credential theft
52 stories on credential theft, newest first, from 54 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Suspected Chinese Spies Used Fake AI Policy Invites to Phish US Experts
- China-Linked Hackers Impersonate AI Policy Experts to Steal Microsoft 365 Logins
- CSuite Phishing Campaign Hijacks Microsoft 365 Sessions and Installs Remote Access Tools
- Newly Patched NetScaler Flaw Already Under Active Attack, Root Access Exploited
- Stolen Staff Passwords Let Attacker Raid French Tax Data for Seven Weeks Undetected
- Flaw in Official MCP Python SDK Could Let Rogue Servers Steal Login Credentials
- AI-Driven Attacker 'JadePuffer' Wipes Out Azure Cloud Resources
- Former US Soldier Jailed Over Telecom Hacking and Extortion Spree
- New Carbonato Botnet Hijacks Exposed Docker Hosts to Run a Telegram-Controlled AI Agent
- Stolen Credentials: How Infostealer Malware Opens the Door to Your Cloud and Code Systems
- New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid
- New Windows Botnet 'x47.c' Can Drain Company AI Credits and Steal Passwords
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Researchers Uncover Windows Malware That Lets AI Models Choose Its Next Move
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- Nearly 1 in 5 US Water Utilities Have Exposed Logins from Infostealer Malware
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Why Knowing Who Has Access Is the New Frontline of Cyber Defence
- Former Employee's Compromised Laptop Led to Leak of 170 CrowdSec Repositories
- China-Linked Hacking Group NightEagle Expands Attacks to Russian Businesses
- AWS AI Agent Tool Could Let Attackers Steal Credentials via Prompt Injection
- Three Ukrainians Charged Over Mass Theft of 610,000 Roblox Accounts
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP
-
Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
Also covered by The Hacker News
- Stolen AI Login Tokens Let Hackers Skip Passwords and MFA Entirely
- Phishing Scam Hides Behind Trusted Google Links to Steal Credentials
- AI-Powered Attacks Are Speeding Up: Google Warns of Autonomous Hacking Campaigns
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
- New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins
- Dark Web Roundup: Bangladeshi E-Commerce Data, Vedicline Records, ASUS Database and More Up for Sale
- JSCeal Malware Steals Browser Sessions to Bypass Google Login Security
- JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials
- Schools and Universities Targeted as Hackers Exploit PaperCut Print Software Flaws
- Shai-Hulud Worm Expands Credential Theft Reach Dramatically
- AI Safety Researcher METR Targeted in Credential Theft, Racks Up $600,000 in Stolen AI Credits
- AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage
- Weekly Threat Recap: Backdoored Routers, Rogue AI Agents, and Old Bugs Still Doing Damage
- China-Linked 'Fire Ant' Group Targets Cisco Routers to Steal Credentials and Cover Its Tracks
- METR Discloses Two Security Incidents, Says No Sensitive Data Accessed
- Critical MLflow Flaw Being Exploited to Steal Cloud Credentials
- Hackers Are Hijacking Trusted Work Chat Tools to Steal Logins
- US Charges 17 Iranian Hackers, Offers $10 Million for Information Leading to Arrests
- Massive Credential Theft Targets Microsoft Entra Users: What SMBs Need to Know
-
New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
Also covered by The Hacker News
- French Tax Authority Breach Exposes Data of 680,000 People
- Fake Job Interview Pages Used to Steal Google and Facebook Logins in Global Phishing Campaign
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
- Fake VS Code Extension 'Solidity Pro' Caught Stealing Crypto Wallets and Credentials
- OpenAI's AI Agents Accidentally Attacked Hugging Face, Timeline Reveals
- AI Gateways Like LiteLLM Are Becoming Prime Targets for Attackers