#Credentialstealing
Incredibile a dirsi, ma le campagne di #phishing mirato e il #credentialstealing ha prodotto un aumento degli attacchi in Italia per il mese di marzo.

Grazie #ACN che li proteggi e grazie #GarantePrivacy che li sanzioni a dovere!

@sonoclaudio.ransomnews.online @garantepiracy.it
🚨 Attacchi italiani rivendicati

📊 gli attacchi ai danni di aziende italiane 🇮🇹, nei primi tre mesi, hanno subito un netto incremento a marzo 2025.

📌 si considerano tutte le rivendicazioni pubblicate dai threat actors, tracciate e confermate
🔗 i dataset degli ultimi mesi sono qui: rnws.online/YyZGM
May 18, 2025 at 2:26 PM
April 6, 2026 at 1:35 PM
AI agents didn't stop when their exploits failed - they rewrote tools and kept attacking for days. https://intel.threadlinqs.com/threat/TL-2026-2030 #ThreatIntel #CVE_2026_65617 #CVE_2026_65921 #Credentialstealing
August 16, 2026 at 4:27 PM
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device #Credential #Credentialstealing #CredentialTheft
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device
 Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had stored login information on a personal device. The ShinyHunters cybercriminal organization claimed on Monday that it had obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV).  The department did not respond to repeated requests for comment throughout the week but publicly confirmed the breach's legitimacy on Thursday night. Officials said they first learned of the breach on September 4 and initially attributed it to an unnamed "international cybercriminal organization."  According to the department, an investigation determined that a criminal actor exploited a single Plant City Police Department user's credentials, which had been improperly stored on the employee's personal electronic device. Plant City is a small suburb outside Tampa. FLHSMV has since notified other Florida government offices and is partnering with the Florida Digital Service to investigate the incident.  As proof of access, ShinyHunters shared alleged photos of a DMV record tied to American financier and convicted child sex offender Jeffrey Epstein. When claims of the breach first surfaced, some cybersecurity experts speculated it might be connected to the recently confirmed breach involving 153 million driver's licenses leaked by identity verification firm IDScan. ShinyHunters had previously attempted to purchase the ID database from the hackers behind the IDScan breach. The group has recently claimed responsibility for attacks on bank IT provider Jack Henry, as well as pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units had been stolen. ShinyHunters also caused widespread disruption across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after targeting the world's largest medical device company in April.  Other victims linked to the group include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In a related development, artificial intelligence company Anthropic released a report Thursday stating that suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes.  The report noted that in one case, an operator escalated from a stolen developer token to full administrative access over a victim's cloud environment in approximately three hours. Incident responders at Google also confirmed last week that members of the group are using Anthropic's AI tools at various stages of their attacks.  The Florida breach adds to a growing list of incidents tied to ShinyHunters, underscoring the group's persistent targeting of both government systems and major corporations, as well as its evolving use of AI tools to accelerate and scale its intrusions.
dlvr.it
September 13, 2026 at 3:38 PM
Think Hotel Wi-Fi Is Safe? Hackers Have Several Ways to Prove You Wrong #Credentialstealing #fakenetwork #FBI
Think Hotel Wi-Fi Is Safe? Hackers Have Several Ways to Prove You Wrong
  For many travelers, connecting to hotel Wi-Fi is one of the first things they do after checking in. But while some guests use the network for banking and work, others avoid sensitive activity unless they are connected through a VPN. So, how safe is hotel Wi-Fi? Cybersecurity experts say the answer is more nuanced than simply calling public Wi-Fi dangerous. Modern encryption has reduced many of the risks associated with public networks, but hotel Wi-Fi can still expose travelers to rogue networks, phishing attacks, poorly configured infrastructure and vulnerable devices. In many cases, the biggest risk may not be the network itself, but how the user connects to and behaves on it. The first risk can come from a fake network Security analyst Udaya Vemuri advises travelers to be cautious about joining a network simply because its name appears to belong to the hotel. Attackers can create fake Wi-Fi networks with names almost identical to legitimate hotel networks. The technique, known as an "evil twin" attack, can trick guests into connecting to an attacker-controlled access point. The FBI's Internet Crime Complaint Center warned about this threat in a 2020 advisory, noting that criminals can create networks resembling legitimate hotel Wi-Fi and potentially monitor activity or redirect victims to fraudulent login pages. The agency also warned that hotel guests have limited control over the security of the infrastructure they are using, which may prioritize convenience over stronger security practices. Travelers should therefore confirm the exact Wi-Fi name with hotel staff before connecting rather than selecting the network that merely looks familiar. Simply sharing a network does not mean you are compromised Dahvid Schloss, chief operating officer of cybersecurity firm Suzu Labs and a former government hacker who has security-tested hotel chains, takes a less alarmist view. Schloss compares hotel Wi-Fi with other public networks, such as those in coffee shops. In his assessment, the likelihood of being attacked simply because another malicious user is connected to the same network is low. That distinction matters because the common image of hackers automatically reading passwords from public Wi-Fi is outdated. The Federal Trade Commission says most websites now use encryption, meaning information sent between a device and a legitimate website is generally protected even when the underlying network is public. HTTPS can therefore provide substantial protection against traffic interception. However, HTTPS does not prove that a website is legitimate. Attackers can create encrypted fraudulent websites and use phishing or redirection to persuade victims to submit credentials. This means a traveler can still be exposed even when the connection itself appears encrypted. Fake hotel portals can steal credentials Hotels commonly use captive portals that redirect guests to a webpage after they connect to Wi-Fi. These pages may request a room number, surname, email address or access code. Because travelers expect this process, attackers can imitate it. A rogue network may display a fake hotel login page or redirect users to a fraudulent Microsoft 365, email or banking page. In such cases, the attacker does not necessarily need to break encryption. The victim may simply be tricked into providing the information. This makes phishing and social engineering an important part of the hotel Wi-Fi threat. Network security is not a perfect guarantee Recent research also shows why travelers should not assume that network-level protections make public Wi-Fi completely secure. Researchers at the University of California, Riverside reported in February 2026 that weaknesses in Wi-Fi client isolation can, under certain conditions, allow attackers to bypass protections designed to prevent devices on the same network from interacting with one another. Their AirSnitch research demonstrated techniques that could potentially allow an attacker to intercept or manipulate traffic despite client isolation. The findings do not mean every hotel network is vulnerable, but they reinforce an important point: users should not rely entirely on the security mechanisms implemented by a public network. Your device can be the weakest link Both experts place considerable emphasis on user behavior. Schloss argues that laptops can be particularly vulnerable to poor security habits because they are frequently used to download files, install software and access corporate systems. Smartphones are not immune, but their operating systems often impose stronger application restrictions. The FBI recommends updating operating systems and applications before travel, keeping security software current, backing up important data, disabling Bluetooth when unnecessary and preventing devices from automatically reconnecting to public networks. Automatic reconnection is particularly important because a device may join a previously saved network without the user consciously verifying that it is legitimate. Browser warnings should also never be ignored. A certificate warning, unexpected redirect or request to install software can indicate that something is wrong with the connection or destination. Use cellular data for sensitive activity Vemuri takes a more cautious approach when handling sensitive information. For banking, work systems and other private activity, he uses a mobile hotspot instead of hotel Wi-Fi. When hotel Wi-Fi is unavoidable, he keeps devices updated, enables multifactor authentication and avoids sensitive tasks. The FBI similarly recommends using a phone's hotspot instead of hotel Wi-Fi when possible, particularly for sensitive activity and telework. A cellular hotspot is not completely immune to cyber threats, but it removes the user from the hotel's shared wireless environment and reduces exposure to risks associated with public Wi-Fi. A VPN and MFA can add protection For travelers who need to use hotel Wi-Fi, a reputable VPN can provide another layer of security by encrypting traffic between the device and the VPN provider. The FBI recommends reputable VPNs for telework over hotel Wi-Fi. A VPN is not a substitute for other security measures, however. It cannot prevent phishing, malware downloads or users from voluntarily entering credentials into fraudulent websites. Multifactor authentication can limit the damage if a password is compromised. The FBI recommends MFA for sensitive accounts and advises users to enable login notifications so suspicious activity can be detected quickly. Travelers should configure MFA before leaving home rather than waiting until they are already on the road. What travelers should do Before connecting to hotel Wi-Fi, users should: * Confirm the legitimate network name with hotel staff. * Update their operating system, browser and applications. * Disable automatic connection to public networks. * Enable MFA and account security alerts. * Use a cellular hotspot for banking and highly sensitive activity where possible. * Use a reputable VPN for sensitive work when hotel Wi-Fi is unavoidable. * Verify the website address and HTTPS before entering credentials. * Avoid unfamiliar downloads or software updates prompted by Wi-Fi portals. * Disable Bluetooth when it is not needed. * Never bypass browser security warnings. So, is hotel Wi-Fi safe? Hotel Wi-Fi is not automatically dangerous, but it should not be treated as a trusted network either. Simply sharing a network with an attacker does not mean a modern device will automatically be compromised, particularly when legitimate services use encryption. At the same time, rogue access points, fake captive portals, phishing, vulnerable devices and weaknesses in network isolation can create opportunities for attackers. For routine browsing, an updated device using legitimate HTTPS websites can be reasonably protected. For banking, corporate systems and other highly sensitive activity, using a cellular hotspot remains the more cautious option. The practical rule for travelers is simple: do not panic about hotel Wi-Fi, but do not trust it blindly either. Verify the network, secure your devices and accounts, and keep sensitive activity off shared networks whenever possible.
dlvr.it
August 9, 2026 at 6:20 PM
Malicious Go Package Disguised as SSH Tool Steals Credentials via Telegram #Bruteforceattack #Credentialstealing #DataBreach
Malicious Go Package Disguised as SSH Tool Steals Credentials via Telegram
 Researchers have uncovered a malicious Go package disguised as an SSH brute-force tool that secretly collects and transmits stolen credentials to an attacker-controlled Telegram bot. The package, named golang-random-ip-ssh-bruteforce, first appeared on June 24, 2022, and was linked to a developer under the alias IllDieAnyway. Although the GitHub profile tied to this account has since been removed, the package is still accessible through Go’s official registry, raising concerns about supply chain security risks for developers who might unknowingly use it.  The module is designed to scan random IPv4 addresses in search of SSH services operating on TCP port 22. Once it detects a running service, it attempts brute-force login using only two usernames, “root” and “admin,” combined with a list of weak and commonly used passwords. These include phrases such as “root,” “test,” “password,” “admin,” “12345678,” “1234,” “qwerty,” “webadmin,” “webmaster,” “techsupport,” “letmein,” and “Passw@rd.” If login succeeds, the malware immediately exfiltrates the target server’s IP address, username, and password through Telegram’s API to a bot called @sshZXC_bot, which forwards the stolen information to a user identified as @io_ping. Since Telegram communications are encrypted via HTTPS, the credential theft blends into ordinary web traffic, making detection much more difficult.  The design of the tool helps it remain stealthy while maximizing efficiency. To bypass host identity checks, the module disables SSH host key verification by setting ssh.InsecureIgnoreHostKey as its callback. It continuously generates IPv4 addresses while attempting concurrent logins in an endless loop, increasing the chances of finding vulnerable servers. Interestingly, once it captures valid credentials for the first time, the malware terminates itself. This tactic minimizes its exposure, helping it avoid detection by defenders monitoring for sustained brute-force activity.  Archival evidence suggests that the creator of this package has been active in the underground hacking community for years. Records link the developer to the release of multiple offensive tools, including an IP port scanner, an Instagram parser, and Selica-C2, a PHP-based botnet for command-and-control operations. Associated videos show tutorials on exploiting Telegram bots and launching SMS bomber attacks on Russian platforms. Analysts believe the attacker is likely of Russian origin, based on the language, platforms, and content of their activity.  Security researchers warn that this Trojanized Go module represents a clear supply chain risk. Developers who unknowingly integrate it into their projects could unintentionally expose sensitive credentials to attackers, since the exfiltration traffic is hidden within legitimate encrypted HTTPS connections. This case underscores the growing threat of malicious open-source packages being planted in widely used ecosystems, where unsuspecting developers become conduits for large-scale credential theft.
dlvr.it
September 3, 2025 at 3:42 PM
Cybercriminals Shift Tactics Towards Stealth and Identity Theft: IBM X-Force 2025 Report #Credentialstealing #CyberSecurity #Cybersecurity
Cybercriminals Shift Tactics Towards Stealth and Identity Theft: IBM X-Force 2025 Report
  iThe IBM X-Force 2025 Threat Intelligence Index highlights a growing trend of cybercriminals adopting more covert attack strategies. Drawing from analysis of over 150 billion security events daily across 130+ countries, the report notes an 84% spike in email-delivered infostealers in 2024 compared to the previous year. This surge signals a marked pivot towards credential theft, even as enterprise-targeted ransomware attacks show a notable decline. “Cybercriminals are most often breaking in without breaking anything – capitalising on identity gaps overflowing from complex hybrid cloud environments that offer attackers multiple access points,” said IBM cybersecurity services global managing partner Mark Hughes. “Businesses need to shift away from an ad-hoc prevention mindset and focus on proactive measures such as modernising authentication management, plugging multi-factor authentication holes and conducting real-time threat hunting to uncover hidden threats before they expose sensitive data.” The report found that critical infrastructure organisations bore the brunt of attacks, accounting for 70% of incidents handled by IBM X-Force last year. More than a quarter of these breaches exploited system vulnerabilities. Data theft (18%) overtook encryption-based attacks (11%) as the preferred method, reflecting improvements in detection tools and increased law enforcement pressure, which have forced threat actors to rethink their strategies. Asia and North America emerged as the primary targets, together representing almost 60% of all global attacks. Asia faced 34% of the incidents, while North America encountered 24%. For the fourth consecutive year, the manufacturing industry remained the most impacted sector, attributed to its sensitivity to operational disruptions and susceptibility to ransomware. Emerging AI-related threats also garnered attention. Although no major AI-focused attacks surfaced in 2024, security teams are racing to find and patch vulnerabilities before they are exploited. A critical remote code execution flaw within an AI development framework is expected to gain traction in 2025 as adoption grows. Experts warn that attackers may soon develop dedicated toolkits aimed specifically at AI systems, underlining the urgent need to secure AI infrastructure.Persistent challenges in critical infrastructure security largely stem from outdated technologies and delayed patch management. IBM X-Force revealed that vulnerabilities accounted for over 25% of exploited incidents. Analyzing discussions on dark web forums showed that four of the ten most talked-about CVEs were associated with advanced threat groups, including state-sponsored actors, escalating the risks of disruption and extortion. Research in collaboration with Red Hat Insights found that over 50% of Red Hat Enterprise Linux users had not patched at least one critical vulnerability, with 18% leaving five or more critical CVEs unaddressed. Moreover, ransomware variants like Akira, Lockbit, Clop, and RansomHub have expanded their capabilities to affect both Windows and Linux systems. A sharp rise in phishing campaigns distributing infostealers was another key finding, with a 180% jump compared to 2023. The use of credential phishing and infostealers enables hackers to swiftly exfiltrate sensitive information while maintaining a low profile. While ransomware still accounted for 28% of malware attacks in 2024, its overall prevalence declined compared to previous years. Cybercriminals are increasingly shifting towards identity-based attacks, adapting to countermeasures that have made traditional ransomware operations more difficult.
dlvr.it
April 28, 2025 at 6:18 PM
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet cod...

#Finance #code #credentialstealing #Dev #dormant #hijacks […]

[Original post on zephyrnet.com]
June 19, 2025 at 3:57 AM