ANSSI says stolen staff passwords let an attacker take data on about 600,000 French taxpayers and firms, and the theft went undetected for seven weeks. Its report blames password-only portals, a flat government network and a reset that left the attacker's session open.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence68
ANSSI says an attacker used dozens of stolen DGFIP staff passwords on password-only portals to take data on over 600,000 French taxpayers and businesses. For other operators, the fixes are login checks on devices they do not manage and a password reset that also ends live sessions.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
SOCRadar tied 5,434 infostealer records for AI tools to 1,500 corporate email addresses at 482 large enterprises. The report says those AI accounts belong under the same sign-on and session controls as a company's identity provider and code repositories.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+35
- Incentives85
- Confidence40
SOCRadar found captured ChatGPT sessions at 358 of the 482 companies whose AI accounts turned up in 90 days of infostealer logs. The firm ties the spread to shadow AI, with employees opening work-email accounts that IT never sees.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence45
n0n, a ransomware crew first seen September 18, listed over a dozen victims in four days and threatens to wipe the backups of those who refuse to pay. Whether it can depends on what its escalated admin accounts reach.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence40
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 61%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60
OpenSourceMalware flagged the campaign on August 15, 2026. The install hook fakes a clean native build while pulling a Windows stealer that goes after browser credentials and crypto wallets.
Publishers:opensourcemalware.com · thehackernews.com Reality
- Evidence72
- Adoption15
- Hype gap+10
- Incentives40
- Confidence70
McAfee says the WeedHack stealer's control server is dead and its renter dashboard gone, but ten impersonation sites and the search rankings behind them are still delivering victims.
Perspective Coverage
3 publishers
- Builder
- Builder 18%
- Operator
- Operator 77%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence60
Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.
Perspective Coverage
7 publishers
- Builder
- Builder 19%
- Operator
- Operator 72%
- Investor
- Investor 9%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
Check Point's deobfuscation of 23 compiled V8 bytecode samples shows JSCeal replaying stolen cookies inside the victim's own browser profile, then stuffing local credentials at any password prompt until it holds a fresh OAuth token.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives45
- Confidence63
Hudson Rock and ADAMnetworks link the ads to an operation they call PasteSwitch, which hands Windows and macOS visitors different paste-this-command lures and swaps payloads on the backend depending on who arrives.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 65%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+8
- Incentives50
- Confidence72
Arctic Wolf Labs found injected iframes on real Ukrainian business sites showing a Ukrainian-language fake Cloudflare check that copies a Windows Installer command for the visitor to paste into Run. Its exposed panel logged 557 views.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 64%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption14
- Hype gap+8
- Incentives35
- Confidence64
LastPass traced a fake Authenticator hosted on GitHub to a months-long impersonation campaign that spoofed at least 40 organizations, including its own brand. The server steering victims to the download was still being updated in September.
Perspective Coverage
4 publishers
- Builder
- Builder 27%
- Operator
- Operator 64%
- Investor
- Investor 9%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence70
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58
LastPass and Delphos Labs say a single malware-as-a-service kit impersonated at least 40 companies on GitHub, and the kernel driver it delivered was Microsoft-attested and undetected by every engine on VirusTotal.
Publishers:blog.lastpass.com
Reality
- Evidence62
- Adoption48
- Hype gap+12
- Incentives68
- Confidence55
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
SpyCloud measured stolen-credential exposure across 10,000 EPA-registered water and wastewater organizations and found it at nearly one in five, with the sharpest single case sitting on a supplier's machine.
Reality
- Evidence58
- Adoption25
- Hype gap+18
- Incentives72
- Confidence52
FlashPoint pulled 555 AI-service tokens out of a single 44,791-token stealer dump, 24 of them still valid, and five dollars is the Telegram bulk price because a copied session leaves the victim's own login working.
Reality
- Evidence22
- Adoption30
- Hype gap+45
- Incentives55
- Confidence28
Japan, Germany, Australia and the US say one North Korean group infected 30,000 devices in more than 100 countries to steal $10.7 million, a thin cash yield that points at the identity documents it also took.
Reality
- Evidence60
- Adoption68
- Hype gap+12
- Incentives55
- Confidence58
Earlier coverage
- Forged government requests pulled passport data out of Revolut for five months
Security · September 17, 2026 · 1 publisher
- Software priced 610,000 stolen Roblox accounts by what was inside them
Security · September 16, 2026 · 1 publisher
- Three malware campaigns stage their lure pages on Claude and ChatGPT share links
Build · September 11, 2026 · 1 publisher
- REVSTEALER-linked module LockAppHost disables 18 Windows update and malware-removal mechanisms before mining
Security · September 7, 2026 · 1 publisher
- Talos splits security burnout into four injuries with four different fixes
Security · September 10, 2026 · 1 publisher
- Replayed session cookies bypassed the conditional access that blocked stolen passwords
Security · September 10, 2026 · 1 publisher
- Stealer logs now carry AI session tokens that replay straight past MFA
Security · September 9, 2026 · 1 publisher
- Anthropic suspended a consultant's Claude account for two weeks to stop a token thief
Product · September 8, 2026 · 1 publisher
- Talos ties a fake Google CAPTCHA to a DLL executing from a remote WebDAV share
Security · September 8, 2026 · 1 publisher
- Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript
Product · September 8, 2026 · 1 publisher
- Anthropic says everyday infostealers are lifting live Claude sessions off victim machines
Security · September 4, 2026 · 1 publisher
- RevStealer spread via fake free Claude Opus 5 desktop build on GitHub
Security · September 1, 2026 · 2 publishers
- Fake macOS troubleshooting posts route infostealers past Gatekeeper
Leadership · August 31, 2026 · 1 publisher
- ClickFix scales by asking employees to paste the command themselves
Leadership · August 31, 2026 · 1 publisher
- Anthropic wipes saved cards after infostealers copy Claude login sessions
Product · August 31, 2026 · 1 publisher
- The fake Qwen repo undershot its advertised weights by a factor of 34,000
Invest · August 28, 2026 · 1 publisher
- GitVenom dressed hundreds of repositories over several years to ship AsyncRAT and Quasar
Build · August 27, 2026 · 1 publisher
- WSL is a working bridge, and npm hygiene stops at the container wall
Security · August 26, 2026 · 1 publisher
- A trailer date is a campaign schedule: fake GTA 6 sites are selling stolen session cookies
Security · August 24, 2026 · 1 publisher
- Google: Russia-linked crews get targets to hand over app passwords, OAuth codes and WhatsApp devices
Build · August 21, 2026 · 1 publisher
- Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one
Security · August 21, 2026 · 2 publishers
- AmnesiaStealer drives your own browser, so session theft is the real macOS loss
Build · August 14, 2026 · 1 publisher