Passkey phishing hijacks Microsoft 365 for data theft
Passkey-themed phishing is hijacking Microsoft 365 accounts through vishing calls. Attackers steal session tokens and exfiltrate data over days, not minutes.
17 stories tagged threat-intel.
Passkey-themed phishing is hijacking Microsoft 365 accounts through vishing calls. Attackers steal session tokens and exfiltrate data over days, not minutes.
The Shai-Hulud npm infostealer worm expanded from 189 to 469 credential-scanning paths across dev machines, CI/CD, cloud, and AI tool configs after the [email protected] compromise. Rotate everything.
Fire Ant, a China-nexus espionage group, expanded from VMware hypervisors to Cisco IOS XR routers and TACACS servers, hijacking the network trust layer to steal credentials and blind security logging across connected environments.
A Rust supply chain attack compromised arrayref with 245 million downloads, injecting build-time malware that steals browser credentials. Check your cache now.
AmnesiaStealer is a new macOS infostealer that clones Chromium profiles and hands attackers live remote control of authenticated browser sessions via CDP.
ChainDrop is a self-propagating npm worm that hit 1,300 packages with 2 billion monthly downloads, stealing cloud credentials from CI/CD runners.
The Keyv npm supply chain attack spread a credential-stealing worm through 444 packages on August 4, 2026. The worm planted execution hooks in Claude Code and VS Code, harvesting CI secrets via Ethereum blockchain C2.
PLC attacks on water utilities by Iranian APTs triggered a CISA alert after attackers locked operators out and caused boil water notices across the US.
PLC attacks on water utilities spread to 7 states after 30 Minnesota systems were hit. CISA says remove exposed controllers from the internet now.
Cl0p affiliates exploit unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM to steal data. Patch, segment, and block external access now.
Citrix Bleed 2 is now an Anubis ransomware access path. Patch NetScaler, kill sessions, and hunt RMM plus credential abuse.
Langflow RCE is being used to mine Monero on exposed AI app endpoints. Patch, isolate, and treat public workflows as production attack surface.
VS Code Tasks supply chain attack is a package hijack pattern that can run outside npm lifecycle scripts, so scan editor configs now.
Signal backup recovery keys can expose historical chats after one phishing win. Treat messenger backups like identity infrastructure now.
FortiBleed FortiGate credentials are an active edge risk: rotate VPN and admin access now, then hunt for persistence.
FortiBleed credential theft turns compromised FortiGate firewalls into sniffers. Rotate secrets and hunt traffic capture now.
Mastra npm supply chain attack exposed AI build pipelines through more than 140 packages, so treat installs as secret exposure events.