threat-intel Infostealers Turn Millions of Devices Into Credential Theft Machines This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resu… SecurityWeek · Jun 10, 2026 High IRinfostealerscredentialsmalware-as-a-service
threat-intel OpenClaw AI agent found falling for phishing attacks, spills user data An OpenClaw AI agent, designed to monitor email and perform automated tasks, was successfully tricked by phishing attacks, highlighting vulnerabilities in AI systems’ ability to discern malicious intent. Researchers at V… BleepingComputer · Jun 9, 2026 High aiphishingcredentials
vulnerability NAVTOR NavBox A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Found… CISA Advisories · Jun 4, 2026 Critical CVE-2026-21404NOsoapcredentialswcf
vulnerability Acer working to patch max severity zero-days in Wave 7 routers Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access t… BleepingComputer · Jun 3, 2026 Critical CVE-2026-49200CVE-2026-49201zero-daymesh routercredentials
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
supply-chain Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive d… The Hacker News · May 22, 2026 Critical IRILci/cdgithubsupply chain
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
threat-intel When Identity is the Attack Path This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c… The Hacker News · May 21, 2026 High USidentitycredentialspermissions
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials 1Password and OpenAI have partnered to create a new system, the Environments MCP Server, designed to protect sensitive credentials used by AI coding agents like OpenAI Codex. This integration addresses the growing risk o… SecurityWeek · May 20, 2026 High aicredentialssecrets
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
vulnerability Siemens Teamcenter Siemens Teamcenter versions 2312, 2406, 2412, and 2506 are affected by multiple vulnerabilities, including a PDF.js flaw and hardcoded credentials. These vulnerabilities could allow for arbitrary code execution and unaut… CISA Advisories · May 14, 2026 High CVE-2026-33862CVE-2026-33893CVE-2024-4367DEpdfjscredentialscve-2024-4367
phishing One in eight UK workers has sold their company passwords, and bosses think it’s fine A recent survey revealed that approximately one in eight UK workers has disclosed their company login credentials, either directly or through a connection. This practice is compounded by a concerning lack of concern from… Graham Cluley · May 8, 2026 High GBpasswordssecurityuk
malware 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users A coordinated campaign involving 108 malicious Chrome extensions has been discovered, stealing data from approximately 20,000 users. The extensions, disguised as legitimate add-ons for popular apps like Telegram and YouT… Graham Cluley · Apr 15, 2026 High RUbrowser extensionsdata theftcredentials