Security News

GoIssue phishing tool targets GitHub developer credentials
2024-11-13 13:36

Researchers discovered GoIssue, a new phishing tool targeting GitHub users, designed to extract email addresses from public profiles and launch mass email attacks. Marketed on a cybercrime forum,...

Massive Git Config Breach Exposes 15,000 Credentials; 10,000 Private Repos Cloned
2024-11-01 10:27

Cybersecurity researchers have flagged a "massive" campaign that targets exposed Git configurations to siphon credentials, clone private repositories, and even extract cloud credentials from the...

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft
2024-11-01 09:48

Microsoft has revealed that a Chinese threat actor it tracks as Storm-0940 is leveraging a botnet called Quad7 to orchestrate highly evasive password spray attacks. The tech giant has given the...

Gang gobbles 15K credentials from cloud and email providers' garbage Git configs
2024-10-31 23:59

Emeraldwhale gang looked sharp – until it made a common S3 bucket mistake A criminal operation dubbed Emeraldwhale has been discovered after it dumped more than 15,000 credentials belonging to...

Microsoft: Chinese hackers use Quad7 botnet to steal credentials
2024-10-31 20:03

Microsoft warns that Chinese threat actors use the Quad7 botnet, compromised of hacked SOHO routers, to steal credentials in password-spray attacks. [...]

Windows Themes zero-day bug exposes users to NTLM credential theft
2024-10-30 21:30

Plus a free micropatch until Redmond fixes the flaw There's a Windows Themes spoofing zero-day bug on the loose that allows attackers to steal people's NTLM credentials.…

Hackers steal 15,000 cloud credentials from exposed Git config files
2024-10-30 14:00

A global large-scale dubbed "EmeraldWhale" exploited misconfigured Git configuration files to steal over 15,000 cloud account credentials from thousands of private repositories. [...]

Cybercriminals Use Webflow to Deceive Users into Sharing Sensitive Login Credentials
2024-10-28 11:10

Cybersecurity researchers have warned of a spike in phishing pages created using a website builder tool called Webflow, as threat actors continue to abuse legitimate services like Cloudflare and...

WordPress forces user conf organizers to share social media credentials, arousing suspicions
2024-10-28 06:27

One told to take down posts that said nice things about WP Engine Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts...

Roundcube XSS flaw exploited to steal credentials, email (CVE-2024-37383)
2024-10-22 09:21

Attackers have exploited an XSS vulnerability (CVE-2024-37383) in the Roundcube Webmail client to target a governmental organization of a CIS country, Positive Technologies (PT) analysts have...