Credential theft through password spraying, brute force, infostealer malware, and phishing is a primary attack vector enabling unauthorized access. defend.network tracks credential theft campaigns, compromised credential dumps, and authentication bypass techniques that affect enterprise environments.
Cisco Secure Email Gateway SQL injection added to CISA KEV; Acronis cPanel plugin flaw exploited; Brazilian banking malware KREMLIN targets Chrome and Edge for session theft.
GitLab path-traversal flaw (CVSS 10.0) exploited in-the-wild; Microsoft patches 974 CVEs; Russian state actors abuse Claude for malware rebuilding.
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
Cisco Secure FMC flaw CVE-2026-20079 under active attack; four China-linked espionage groups deployed BlueMoon exploit kit targeting Chrome and Windows; AI user accounts hijacked via infostealer logs to bypass MFA.
Microsoft released 974 security patches including two actively exploited zero-days. AI-driven credential harvesting compromised thousands of accounts in six hours. F5 BIG-IP devices are being breached to deploy Linux rootkits.
PEEP toolkit turns Chrome and Edge into post-compromise backdoors; Magento StyleSmuggler zero-day actively exploited to deploy Linux backdoors; BigBear phishing framework bypassed MFA at 258 organizations and stole 5,000+ Microsoft 365 credentials.
MikroTik routers hijacked without authentication; Magento/Adobe Commerce zero-day in active exploitation; REVSTEALER disables Defender to mine crypto; Chromium V8 in CISA KEV.
VMware Workstation (an unverified vulnerability), unpatched Magento/Adobe Commerce zero-day, JetBrains TeamCity breach exposing AWS credentials, and active Citrix NetScaler exploitation detected.
Cisco patches critical Nexus 9000 unauthenticated RCE affecting 10 Silicon One switches; HPE releases 8 CVEs in ArubaOS-CX. Coder's Cloudflare infrastructure hijacked to distribute malicious Terraform modules. 153M+ driver licenses offered on dark web.
JFrog Artifactory CVE-2026-82329 (CVSS 9.8) exploited to mint admin tokens; Langflow CVE-2026-0768 RCE active for API key theft. Two alleged TeamPCP supply-chain attackers arrested in Australia. iOS spyware campaign harvesting wallet seeds.
Infostealer malware targets Anthropic and Microsoft users; Aurora ransomware gang deploys Cursor AI; North Korean threat actors expand beyond IT into healthcare and sales.
$320/month subscription model.
Mirage2FA phishing toolkit has compromised 4,500 US/EU organizations via Microsoft 365 spoofing; Oracle Weblogic Server vulnerability (CVE-2026-21962) added to CISA KEV with 3-day patch deadline; NVIDIA NemoClaw vulnerable to unauthenticated model poisoning.
Red Hat patches critical Keycloak account-takeover flaw; Microsoft releases 398 patches including one under active exploitation; WordlistLoader and SynkLoader malware families accelerate ransomware-adjacent payload delivery via ClickFix.
Android car head units infected via malware-laden firmware updates; 9,300+ AWS keys remain active; Snowflake extortionist pleads guilty after compromising 165+ organizations.
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
Microsoft Copilot Personal one-click data exfiltration flaws disclosed. MLflow and FUXA critical vulnerabilities exploited for cloud credential theft. Windows Task Host now actively exploited by ransomware gangs.
GitLab patched critical GraphQL flaw; Forminator WordPress plugin RCE affects 600K+ sites; threat actor claims 3.6M Azure account records stolen from Fortune 500 companies.
Nearly 800 malicious npm packages deliver cross-platform RAT/infostealer; Metabase SQL injection exploited at Framework and Tally; UNC6671 extortion group rebrands across Redact, Pink, Helix, Falcon operations after millions in vishing revenue.
Malware on Windows machines can hijack Google-synced passkeys without verification. Russian APT29 is actively compromising hotel Wi-Fi globally to steal Microsoft 365 credentials. N-able N-central RMM faces active CVE-2026-18577 exploitation with a second bypass vector discovered post-patch.
Microsoft research exposes AI agent manipulation via poisoned tool descriptions; Langflow RCE (CVE-2026-33017) actively exploited for Monero mining; six critical shell-injection bypasses discovered in open-source AI coding agents.
Oracle PeopleSoft zero-day exploited at Nissan and NAIC; malicious Chrome extension intercepted searches and address bar input; Mustang Panda uses Zoho WorkDrive in Indian government campaigns.
Russian intelligence phishing now targets Signal Backup Recovery Keys. Linux kernel privilege escalation (CVE-2026-46331) has working exploit. AWS Q flaw (CVE-2026-12957, CVSS 8.5) allows malicious repos to steal cloud credentials.
FortiBleed credential-harvesting campaign collected 110 million credentials from 430
Microsoft Defender privilege-escalation zero-day CVE-2026-50656 (patch pending). FortiBleed leaks credentials for 73,932 Fortinet devices; attackers actively harvesting access across 200 countries. GitHub supply-chain worm exploiting dismissed design flaws compromises hundreds of packages.
Google Gemini voice assistant hijackable via poisoned notifications; Microsoft 365 Android apps leak tokens; Redis RCE (CVE-2026-23479) patched; critical fuel tank systems under active attack.
Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.
FortiClient EMS actively exploited to deploy credential stealer; CISA contractor leaked AWS GovCloud keys on GitHub; BTMOB Android RAT spreading via phishing with builder interface.
FortiClient EMS and Gogs RCE vulnerabilities actively exploited in the wild. CISA contractor exposed AWS GovCloud credentials on GitHub. FIFA World Cup fraud campaigns register 4,300+ malicious domains.
Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.
Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.
Critical supply-chain compromises affecting Bitwarden CLI and Checkmarx tools; Russian state actors harvesting Office 365 tokens; AI-powered attacks outpacing human response capabilities.
Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.
Critical Microsoft Defender zero-days actively exploited, 68% of cloud breaches from unmanaged service accounts, Russian state actors harvesting Office tokens, protobuf.js RCE with public exploit, APT28 targeting Ukrainian government.
Critical Microsoft Defender zero-days under active exploitation, 68% of cloud breaches from unmanaged service accounts, and Russian state-sponsored token harvesting campaigns demand immediate action.
Russian APT28 conducting large-scale DNS hijacking via compromised routers for token theft; Iranian hackers targeting U.S. critical infrastructure PLCs; critical Docker and Flowise vulnerabilities under active exploitation.
Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts
Subscribe free and never miss a threat briefing.