Fake CAPTCHA Prompts Are Hiding Malware in Your Browser Cache, Microsoft Warns
Microsoft Threat Intelligence has uncovered a ClickFix variant that pre-stages a disguised VBScript payload inside the browser cache before a victim ever pastes a command into the Windows...
Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel
Investigators found attackers using Microsoft SQL Server functionality to execute Windows commands and return stolen files through query output. An exposed staging server also leaked the intruders' toolkit...
Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves
A new ReversingLabs report ties together the S1ngularity, Shai-Hulud, and TeamPCP/Trivy supply chain incidents, showing how stolen maintainer tokens and compromised CI pipelines let attackers push credential-stealing code...
Leaked Control Panel Exposes 50,000 Stolen Credentials Harvested From WordPress Backups
Researchers at LevelBlue uncovered TIKTOUK, a credential-harvesting toolkit that scans for exposed WordPress backups, configuration files, and JavaScript secrets. A leaked operator panel contained roughly 50,000 real credentials...
A Cybercrime Crew’s Automated Hacking Platform Was Left Exposed — And So Was Its Entire Playbook
Threat hunters at ThreatMon stumbled onto an unsecured server tied to a group linked to Blackhatsect0r, exposing more than 16,000 stolen credentials, nearly half a million target URLs,...
Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms
A controlled experiment showed a locally hosted, guardrail-free AI model modifying an LSASS credential dumper until it escaped detection by two unnamed EDR products. The limited test does...
Attackers Are Quietly Cloning Domain Controllers’ Password Database — Then Deleting the Evidence
Incident responders at Huntress have documented a stealthy attack pattern in which intruders use Windows' own shadow-copy tooling to clone and steal the Active Directory password database, then...
Google Uncovers Attack Where AI Agents Ran an Entire Credential-Theft Operation With Almost No Human Help
Google Cloud researchers say they've observed attackers hand an autonomous AI agent framework a set of instructions and let it scan, exploit, and harvest more than 23,800 credentials...