A court admission in the Snowflake-linked case underscores how stolen credentials can fuel broad data theft and extortion.
A social-engineering chain is turning user trust into code execution, then targeting the secrets that make account takeover and crypto theft possible.
Vanta Stealer shows how packaging and obfuscation can turn familiar developer tools into a concealment layer for credential theft, token abuse, and wallet scraping.
Research presented at Black Hat USA 2026 points to a fragile trust boundary: once AI coding tools touch GitHub workflows, a mistake in permissions or input handling can raise the risk of code execution, token exposure, and pipeline control.
A Python-based infostealer linked to fake updates, cracked software, and game cheats shows how one careless launch can turn into credential theft and account takeover.
A reported toolkit called KHunt shows how a web-facing SQL injection can be pushed past data access and into database-hosted execution, raising the stakes for over-privileged Oracle deployments.
A directory left visible online appears to contain tooling for Windows access, credential theft, security evasion, lateral movement, and a blockchain-linked command channel.
A leaked iOS exploit chain paired with a counterfeit Apple sign-in page shows how one malicious visit can blend device exploitation and credential theft into a single attack path.
A compromised internet-facing system can expose how credential theft and Active Directory abuse turn a routine foothold into domain-level control.
Attackers are using AI-branded lures and cloned GitHub repositories to push infostealers toward developers and AI users, with credentials and cloud secrets in the crosshairs.
Cloned repositories, infostealers, and social-engineering lures are turning routine AI setup work into a path to cloud credential theft.
A reported campaign tied to ChocoShell shows how compromised hospitality guest networks can be used to collect cloud session material, not just passwords, from roaming users.
A fresh attribution tied to Russian state-sponsored operators puts hotel wireless networks in the spotlight as a credential and malware delivery surface, not just a convenience layer for travelers.
A newly documented macOS threat shows how social engineering, browser-session theft, and Keychain harvesting can turn one user interaction into a much wider credential crisis.
Attackers are using fake CAPTCHAs to trick macOS users into running malicious commands, in a campaign that reportedly deploys AMOS and targets browser credentials and crypto wallets.
As concern over AI grows, Arctic Wolf warns that companies may be paying less attention to the familiar threats that still drive most day-to-day security work.
The disruption of Kratos may have removed one criminal service, but the deeper problem is the reusable playbook behind modern Microsoft 365 account-takeover campaigns.
A malvertising campaign dressed up as a Claude Code setup guide shows how one pasted command can turn a developer workstation into a map of reusable secrets.
A public claim tied to EY points to the risk hidden in third-party support access, where one trusted link can become the pressure point for an extortion attempt.
A compromise at the network edge can turn a routine travel login into a credential-and-token capture event, with cloud identity as the real target.