Skip to main content
← All Articles

Tag

#Credential Theft

173 articles

Advertisement

HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read · Apr 27, 2026
HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read · Apr 23, 2026
Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks
HIGH
Threat Intel

Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks

Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.

Runtime Rebel Intel
3 min read · Apr 21, 2026
HIGH
Malware

Python Infostealer Targeting Browser Credentials and Discord Tokens

Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
MEDIUM
Supply Chain

Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure

Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.

Runtime Rebel Intel
4 min read · Apr 20, 2026
HIGH
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…

Runtime Rebel Intel
5 min read · Apr 16, 2026

Advertisement

HIGH
Data Breach

Basic-Fit Data Breach: 1 Million Members Impacted by Credential Theft

Europe's largest gym chain, Basic-Fit, confirms a data breach impacting 1 million members. Attackers accessed names, DOBs, and IBANs via automated scripts.

Runtime Rebel Intel
3 min read · Apr 14, 2026
INFO
Identity & Access

Identity-First Zero Trust Strategies to Prevent Credential Theft

Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.

Runtime Rebel Intel
3 min read · Apr 14, 2026
VIP Credential Monitoring: Defending High-Value Targets
MEDIUM
Identity & Access

VIP Credential Monitoring: Defending High-Value Targets

Learn how VIP credential monitoring protects high-privilege users from account takeover by tracking exposures across personal and corporate email domains.

Runtime Rebel Intel
3 min read · Apr 13, 2026
HIGH
Malware

Storm Infostealer: Bypassing Local Decryption for Session Hijacking

Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.

Runtime Rebel Intel
3 min read · Apr 13, 2026
FBI and Indonesia Dismantle W3LL Phishing Infrastructure
MEDIUM
Threat Intel

FBI and Indonesia Dismantle W3LL Phishing Infrastructure

Law enforcement dismantles the W3LL phishing toolkit infrastructure responsible for $20M in fraud attempts and thousands of credential thefts globally.

Runtime Rebel Intel
4 min read · Apr 13, 2026
Detecting Credential-Based Attacks: Moving Beyond Signatures
MEDIUM
Identity & Access

Detecting Credential-Based Attacks: Moving Beyond Signatures

Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.

Runtime Rebel Intel
3 min read · Apr 10, 2026
HIGH
Threat Intel

VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins

Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.

Runtime Rebel Intel
4 min read · Apr 10, 2026
APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers
CRITICAL
Threat Intel

APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers

Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…

Runtime Rebel Intel
5 min read · Apr 9, 2026
HIGH
Threat Intel

UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets

New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.

Runtime Rebel Intel
4 min read · Apr 9, 2026
HIGH
Threat Intel

APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins

Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.

Runtime Rebel Intel
5 min read · Apr 7, 2026
HIGH
Vulnerabilities

CVE-2025-55182: Hackers Exploit React2Shell in Next.js Applications

Security researchers observe automated credential theft campaigns exploiting the React2Shell vulnerability (CVE-2025-55182) in vulnerable Next.js frameworks.

Runtime Rebel Intel
3 min read · Apr 5, 2026
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
HIGH
Threat Intel

CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets

Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.

Runtime Rebel Intel
3 min read · Apr 3, 2026
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Threat Intel

Routine Access Powers Intrusions: VPNs & RMM Tools Abused

Blackpoint Cyber's report reveals modern intrusions leverage routine access via compromised credentials, VPN abuse, RMM tools, and social engineering, not exploits.

Runtime Rebel Intel
5 min read · Apr 1, 2026
HIGH
Identity & Access

OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw

Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.

Runtime Rebel Intel
4 min read · Mar 31, 2026
DeepLoad Malware Leverages AI for Evasion and Credential Theft
HIGH
Malware

DeepLoad Malware Leverages AI for Evasion and Credential Theft

DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Mar 31, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
5 min read · Mar 30, 2026
Telnyx PyPI Package Compromised by TeamPCP via Steganography
HIGH
Supply Chain

Telnyx PyPI Package Compromised by TeamPCP via Steganography

TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.

Runtime Rebel Intel
4 min read · Mar 27, 2026