< ciso
brief />
Tag Banner

All news with #credential access tag

222 articles

Spring Ring: Voice Phishing Through Collaboration Tools

🛡️ Between January and April 2026, Unit 42 uncovered a coordinated vishing operation—named Spring Ring—using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
read more →

ZeroTokens phishing platform enables live session control

🔒 A phishing platform named ZeroTokens gives attackers live visibility into victim sessions and lets operators change prompts in real time to steer interactions. The campaign, analyzed by Abnormal AI on August 25, sent over 45,000 messages to more than 24,000 recipients across 700+ organizations, using convincing pretexts and legitimate-looking email authentication. The platform replicated financial institutions' verification flows, collected credentials and codes, and used persistent WebSocket connections to relay victim inputs to operator consoles for adaptive attacks.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

Password spraying surge exploits MFA gaps

🔐 Huntress reported a 155x increase in password spraying in H1 2026, driven by a campaign abusing Azure CLI and IPv6 BYOIP ranges from LSHIY LLC. The attacker leveraged reused credentials and the deprecated ROPC OAuth grant to bypass MFA protections that were not applied to this flow. Rampant login attempts led to dozens of compromises while attackers rotated providers and IP ranges to evade blocking. Huntress recommends disabling ROPC, enforcing broad MFA and conditional access, and limiting Azure CLI access to necessary admins.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

FBI warns of hackers stealing explicit images online

🔔 The FBI warns cybercriminals are compromising adults' and children's social media and other online accounts to steal sexually explicit photos and videos for blackmail or sale. Victims risk re-victimization through sextortion, harassment, stalking, and public exposure when attackers post or trade stolen content alongside personal details. Authorities advise not sharing verification codes, avoiding internet-accessible storage for explicit material, using complex passwords, and enabling multi-factor authentication.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

UNC6671 Targets Financial and Cloud Environments

🔎 GTIG reports UNC6671 continues active compromises and data-theft extortion despite the alleged BlackFile retirement, diversifying into Redact, Pink, Helix, and Falcon. The actor uses targeted voice phishing (vishing) to lure employees—often on personal phones—to spoofed login portals with AiTM infrastructure to harvest credentials and MFA tokens, then deploys scripts to exfiltrate data from enterprise cloud apps like Microsoft 365 and Okta. The update details infrastructure linkages, evolving targeting focused on financial services and private equity, and offers hardening guidance to mitigate these identity-centric threats.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

CISA warns of attacks on US water and wastewater systems

🚨 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after hackers disrupted over 30 Minnesota community water systems by targeting internet-exposed programmable logic controllers (PLCs). The attacks included password changes that locked operators out, IP alterations that severed internet connectivity, and other actions that impaired operations. CISA urges owners and operators to remove publicly exposed PLCs and OT from the internet, use VPNs or gateway devices for access, change default passwords, and implement IP allow-lists. Security vendor research from Censys found thousands of internet-reachable PLC hosts and highlighted undocumented cellular modems as a common blind spot.
read more →

Attackers hijack hotel Wi‑Fi to steal Microsoft 365 logins

🔒 Since at least June, researchers observed threat actors compromising captive Wi‑Fi gateways at hotels and venues to redirect traffic and harvest Microsoft 365 credentials. ReliaQuest found attackers gain admin access to portal appliances via exposed interfaces or weak credentials, then poison DNS responses to point users to attacker-controlled endpoints. The technique bypasses device-level protections and can affect employees from multiple sectors, while DNSSEC or changing resolvers alone offers limited protection. ReliaQuest recommends full‑tunnel VPNs, conditional access, encrypted DNS, and hardening PAC/WPAD settings to mitigate the risk.
read more →

ShinyHunters Claims Responsibility for EY Breach

🔐 The ShinyHunters extortion group claims it conducted the Ernst & Young breach, asserting it obtained credentials via a supply-chain attack and accessed the firm's support systems. EY disclosed the incident after detecting unusual activity on April 23, noting attackers accessed a third-party support ticket platform between March 28 and April 12 and downloaded documents. The firm said stolen tickets may include client tax information and has offered affected clients 24 months of identity monitoring through Experian. EY has not confirmed ShinyHunters' claim or identified the compromised third-party service.
read more →

Man sentenced for mass Snapchat account hacks

🔒 An Illinois man received a 76-month prison sentence and three years supervised release after admitting to social engineering attacks that compromised over 750 women's Snapchat accounts to steal and trade nude photos. Between May 2020 and February 2021, he targeted thousands of users while impersonating Snap Inc., accessed at least 517 accounts to download explicit images, and enabled two-factor authentication to lock victims out. Investigators also found hundreds of CSAM files in his cloud storage, and he advertised hacking services online, using Kik to communicate with clients including a former coach who was separately convicted for hiring hacks.
read more →

Synthetic Machine Identity Fraud and Emerging Risks

🔒 Synthetic identity fraud for machines involves attackers fabricating service accounts or credentials rather than stealing existing ones. These fabricated NHIs blend real environmental attributes with fake data to appear legitimate, evading detection because no human owner flags misuse. Techniques include rogue service accounts, DCShadow-style fake domain authorities, and shadow credentials implanted into existing objects. Defenses focus on ownership, secrets rotation, least privilege, and continuous behavioral verification.
read more →

Dolphin X infostealer uses AI to prioritize victims

🔍 A new Windows infostealer and RAT named Dolphin X uses an AI-powered profiling system to help operators rank infected machines and identify high-value victims. Advertised on cybercrime forums, it targets over 300 applications to steal credentials, wallets, SSH keys, cloud tokens and DevOps secrets. Varonis Threat Labs analyzed the operator panel and found a scoring system that summarizes daily rankings to streamline attacker triage. Researchers advise defenders to keep long-lived credentials off disk and focus detection on behavior rather than file signatures.
read more →

How enterprise GenAI can amplify ransomware risk

🛡️ Generative AI is increasingly embedded in business workflows as assistants and agents that access documents, apps, and identities. While AI promises productivity gains, it can amplify existing ransomware tactics by accelerating reconnaissance, credential abuse, and data theft when compromised. The article outlines two threat models—attackers using AI and organizations deploying AI—and recommends governance, least privilege, monitoring, and human approval for high-risk actions.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

🔍 Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more →

Amazon Cognito adds password hash import support

🔐 Amazon Cognito now supports importing users with password hashes in CSV imports, allowing migrated users to sign in immediately with existing credentials. Administrators specify the source system's hashing algorithm during import, and Cognito verifies passwords against the imported hash on first sign-in. Supported algorithms include bcrypt, scrypt, Argon2id, and PBKDF2 with SHA-256; all imported hashes receive additional cryptographic protection before storage. The feature is available in all AWS Regions where Cognito is offered and can be used via the Console, CLI, or SDKs.
read more →