credentials

Product showcase: GitGuardian Honeytoken catches credential theft as it happens

Product showcase: GitGuardian Honeytoken catches credential theft as it happens 2026-09-10 at 08:30 By Help Net Security Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, […]

Product showcase: GitGuardian Honeytoken catches credential theft as it happens Read More »

This Key Will Self-Destruct: An Open Standard for Revocable API Keys

This Key Will Self-Destruct: An Open Standard for Revocable API Keys 2026-09-09 at 13:00 By Matt Honea Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on […]

This Key Will Self-Destruct: An Open Standard for Revocable API Keys Read More »

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents 2026-09-08 at 08:00 By Help Net Security Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and MCP servers broker access to databases, cloud providers, and […]

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are posing as AI crawlers to hunt for exposed credentials 2026-08-31 at 17:54 By Sinisa Markovic Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits […]

Threat actors are posing as AI crawlers to hunt for exposed credentials Read More »

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model 2026-08-10 at 08:00 By Anamarija Pogorelec Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the […]

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model Read More »

Buying TikTok followers can expose users to scams and account theft

Buying TikTok followers can expose users to scams and account theft 2026-08-03 at 07:00 By Anamarija Pogorelec Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The […]

Buying TikTok followers can expose users to scams and account theft Read More »

Exposed credentials are giving attackers a head start many organizations don’t see

Exposed credentials are giving attackers a head start many organizations don’t see 2026-07-30 at 07:00 By Anamarija Pogorelec Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring […]

Exposed credentials are giving attackers a head start many organizations don’t see Read More »

Claude can now sign into websites with 1Password without exposing your credentials

Claude can now sign into websites with 1Password without exposing your credentials 2026-07-17 at 12:17 By Anamarija Pogorelec 1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max, Team, […]

Claude can now sign into websites with 1Password without exposing your credentials Read More »

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. […]

Ransom demands are down, email is the top way attackers get in Read More »

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware 2026-07-15 at 16:52 By Zeljka Zorz A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, […]

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware Read More »

Fake OAuth client IDs are helping attackers slip past sign-in logs

Fake OAuth client IDs are helping attackers slip past sign-in logs 2026-07-13 at 15:10 By Mirko Zorz Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as […]

Fake OAuth client IDs are helping attackers slip past sign-in logs Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud […]

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

FortiBleed: 86,000 Fortinet Device Credentials Compromised

FortiBleed: 86,000 Fortinet Device Credentials Compromised 2026-06-19 at 13:48 By Ionut Arghire The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

FortiBleed: 86,000 Fortinet Device Credentials Compromised Read More »

74,000 Fortinet firewall credentials exposed in FortiBleed data leak

74,000 Fortinet firewall credentials exposed in FortiBleed data leak 2026-06-18 at 15:10 By Zeljka Zorz A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, […]

74,000 Fortinet firewall credentials exposed in FortiBleed data leak Read More »

Microsoft Entra pushes passkeys, tightens identity security

Microsoft Entra pushes passkeys, tightens identity security 2026-06-02 at 15:47 By Anamarija Pogorelec Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication updates Phishing-resistant […]

Microsoft Entra pushes passkeys, tightens identity security Read More »

New infostealer reaches enterprise devices through FortiClient EMS vulnerability

New infostealer reaches enterprise devices through FortiClient EMS vulnerability 2026-05-29 at 18:31 By Zeljka Zorz Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” Arctic Wold […]

New infostealer reaches enterprise devices through FortiClient EMS vulnerability Read More »

Deleted Google API keys keep working for up to 23 minutes, researchers warn

Deleted Google API keys keep working for up to 23 minutes, researchers warn 2026-05-22 at 15:08 By Zeljka Zorz Google API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if […]

Deleted Google API keys keep working for up to 23 minutes, researchers warn Read More »

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector 2026-05-20 at 17:16 By Zeljka Zorz Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the […]

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Read More »

Over 70% of organizations hit by identity breaches

Over 70% of organizations hit by identity breaches 2026-05-14 at 07:30 By Anamarija Pogorelec Attackers rely on stolen credentials, compromised service accounts, and social engineering attacks targeting employees, according to Sophos’ The State of Identity Security 2026 survey. What do you estimate to be the overall cost to your organization to rectify the identity breach? […]

Over 70% of organizations hit by identity breaches Read More »

Scroll to Top