LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

credential theft news

8 stories
data breachhigh

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

France's tax administration recently experienced a significant data breach, where an attacker reportedly used stolen staff passwords to access sensitive tax data. The incident, which impacted hundreds of thousands of individuals and businesses, went undetected for seven weeks. The breach was only brought to light after the attacker publicly claimed responsibility online, prompting an…

identity theft

Attackers Exploit Collaboration Tools for Identity Theft

Cybersecurity researchers have observed a significant increase in threat actors exploiting enterprise collaboration platforms for identity-focused attacks, including phishing, impersonation, credential theft, and malware delivery. Over the past year, alerts related to malicious activity involving these tools have quadrupled, indicating a growing trend in their misuse.

css attackshigh

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

A security researcher has demonstrated a series of webmail client vulnerabilities that leverage Cascading Style Sheets (CSS) to steal credentials, hijack sessions, and manipulate AI tools integrated with user inboxes. The research, conducted by Gareth Heyes of PortSwigger, details attack chains against major webmail services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL…

malwarehigh

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

A sophisticated threat actor, identified as Storm-2945, a sub-cluster of the group known as Midnight Blizzard, has reportedly initiated a global campaign dubbed "CaptiveCrunch." This operation specifically targets travelers by exploiting captive portal networks to facilitate malware delivery and credential theft. The threat actor is said to manipulate network traffic to achieve these…

north koreahigh

North Korean hackers use fake coding interviews to steal developer credentials

North Korean state-sponsored hackers are employing a sophisticated new tactic, dubbed "Contagious Interview," to compromise developers by embedding malware within seemingly benign coding challenges. The campaign, tracked as REF9403, leverages steganography to hide multi-stage payloads within SVG image files, which have gone undetected by all major antivirus vendors.

CVE-2026-20245high

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches

The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.

fifa world cup

Cybercriminals Are Targeting the FIFA World Cup 2026

Cybercriminals are actively targeting the upcoming FIFA World Cup 2026, establishing infrastructure and launching various scams to exploit the event's global appeal, according to research from FortiGuard Labs. The tournament, set to begin on June 11, 2026, is expected to attract significant attention and drive a high volume of digital transactions, creating a fertile ground for malicious actors.

CVE-2025-29927high

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts

A newly identified cloud worm, dubbed PCPJack, is actively targeting exposed cloud infrastructure to steal credentials and remove any artifacts associated with the threat actor group TeamPCP. SentinelLabs researchers discovered the framework, which operates as a credential theft toolset that propagates across cloud environments.