< ciso
brief />
Tag Banner

All news with #credential stuffing tag

94 articles · page 2 of 5

Oxford University reports CareerConnect credential breach

🔒 Oxford University disclosed a data breach after its third-party provider, Group GTI, reported that the CareerConnect platform was compromised on May 28. The attackers accessed users' first and last names, email addresses, and encrypted passwords for accounts not using Single Sign-On; GTI has invalidated those passwords and will require resets. The university said no course materials, uploaded files, appointments, or financial data appear affected, but warned users to watch for phishing attempts.
read more →

FIFA World Cup 2026: Rising Cybercrime Threats

🛡️ FortiGuard Labs warns that cybercriminals are actively exploiting FIFA World Cup 2026 demand, registering thousands of themed domains and creating fake ticketing sites, malicious apps, and impersonation accounts to steal credentials and payments. Their research found over 13,000 new tournament-related domains and identified numerous scams across social media, underground forums, and stealer telemetry. Organizations and fans are urged to prepare early and verify official channels.
read more →

WeedHack campaign infects over 116,000 Minecraft systems

🛡️ McAfee researchers report that a large-scale malware campaign named WeedHack has infected more than 116,000 systems by distributing malicious Minecraft mods, clients, cheats, and utilities via YouTube links and SEO poisoning. The operation provides a free, clear-net MaaS dashboard and a paid premium tier that adds remote control, keylogging, and webcam access, targeting session IDs, browsers, wallets, and gaming credentials. Victims are concentrated in the US, Germany, India, and the UK, and the campaign uses hundreds of distribution URLs and thousands of malicious JARs. Players are urged to only download from official sources and use the in-game Marketplace for safety.
read more →

Romanian sentenced for hacking Oregon government network

🔒 A Romanian national was sentenced to 56 months in federal prison after pleading guilty to aggravated identity theft and unauthorized access to an Oregon state government computer network. The 46-year-old, known online as "inthematrixl," also sold access and stolen personal data from other U.S. victims, causing at least $250,000 in losses. Authorities coordinated internationally to arrest and extradite him, and the court ordered forfeiture of cryptocurrency and supervised release.
read more →

AppSheet-phishing: attackers abusing Google-linked emails

📧 Recent phishing campaigns exploit Google’s AppSheet platform to send convincing emails from a legitimate noreply{@}appsheet.com address, making them likely to bypass filters. Attackers craft personalized messages — urgent warnings or enticing job offers — to trick victims into submitting identity details on clone sites, then harvest credentials and data. The compromises can lead to account takeover, device control, and secondary targeted attacks using the stolen information.
read more →

How to Manage Subscriptions Securely and Avoid Scams

🔒 Subscription services are widespread and often contain personal data, making them attractive targets for attackers. The article outlines common attack vectors — phishing, credential reuse, infostealers, and bulk-resale of hacked family slots — and explains practical defenses: use password managers, enable two-factor authentication or passkeys, and monitor active sessions. It also advises how to spot phishing and track hidden recurring charges through bank statements and app-store settings.
read more →

PCPJack worm steals cloud credentials and cleans TeamPCP

🐛 PCPJack is a new worm that targets exposed cloud infrastructure to harvest credentials while actively removing traces of rival group TeamPCP. It infects Linux systems via a shell script (bootstrap.sh), establishes persistence (monitor.py), and propagates by scanning for exposed Docker, Kubernetes, Redis, MongoDB and RayML services. Stolen credentials are encrypted with X25519/ChaCha20-Poly1305 and exfiltrated to Telegram channels; researchers recommend MFA, IMDSv2 and least-privilege controls.
read more →

Hackers Use Google Ads to Phish ManageWP Logins via AitM

🔒 A phishing campaign abused Google sponsored search results to deliver a live adversary-in-the-middle (AitM) proxy that mimics ManageWP's sign-in page, placing the fake result above the legitimate one for the "managewp" query. Any credentials entered are exfiltrated to a Telegram channel and used in real time to bypass 2FA. Guardio Labs infiltrated the attackers' C2, observed an operator-driven phishing framework, and confirmed around 200 unique victims.
read more →

30,000 Facebook Accounts Hacked via AppSheet Phishing Relay

🔐 A Vietnamese-linked operation used a Google AppSheet address as a phishing relay to distribute credential-harvesting pages and compromise roughly 30,000 Facebook accounts. Guardio, calling the scheme AccountDumpling, says stolen accounts are resold via an illicit storefront after exfiltration to Telegram channels. Lures hosted on Netlify, Vercel and Google Drive, plus Canva-generated PDFs, were used to harvest passwords, 2FA codes, IDs and business data, leaving many victims locked out.
read more →

Inside an OPSEC Playbook: How Actors Evade Detection

🔍 Flare researchers examined a recent forum post in which a threat actor details a structured OPSEC framework aimed at sustaining high-volume carding operations while avoiding detection. The actor prescribes a three-tier architecture—public, operational, and extraction layers—with strict identity compartmentalization, residential IP rotation, and isolated cashout channels. The post highlights recurring failures like identity reuse, metadata leakage, and weak anti-fingerprinting, and recommends resilience measures such as time-delayed triggers and dead man's switches. For defenders, it underscores the need to link cross-platform identities, evolve behavioral detection, and monitor the full attack chain.
read more →

BlueNoroff Targets Crypto Firms with AI-Enhanced Lures

🔒 Arctic Wolf attributes a large-scale spear-phishing campaign to BlueNoroff, a subgroup of the Lazarus Group, which targeted more than 100 cryptocurrency and fintech organizations across 20+ countries. The operation used typosquatted Zoom and Microsoft Teams links, manipulated Calendly invites, fake meeting interfaces and ClickFix-style clipboard injection to harvest credentials and wallet data. Researchers observed a self-sustaining deepfake pipeline, PowerShell-based C2, AES-encrypted browser payloads and Telegram-based exfiltration, with some intrusions persisting for 66 days.
read more →

Tax Season Phishing Targets Individuals and Crypto Users

🛡️Scammers are creating convincing fake tax authority websites worldwide to harvest credentials, steal personal data, and distribute malware embedded in downloaded “documents.” These portals also run fraudulent paid services that collect taxpayer identifiers and financial details for later abuse. Cryptocurrency holders are specifically targeted with fake verification flows that request seed phrases or wallet connections, leading to immediate theft. Kaspersky cautions against using cloud-hosted AI for tax preparation and recommends sticking to verified official channels, encrypting sensitive files, and employing reputable security tools.
read more →

Malicious pgserve and automagik Packages Target npm

🛡️ Security researchers at Socket and StepSecurity have identified malicious versions of pgserve and automagik published to the npm registry that execute a credential-harvesting payload during installation. The trojans collect tokens, SSH keys, cloud credentials (AWS, Azure, GCP), browser passwords and crypto wallet funds, and attempt to propagate by using any npm publish tokens found on infected machines. Stolen data is encrypted and exfiltrated to a decentralized ICP canister, chosen specifically to resist takedown. Developers are urged to rotate all credentials immediately, disable automatic postinstall scripts (npm config set ignore-scripts true), harden CI/CD egress and tighten token scopes.
read more →

No Exploit Needed: Identity-Based Attacks Remain Top Threat

🔐 Attackers increasingly rely on stolen credentials—via credential stuffing, password spraying and phishing—to gain immediate, low-noise access. Legitimate logins often evade detection, allowing adversaries to dump additional passwords, move laterally, and persist. The author warns that AI is accelerating these techniques and advocates a DAIR (Dynamic Approach to Incident Response) loop, plus clear communication and hands-on training to contain and remediate identity-based intrusions.
read more →

Scattered Spider Leader Pleads Guilty to Crypto Theft

🔒 Tyler Robert Buchanan, a 24-year-old British national believed to lead the Scattered Spider cybercrime collective, has pleaded guilty in U.S. federal court to wire fraud and aggravated identity theft in connection with cryptocurrency thefts. Prosecutors say Buchanan and co-conspirators used large-scale SMS phishing campaigns and SIM swap attacks to steal at least $8 million from companies and individuals between September 2021 and April 2023. Buchanan was arrested in June 2024 in Palma de Mallorca, has been in U.S. custody since April 2025, and faces a statutory maximum of 22 years; sentencing is scheduled for August 21, 2026.
read more →

Underground Guide: How Threat Actors Vet Stolen Cards

🔍 Flare analysts recovered a forum document, The Underground Guide to Legit CC Shops, that explains how fraud actors vet stolen credit card marketplaces. The guide shifts emphasis from opportunistic card use to disciplined supplier evaluation, offering a technical checklist (domain age, WHOIS, SSL), social‑intel techniques, and strict OPSEC recommendations. It also highlights how shops emulate legitimate e‑commerce (pricing, ticketing, escrow) and warns of commercial bias in endorsed services.
read more →

Man jailed for selling hacked DraftKings accounts in bulk

🔒 Kamerin Stokes, 23, was sentenced to 30 months in prison after selling access to tens of thousands of hacked accounts tied to DraftKings. Prosecutors say a November 2022 credential‑stuffing attack led by Nathan Austad (aka Snoopy) with accomplice Joseph Garrison compromised nearly 68,000 accounts; the group stole about $635,000 from roughly 1,600 accounts and generated over $2.1 million selling hacked accounts. Stokes, who operated as TheMFNPlug, briefly reopened his shop after pleading guilty with the tagline fraud is fun, was remanded for violating pretrial conditions, and was ordered to pay $1,327,061 in restitution and $125,965.53 in forfeiture, plus three years of supervised release.
read more →

Rockstar Games analytics data leaked after Anodot breach

🔓 A data set allegedly belonging to Rockstar Games was published by the ShinyHunters extortion group after they say authentication tokens were stolen from Anodot and used to access connected Snowflake accounts. The leak reportedly contains more than 78.6 million records of internal analytics — including in‑game revenue, purchase metrics, player behavior, and game economy data for GTA Online and Red Dead Online — plus Zendesk support analytics. Rockstar said only a limited amount of non‑material company information was accessed and that the incident does not affect players.
read more →

Mass Credential Theft via CVE-2025-55182 Targets Next.js

🔓 Cisco Talos has linked a large-scale credential harvesting campaign to a threat cluster tracked as UAT-10608 that exploited CVE-2025-55182 in React Server Components and the Next.js App Router to breach at least 766 hosts. The intruders deployed a multi-stage dropper that collected environment variables, SSH keys, cloud metadata credentials, API keys, and other secrets before aggregating them in a password-protected web GUI called NEXUS Listener. Researchers accessed an exposed instance and observed a broad array of stolen items, including Stripe keys, GitHub tokens, AI platform keys, webhook secrets, and database connection strings. Organizations are urged to patch vulnerable Next.js deployments, enforce least privilege, enable IMDSv2, rotate credentials, and implement secret scanning.
read more →

Inside Modern Fraud: Bot Signups to Account Takeovers

🛡️ Modern fraud attacks function like a relay race: adversaries use bots, leaked credentials, and residential proxies to create large numbers of plausible accounts, then pivot to slower, human-driven sessions for logins and cash-out. Point-in-time, single-signal checks (IP, email, device) generate false positives and miss adaptive, multi-stage chains. The piece argues for correlating IP, identity, device, and behavioral signals into a unified risk model to reduce friction for legitimate users while stopping coordinated abuse.
read more →