Advertisement
TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks
TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.
Supply Chain Attack: Bitwarden CLI npm Package Compromised
Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.
Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks
Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.
Python Infostealer Targeting Browser Credentials and Discord Tokens
Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.
AgingFly Malware: Credential Theft Operations Against Ukraine
Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…
Advertisement
Basic-Fit Data Breach: 1 Million Members Impacted by Credential Theft
Europe's largest gym chain, Basic-Fit, confirms a data breach impacting 1 million members. Attackers accessed names, DOBs, and IBANs via automated scripts.
Identity-First Zero Trust Strategies to Prevent Credential Theft
Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.
VIP Credential Monitoring: Defending High-Value Targets
Learn how VIP credential monitoring protects high-privilege users from account takeover by tracking exposures across personal and corporate email domains.
Storm Infostealer: Bypassing Local Decryption for Session Hijacking
Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.
FBI and Indonesia Dismantle W3LL Phishing Infrastructure
Law enforcement dismantles the W3LL phishing toolkit infrastructure responsible for $20M in fraud attempts and thousands of credential thefts globally.
Detecting Credential-Based Attacks: Moving Beyond Signatures
Identity-based attacks leverage valid credentials to mimic legitimate activity, requiring a shift toward behavioral detection and identity-centric monitoring.
VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins
Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.
APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers
Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…
UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets
New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.
APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins
Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.
CVE-2025-55182: Hackers Exploit React2Shell in Next.js Applications
Security researchers observe automated credential theft campaigns exploiting the React2Shell vulnerability (CVE-2025-55182) in vulnerable Next.js frameworks.
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.
DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation
DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.
Routine Access Powers Intrusions: VPNs & RMM Tools Abused
Blackpoint Cyber's report reveals modern intrusions leverage routine access via compromised credentials, VPN abuse, RMM tools, and social engineering, not exploits.
OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw
Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.
DeepLoad Malware Leverages AI for Evasion and Credential Theft
DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.
Telnyx PyPI Package Compromised by TeamPCP via Steganography
TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.