Security News

The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That
2025-05-12 11:00

Detecting leaked credentials is only half the battle. The real challenge—and often the neglected half of the equation—is what happens after detection. New research from GitGuardian's State of...

OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
2025-05-09 16:25

The North Korean threat actors behind the Contagious Interview campaign have been observed using updated versions of a cross-platform malware called OtterCookie with capabilities to steal...

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
2025-05-09 10:57

Cybersecurity researchers have flagged three malicious npm packages that are designed to target the Apple macOS version of Cursor, a popular artificial intelligence (AI)-powered source code...

CoGUI phishing platform sent 580 million emails to steal credentials
2025-05-07 18:02

A new phishing kit named 'CoGUI' sent over 580 million emails to targets between January and April 2025, aiming to steal account credentials and payment data. [...]

Third Parties and Machine Credentials: The Silent Drivers Behind 2025's Worst Breaches
2025-05-06 11:25

It wasn't ransomware headlines or zero-day exploits that stood out most in this year's Verizon 2025 Data Breach Investigations Report (DBIR) — it was what fueled them. Quietly, yet consistently,...

Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data
2025-05-05 05:39

The threat actors known as Golden Chickens have been attributed to two new malware families dubbed TerraStealerV2 and TerraLogger, suggesting continued development efforts to fine-tune and...

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials
2025-04-22 10:50

In what has been described as an "extremely sophisticated phishing attack," threat actors have leveraged an uncommon approach that allowed bogus emails to be sent via Google's infrastructure and...

7 Steps to Take After a Credential-Based cyberattack
2025-04-18 13:33

Hackers don't break in—they log in. Credential-based attacks now fuel nearly half of all breaches. Learn how to scan your Active Directory for compromised passwords and stop attackers before they...

CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
2025-04-18 04:29

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog,...

Malicious PyPI Package Targets MEXC Trading API to Steal Credentials and Redirect Orders
2025-04-15 13:20

Cybersecurity researchers have disclosed a malicious package uploaded to the Python Package Index (PyPI) repository that's designed to reroute trading orders placed on the MEXC cryptocurrency...