Tag Archives: Credential Theft
BlackFile Cluster: The Rise of Prime Extortion Tactics
Cybersecurity researchers have identified the BlackFile Cluster, a group utilizing Prime Extortion tactics like vishing and swatting to bypass traditional ransomware encryption. Continue reading
Stolen Credentials Report: KELA Reveals 2.86 Billion Records Exposed
The latest Stolen Credentials Report from KELA exposes 2.86 billion compromised records, highlighting a dangerous shift in infostealer malware targeting session tokens to bypass 2FA. Continue reading
PyTorch Lightning Attack: Supply Chain Breach Steals Developer Credentials
A significant PyTorch Lightning attack has targeted the PyPI ecosystem, deploying malicious versions of the popular machine learning library to steal developer credentials and cloud access tokens. Continue reading
Supply Chain Attack: Checkmarx Confirms Massive Credential Exfiltration
A devastating supply chain attack targeting the KICS project has led to the exfiltration of sensitive API keys and database credentials for MongoDB and MySQL. Continue reading
Kuse AI Phishing Campaign Leverages Trusted Workplace App for Credential Theft
A sophisticated Kuse AI phishing campaign is abusing the legitimate storage features of the popular workplace application to bypass email filters and harvest corporate credentials. Continue reading
CVE-2026-32202 Vulnerability: Zero-Click Windows Credential Theft
Researchers have uncovered the critical CVE-2026-32202 vulnerability, a zero-click flaw used by APT28 to steal Windows credentials through authentication coercion. Continue reading
Bitwarden Supply Chain Attack: Trojanized CLI Package Exposed
Security researchers have detailed a critical Bitwarden supply chain attack involving a malicious NPM package designed to exfiltrate developer cloud credentials and SSH material. Continue reading
Session Hijacking Attacks: Storm Infostealer and EvilTokens Bypass 2FA
Discover how the Storm infostealer and EvilTokens campaigns leverage session hijacking to bypass 2FA, putting organizational accounts at risk. Continue reading
Storm Malware Targets Browsers to Bypass 2FA Security
Security researchers have identified the new Storm malware, a sophisticated threat that exfiltrates browser data to bypass 2FA and hijack active user sessions. Continue reading