credentials
7 stories
Hundreds of leaked AWS keys give full control over corporate accounts
Truffle Security has identified over 9,300 active AWS access keys exposed publicly between August 2022 and August 2026. Of these, 817 keys were linked to companies, with 526 being root keys and 242 granting full administrative privileges. This level of access allows attackers to potentially steal, delete, or manipulate cloud data and services, or deploy resource-intensive applications like cryptominers.

Malware injected into popular Rust packages to steal developer credentials
Malicious actors have compromised several widely-used Rust packages, including arrayref, internment, and append-only-vec, by injecting malware into their build scripts. These poisoned packages, disguised as legitimate updates, were designed to steal developers' credentials. The attack leveraged a typosquatted dependency, proc-macro1, which fetched malware from a remote server during the compilation process. The compromised packages were quickly removed from the registry, but their popularity raises concerns about the potential impact on developers.

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
A newly identified botnet written in Go, dubbed NadMesh, is actively scanning for and exploiting exposed AI services. The botnet specifically targets cloud environments, seeking to steal AWS keys and Kubernetes tokens from vulnerable AI platforms. Researchers have observed it scanning for services like ComfyUI and Ollama, which are often deployed without adequate security measures.

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

Telco giant KDDI says data breach affects over 12 million people
KDDI, a major Japanese telecommunications company, has reported a significant data breach impacting over 12 million individuals. The breach occurred on an email platform utilized by five national internet service providers, resulting in the exposure of email addresses and passwords.

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.