Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks

A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.

Runtime Rebel Intel
4 min read · May 8, 2026

Advertisement

PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery
HIGH
Cloud Security

PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery

PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.

Runtime Rebel Intel
3 min read · May 8, 2026
HIGH
Malware

PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments

PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.

Runtime Rebel Intel
4 min read · May 8, 2026
HIGH
Threat Intel

ShinyHunters Defaces Canvas Login Portals in Extortion Campaign

ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.

Runtime Rebel Intel
5 min read · May 8, 2026
HIGH
Malware

PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access

New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.

Runtime Rebel Intel
4 min read · May 7, 2026
Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
CRITICAL
Threat Intel

Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks

Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.

Runtime Rebel Intel
3 min read · May 7, 2026
HIGH
Threat Intel

Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

A persistent phishing campaign leverages malicious Google Ads to steal GoDaddy ManageWP credentials, risking extensive WordPress site compromises.

Runtime Rebel Intel
4 min read · May 7, 2026
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs
HIGH
Threat Intel

CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Researchers identify CloudZ RAT and the Pheno plugin exploiting Windows Phone Link to bypass MFA by stealing one-time passwords from synchronized devices.

Runtime Rebel Intel
4 min read · May 6, 2026
HIGH
Malware

Stealthy Quasar Linux (QLNX) Malware Targets Developers

New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.

Runtime Rebel Intel
5 min read · May 6, 2026
MEDIUM
Threat Intel

AitM Phishing Attacks Target US Organizations with Conduct Reports

Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.

Runtime Rebel Intel
3 min read · May 5, 2026
MEDIUM
Vulnerabilities

Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide

Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.

Runtime Rebel Intel
4 min read · May 5, 2026
Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users
HIGH
Threat Intel

Credential Theft: Microsoft Details Phishing Campaign Targeting 35k Users

Microsoft warns of a global phishing campaign targeting 35,000 users with code-of-conduct lures to steal authentication tokens across 13,000 organizations.

Runtime Rebel Intel
4 min read · May 5, 2026
MEDIUM
Threat Intel

Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure

Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.

Runtime Rebel Intel
4 min read · May 4, 2026
AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet
HIGH
Threat Intel

AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet

A Vietnamese-linked operation dubbed AccountDumpling used Google AppSheet as a phishing relay to compromise 30,000 Facebook accounts for illicit resale.

Runtime Rebel Intel
4 min read · May 1, 2026
HIGH
Threat Intel

US Security Experts Sentenced in REvil Ransomware Conspiracy

Two US security professionals were sentenced to prison for selling corporate credentials to the REvil ransomware gang, highlighting insider threat risks.

Runtime Rebel Intel
3 min read · May 1, 2026
PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain
HIGH
Supply Chain

PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain

Threat actors injected malicious code into PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI, enabling credential theft via a supply chain attack.

Runtime Rebel Intel
5 min read · Apr 30, 2026
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
HIGH
Malware

New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials

DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.

Runtime Rebel Intel
4 min read · Apr 30, 2026
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Apr 30, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026