Skip to content

Topic

Credential Theft and Stealer Logs

Usernames, passwords, cookies, and tokens harvested by infostealer malware, compiled into logs sold on criminal markets to enable account takeover.

Current stories

security3 publishersConfirmed

Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers

Arctic Wolf reports the two newly disclosed PaperCut bugs being used together against K-12 and university print servers in the US and Europe, with collection aimed at the directory credentials the server stores to do its job.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives30
Confidence62
build1 publisherOne report

Tag-pinned workflows re-ran Mini Shai-Hulud after issues-helper was re-enabled

Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.

Publishers:dev.to

Reality

Evidence55
Adoption35
Hype gap+10
Incentives
Insufficient
Confidence55
security4 publishersConfirmed

Detections on VulnCheck's canaries climb from 50 to 360 amid Langflow, Rails exploitation

The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence62
Adoption40
Hype gap+15
Incentives65
Confidence60
build1 publisherOne report

Compromised MemOS packages scan for developer tokens the moment Python imports them

Semgrep found sckit hidden in the genuine MemOS npm and PyPI packages, where it fires on Python import to scan for npm, GitHub, cloud and Slack tokens. It runs on import, not on install, so install-time scanning misses it, and anyone who imported an affected version should rotate those tokens.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence50
security1 publisherOne report

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives55
Confidence60

Earlier coverage

  1. KREMLIN installers forge Chrome's Secure Preferences HMACs to register a stealer extension

    Security · September 15, 2026 · 1 publisherOne report

  2. One file read inside a restricted agent pod hands over the LLM key

    Build · September 15, 2026 · 1 publisherOne report

  3. An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud

    Build · September 12, 2026 · 1 publisherOne report

  4. A stolen supplier credential put Stadler's name on a CHF 10 million extortion demand

    Build · September 10, 2026 · 1 publisherOne report

  5. A six-hour agent run harvested credentials from behind the victim's own cloud IPs

    Build · September 10, 2026 · 1 publisherOne report

  6. Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks

    Security · September 8, 2026 · 1 publisherOne report

  7. Shai-Hulud's third wave printed SAP's npm token straight into a workflow log

    Security · September 8, 2026 · 1 publisherOne report

  8. Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

    Security · September 8, 2026 · 3 publishersConfirmed

  9. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · 1 publisherOne report

  10. Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD

    Security · September 3, 2026 · 1 publisherOne report

  11. AFP charges two Perth men over malicious open-source packages that reached 1,000 organisations

    Security · September 3, 2026 · 1 publisherOne report

  12. AFP charges two Perth men over poisoned packages police say reached 1000 organisations

    Build · August 28, 2026 · 2 publishersConfirmed

  13. Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name

    Product · August 27, 2026 · 1 publisherOne report

  14. Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms

    Security · August 24, 2026 · 1 publisherOne report