#credential


Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Sep 23, 2026 // 16:57

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based […]

Hackers build AI frameworks for widescale credential theft

Sep 8, 2026 // 15:16

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident […]

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Aug 14, 2026 // 14:13

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook […]

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Aug 5, 2026 // 14:55

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive […]

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Aug 5, 2026 // 13:38

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive […]

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Jul 30, 2026 // 10:50

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft […]

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Jul 30, 2026 // 01:16

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain […]

Is Your SSO Protected Against Modern Credential Attacks?

Jul 28, 2026 // 17:16

Single sign on (SSO) simplifies access by letting users log into multiple systems with one set of credentials. While this delivers clear benefits to the […]

Chick-fil-A discloses data breach after credential stuffing attacks

Jul 22, 2026 // 09:56

American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave […]

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

Jul 2, 2026 // 15:27

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on […]

1 2 Next