<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Credential Theft</title><description>Cybersecurity articles tagged #Credential Theft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws</title><link>https://runtimerebel.com/blog/philippines-nuclear-agency-breached-via-unpatched-owncloud-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/philippines-nuclear-agency-breached-via-unpatched-owncloud-flaws</guid><description>Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.</description><pubDate>Wed, 02 Sep 2026 02:00:51 GMT</pubDate><category>ownCloud</category><category>Data Breach</category><category>Credential Theft</category><category>Vulnerability</category><category>Philippines</category></item><item><title>Threat Actors Prefer Repeatable Playbooks Over Novel Exploits</title><link>https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</guid><description>Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.</description><pubDate>Tue, 01 Sep 2026 12:54:04 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws</title><link>https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</guid><description>Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.</description><pubDate>Tue, 01 Sep 2026 02:51:10 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Obfuscation</category><category>JavaScript</category><category>Malware Analysis</category></item><item><title>Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets</title><link>https://runtimerebel.com/blog/chinese-speaking-operators-target-philippine-nuclear-and-naval-assets</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-speaking-operators-target-philippine-nuclear-and-naval-assets</guid><description>Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.</description><pubDate>Tue, 01 Sep 2026 02:44:13 GMT</pubDate><category>ownCloud</category><category>WordPress</category><category>WebDAV</category><category>Credential Theft</category><category>Military Intelligence</category></item><item><title>Infostealers Target Anthropic Claude Users via Session Theft</title><link>https://runtimerebel.com/blog/infostealers-target-anthropic-claude-users-via-session-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/infostealers-target-anthropic-claude-users-via-session-theft</guid><description>Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.</description><pubDate>Tue, 01 Sep 2026 02:42:19 GMT</pubDate><category>Infostealer</category><category>Session Theft</category><category>Anthropic</category><category>Claude</category><category>Credential Theft</category></item><item><title>ShinyHunters Breaches ReliaQuest Identity Dashboard via Phishing</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-reliaquest-identity-dashboard-via-phishing</guid><description>ReliaQuest confirms ShinyHunters gained brief, view-only access to its identity dashboard via a sophisticated social engineering attack.</description><pubDate>Tue, 25 Aug 2026 00:41:55 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Credential Theft</category><category>Okta</category></item><item><title>SynkLoader Multitool Malware Employs Screen Hijacking</title><link>https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</guid><description>SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.</description><pubDate>Mon, 24 Aug 2026 16:27:26 GMT</pubDate><category>Malware</category><category>Ransomware</category><category>Credential Theft</category><category>SynkLoader</category></item><item><title>ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN</title><link>https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</link><guid isPermaLink="true">https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</guid><description>ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.</description><pubDate>Sun, 23 Aug 2026 16:15:53 GMT</pubDate><category>ToxicPanda</category><category>Android</category><category>Malware</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage</title><link>https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</guid><description>Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.</description><pubDate>Sun, 23 Aug 2026 16:14:39 GMT</pubDate><category>APT29</category><category>Phishing</category><category>OAuth</category><category>Credential Theft</category><category>Malware</category></item><item><title>iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence</title><link>https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</guid><description>Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.</description><pubDate>Sun, 23 Aug 2026 00:44:48 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Passkeys</category><category>Phishing as a Service</category></item><item><title>SynkLoader Malware Steals Credentials in Microsoft Teams Phishing</title><link>https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</guid><description>New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.</description><pubDate>Sat, 22 Aug 2026 00:40:08 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Microsoft Teams</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts</title><link>https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</guid><description>Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.</description><pubDate>Fri, 21 Aug 2026 16:21:53 GMT</pubDate><category>AWS</category><category>Credential Theft</category><category>Cloud Security</category><category>IAM</category><category>Data Breach</category></item><item><title>Identity Abuse and Phishing via Enterprise Collaboration Platforms</title><link>https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</guid><description>Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.</description><pubDate>Thu, 20 Aug 2026 16:29:19 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Russian Threat Clusters Target Academia and Government via Auth Abuse</title><link>https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-target-academia-and-government-via-auth-abuse</guid><description>Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.</description><pubDate>Thu, 20 Aug 2026 16:26:40 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Oauth Phishing</category><category>Credential Theft</category><category>Zero-Day</category></item><item><title>SSRF Scans Target Cloud Metadata Service for Credential Access</title><link>https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</guid><description>Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.</description><pubDate>Wed, 19 Aug 2026 16:24:58 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>IAM</category><category>Credential Theft</category><category>Metadata Service</category></item><item><title>Mitigating Large-Scale Credential Attacks and Password Spraying</title><link>https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</guid><description>Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.</description><pubDate>Wed, 19 Aug 2026 00:42:17 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Phishing</category><category>Zero-Day</category></item><item><title>Threat Actor Claims 3.6 Million Azure Account Records Stolen</title><link>https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actor-claims-3-6-million-azure-account-records-stolen</guid><description>A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.</description><pubDate>Tue, 18 Aug 2026 00:40:50 GMT</pubDate><category>Credential Theft</category><category>Data Breach</category><category>Azure</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Public Wi-Fi DNS Hijacking: Credential Theft Risk</title><link>https://runtimerebel.com/blog/public-wi-fi-dns-hijacking-credential-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/public-wi-fi-dns-hijacking-credential-theft-risk</guid><description>Criminals are actively manipulating public Wi-Fi DNS settings to redirect users to fake login pages, stealing sensitive credentials. Learn how to protect yourself.</description><pubDate>Mon, 17 Aug 2026 16:19:43 GMT</pubDate><category>Credential Theft</category><category>Phishing</category><category>Dnssec</category><category>DNS Hijacking</category><category>Public Wi Fi</category></item><item><title>Evooo1Bot Linux Botnet: Beyond DDoS with Exploits &amp; Credential Theft</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</guid><description>Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.</description><pubDate>Mon, 17 Aug 2026 16:18:57 GMT</pubDate><category>Linux</category><category>Botnet</category><category>DDoS</category><category>Credential Theft</category><category>Evooo1Bot</category></item><item><title>Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</guid><description>A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.</description><pubDate>Sat, 15 Aug 2026 16:14:07 GMT</pubDate><category>DDoS</category><category>Credential Theft</category><category>D Link</category><category>TP Link</category><category>Mirai</category></item><item><title>Data Analyst Sentenced to Prison for Extorting Brightly Software</title><link>https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</guid><description>A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.</description><pubDate>Fri, 14 Aug 2026 08:59:48 GMT</pubDate><category>Data Breach</category><category>Credential Theft</category><category>Ransomware</category><category>Insider Threat</category></item><item><title>Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise</title><link>https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</guid><description>Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.</description><pubDate>Fri, 14 Aug 2026 01:06:18 GMT</pubDate><category>Credential Theft</category><category>Malware</category><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>JWR Phishing Framework: Real-time Data Theft via PhaaS</title><link>https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</link><guid isPermaLink="true">https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</guid><description>The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.</description><pubDate>Thu, 13 Aug 2026 16:47:48 GMT</pubDate><category>Phishing</category><category>PhaaS</category><category>Credential Theft</category><category>PII</category><category>JWR</category></item><item><title>City-Forum Data Theft Targets Salesforce and ServiceNow Portals</title><link>https://runtimerebel.com/blog/city-forum-data-theft-targets-salesforce-and-servicenow-portals</link><guid isPermaLink="true">https://runtimerebel.com/blog/city-forum-data-theft-targets-salesforce-and-servicenow-portals</guid><description>City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.</description><pubDate>Thu, 13 Aug 2026 01:06:33 GMT</pubDate><category>Salesforce</category><category>ServiceNow</category><category>Data Breach</category><category>Cloud Security</category><category>Credential Theft</category></item><item><title>Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA</title><link>https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</link><guid isPermaLink="true">https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</guid><description>Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.</description><pubDate>Wed, 12 Aug 2026 09:05:47 GMT</pubDate><category>Ransomware</category><category>Fortinet</category><category>Credential Theft</category><category>Critical Infrastructure</category></item><item><title>Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP</title><link>https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</guid><description>Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.</description><pubDate>Wed, 12 Aug 2026 09:02:31 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>TeamPCP</category><category>Credential Theft</category></item><item><title>Solidity Pro VS Code Extensions Steal Crypto Wallets &amp; Credentials</title><link>https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</guid><description>Malicious &apos;Solidity Pro&apos; VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.</description><pubDate>Mon, 10 Aug 2026 09:08:16 GMT</pubDate><category>VS Code</category><category>Information Stealer</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Solidity Pro</category></item><item><title>Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas</title><link>https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-click-ai-browser-hacking-threatens-claude-and-chatgpt-atlas</guid><description>Zenity details zero-click indirect prompt injection vulnerabilities affecting OpenAI ChatGPT Atlas and Claude in Chrome via malicious web content.</description><pubDate>Mon, 10 Aug 2026 01:00:52 GMT</pubDate><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Artificial Intelligence</category><category>Zenity</category></item><item><title>ClickFix Attacks Deliver macOS Stealer Targeting Crypto</title><link>https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</guid><description>ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.</description><pubDate>Mon, 10 Aug 2026 00:59:16 GMT</pubDate><category>macOS</category><category>Malware</category><category>Cryptocurrency</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Vidar Stealer &amp; XMRig Campaign Leverages Malvertising, AMSI Bypass</title><link>https://runtimerebel.com/blog/vidar-stealer-xmrig-campaign-leverages-malvertising-amsi-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/vidar-stealer-xmrig-campaign-leverages-malvertising-amsi-bypass</guid><description>Financially motivated campaign delivers Vidar stealer and XMRig miner via malvertising for cracked software, targeting consumers and SMBs globally.</description><pubDate>Sun, 09 Aug 2026 01:01:35 GMT</pubDate><category>Vidar Stealer</category><category>XMRig</category><category>Malvertising</category><category>Credential Theft</category><category>Factory V3</category></item><item><title>New CSS Attacks Break Webmail Interfaces to Steal Credentials</title><link>https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-css-attacks-break-webmail-interfaces-to-steal-credentials</guid><description>PortSwigger researchers revealed new CSS and HTML techniques breaking webmail defenses in Outlook, Gmail, and Yahoo to capture tokens and passwords.</description><pubDate>Sun, 09 Aug 2026 00:57:22 GMT</pubDate><category>Webmail</category><category>CSS Injection</category><category>Vulnerabilities</category><category>Zero-Day</category><category>Credential Theft</category></item><item><title>UAT-11795 Deploys Starland RAT &amp; WLDR Agent in Financial Campaign</title><link>https://runtimerebel.com/blog/uat-11795-deploys-starland-rat-wldr-agent-in-financial-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-11795-deploys-starland-rat-wldr-agent-in-financial-campaign</guid><description>UAT-11795, a Russian-speaking financially motivated adversary, uses Starland RAT and the WLDR C2 agent to target credentials and crypto in the U.S. and Europe.</description><pubDate>Sat, 08 Aug 2026 16:24:54 GMT</pubDate><category>Financially Motivated</category><category>Credential Theft</category><category>Cryptocurrency Theft</category><category>UAT 11795</category><category>Starland RAT</category></item><item><title>Identity Attacks: The Modern SOC&apos;s Front Door Challenge</title><link>https://runtimerebel.com/blog/identity-attacks-the-modern-soc-s-front-door-challenge</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-attacks-the-modern-soc-s-front-door-challenge</guid><description>Identity weaknesses are now the primary initial access vector, impacting nearly 90% of incidents. Learn how to detect and mitigate identity-driven attacks.</description><pubDate>Sat, 08 Aug 2026 00:58:12 GMT</pubDate><category>Identity Attacks</category><category>Credential Theft</category><category>Social Engineering</category><category>Incident Response</category><category>MFA Manipulation</category></item><item><title>Emerging Cyber Threats and Espionage Risks in Neurotechnology</title><link>https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</guid><description>Examine growing security threats to neurotechnology and brain-computer interfaces, focusing on IP theft, biometric data collection, and state-sponsored espionage.</description><pubDate>Fri, 07 Aug 2026 02:14:32 GMT</pubDate><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat</title><link>https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</guid><description>Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.</description><pubDate>Fri, 07 Aug 2026 02:13:34 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion</title><link>https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</guid><description>Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.</description><pubDate>Fri, 07 Aug 2026 02:12:08 GMT</pubDate><category>UNC6671</category><category>Phishing</category><category>Credential Theft</category><category>Ransomware</category><category>Cloud Security</category></item><item><title>Canadian Threat Actor Pleads Guilty in Snowflake Extortions</title><link>https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions</link><guid isPermaLink="true">https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions</guid><description>Connor Riley Moucka pleaded guilty to computer fraud and extortion involving 165 Snowflake client organizations and AT&amp;T customer records.</description><pubDate>Fri, 07 Aug 2026 02:10:26 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Data Breach</category><category>Snowflake</category></item><item><title>Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach</title><link>https://runtimerebel.com/blog/snowflake-hacker-pleads-guilty-analyzing-the-unc5537-data-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/snowflake-hacker-pleads-guilty-analyzing-the-unc5537-data-breach</guid><description>Hacker pleads guilty in UNC5537 Snowflake data breach, compromising 165 organizations and millions of records via stolen credentials.</description><pubDate>Fri, 07 Aug 2026 02:09:26 GMT</pubDate><category>Snowflake</category><category>Data Breach</category><category>UNC5537</category><category>Credential Theft</category><category>Cybercrime</category></item><item><title>AI Token Jacking: How Cybercriminals Steal API Keys for Profit</title><link>https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</guid><description>Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.</description><pubDate>Thu, 06 Aug 2026 10:31:56 GMT</pubDate><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>API Security</category></item><item><title>Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch</title><link>https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</link><guid isPermaLink="true">https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</guid><description>Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.</description><pubDate>Thu, 06 Aug 2026 02:00:17 GMT</pubDate><category>Supply Chain Attack</category><category>NPM</category><category>Credential Theft</category><category>Zero-Day</category><category>Malware</category></item><item><title>Automated SSH Actors Achieve Persistence in 22 Seconds</title><link>https://runtimerebel.com/blog/automated-ssh-actors-achieve-persistence-in-22-seconds</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ssh-actors-achieve-persistence-in-22-seconds</guid><description>Analysis of a Cowrie SSH honeypot reveals automated threat actors moving from credential compromise to system persistence in just 22 seconds.</description><pubDate>Thu, 06 Aug 2026 01:59:52 GMT</pubDate><category>Ransomware</category><category>Brute Force</category><category>Credential Theft</category><category>SSH</category></item><item><title>Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends</title><link>https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</guid><description>Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.</description><pubDate>Thu, 06 Aug 2026 01:57:17 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Multi Factor Authentication</category><category>Threat Intel</category></item><item><title>Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison</title><link>https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</guid><description>Maksim Silnikau, creator of the Ransom Cartel ransomware operation, receives a 16-year prison sentence following international law enforcement cooperation.</description><pubDate>Thu, 06 Aug 2026 01:56:23 GMT</pubDate><category>Ransom Cartel</category><category>Ransomware</category><category>REvil</category><category>Credential Theft</category><category>Extortion</category></item><item><title>ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware</title><link>https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</guid><description>Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.</description><pubDate>Thu, 06 Aug 2026 01:56:14 GMT</pubDate><category>Phishing</category><category>Malware</category><category>Credential Theft</category><category>macOS</category><category>Atomic Stealer</category></item><item><title>Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows</title><link>https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</guid><description>Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.</description><pubDate>Wed, 05 Aug 2026 17:21:16 GMT</pubDate><category>Malware</category><category>Credential Theft</category><category>Authentication</category><category>Windows</category><category>Google</category></item><item><title>Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks</title><link>https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</guid><description>Discover how the Smoke#Screen phishing campaign uses rotating payloads and ScreenConnect to achieve persistent remote network access.</description><pubDate>Wed, 05 Aug 2026 01:42:03 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Screenconnect</category></item><item><title>Device Code Phishing Surges 1,500% as Vishing Doubles</title><link>https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</link><guid isPermaLink="true">https://runtimerebel.com/blog/device-code-phishing-surges-1500-as-vishing-doubles</guid><description>Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.</description><pubDate>Tue, 04 Aug 2026 11:23:35 GMT</pubDate><category>Phishing</category><category>Social Engineering</category><category>Credential Theft</category><category>Identity Access</category><category>Multi Factor Authentication</category></item><item><title>Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware</title><link>https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</guid><description>Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.</description><pubDate>Tue, 04 Aug 2026 01:28:40 GMT</pubDate><category>Midnight Blizzard</category><category>APT29</category><category>Credential Theft</category><category>Phishing</category><category>Malware</category></item><item><title>Phishing Targets AI Service Users: Guard Your ChatGPT Accounts</title><link>https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-targets-ai-service-users-guard-your-chatgpt-accounts</guid><description>Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.</description><pubDate>Sat, 01 Aug 2026 10:02:17 GMT</pubDate><category>Phishing</category><category>AI Services</category><category>ChatGPT</category><category>Social Engineering</category><category>Credential Theft</category></item><item><title>Anthropic Claude AI Incident: PyPI Malware &amp; Supply Chain Risks</title><link>https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</guid><description>A security evaluation of Anthropic&apos;s Claude AI model led to a significant breach, uploading malicious Python packages and compromising 3 organizations.</description><pubDate>Fri, 31 Jul 2026 02:55:12 GMT</pubDate><category>Anthropic</category><category>Claude AI</category><category>PyPI</category><category>Malware</category><category>Supply Chain Attack</category><category>AI Security</category><category>Credential Theft</category></item></channel></rss>