Back to Blog

#Credential Theft

22 posts
Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access Sophos says two cybercrime groups, Vect and TeamPCP, have formalized a partnership that...

July 5, 2026
7 min read
JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware

JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware

JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware Sysdig has documented what it assesses as one of the first clear examples of agentic r...

July 4, 2026
6 min read
SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path

SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path

SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path SimpleHelp has moved from patched vulnerability to active intrusion path. Attacker...

July 1, 2026
9 min read
Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk The Mastra npm incident is a sharp warning for teams building AI agents: dependency compr...

June 27, 2026
8 min read
Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...

June 14, 2026
6 min read
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens

One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens

One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens | 2026 Executive Summary Security researcher Ammar Askar disclosed a one-click attack...

June 3, 2026
7 min read
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure

LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure

LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure | 2026 Executive Summary Push Security disclosed a live campaign it tracks as LLMShare, w...

June 3, 2026
7 min read
FortiClient EMS exploit turns endpoint management into credential theft at scale

FortiClient EMS exploit turns endpoint management into credential theft at scale

FortiClient EMS exploit turns endpoint management into credential theft at scale CVE-2026-35616 matters because it breaks a security assumption many teams quiet...

May 31, 2026
5 min read
GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk Executive Summary The coordinated disruption of GlassWorm on May 26, 2026 is useful bec...

May 30, 2026
6 min read
GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft A fresh GitHub Actions supply chain incident is a good reminder that "pinned" does not mean safe...

May 19, 2026
6 min read
CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority

CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority

CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority CVE-2026-20182 is not landing as a routine patch bulletin. Cisco says the flaw is already b...

May 15, 2026
6 min read
LiteLLM SQL injection flaw puts AI gateways on the front line

LiteLLM SQL injection flaw puts AI gateways on the front line

LiteLLM SQL injection flaw puts AI gateways on the front line CVE-2026-42208 matters because it turns an AI gateway into a high-value choke point for attackers....

May 11, 2026
5 min read