← All Intelligence

Credential Theft Threat Intelligence

13 briefings0 vulnerability reports

Credential theft through password spraying, brute force, infostealer malware, and phishing is a primary attack vector enabling unauthorized access. defend.network tracks credential theft campaigns, compromised credential dumps, and authentication bypass techniques that affect enterprise environments.

13
briefings
0
critical
6
high
14%
of all briefings

Threat Briefings

2026-06-18

Microsoft Defender zero-day, FortiBleed exposes 73k devices, GitHub worm spreads

Microsoft Defender privilege-escalation zero-day CVE-2026-50656 (patch pending). FortiBleed leaks credentials for 73,932 Fortinet devices; attackers actively harvesting access across 200 countries. GitHub supply-chain worm exploiting dismissed design flaws compromises hundreds of packages.

2026-06-04

Google Gemini prompt injection, Microsoft 365 token theft, Redis RCE patched

Google Gemini voice assistant hijackable via poisoned notifications; Microsoft 365 Android apps leak tokens; Redis RCE (CVE-2026-23479) patched; critical fuel tank systems under active attack.

2026-05-31

Active exploits: Palo Alto GlobalProtect, CISA credential leak, Linux kernel RCE

Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.

2026-05-29

FortiClient EMS, GitHub secrets, CISA breach: critical exploitation ongoing

FortiClient EMS actively exploited to deploy credential stealer; CISA contractor leaked AWS GovCloud keys on GitHub; BTMOB Android RAT spreading via phishing with builder interface.

2026-05-28

FortiClient EMS, Gogs RCE actively exploited; CISA GitHub leak exposes AWS keys

FortiClient EMS and Gogs RCE vulnerabilities actively exploited in the wild. CISA contractor exposed AWS GovCloud credentials on GitHub. FIFA World Cup fraud campaigns register 4,300+ malicious domains.

2026-05-02

cPanel auth bypass; state token harvesting; SaaS extortion attacks

Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.

2026-04-30

SAP npm compromise; cPanel auth bypass; DPRK AI-assisted malware

Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.

2026-04-24

Bitwarden CLI & Checkmarx compromised; Russian Office 365 token theft

Critical supply-chain compromises affecting Bitwarden CLI and Checkmarx tools; Russian state actors harvesting Office 365 tokens; AI-powered attacks outpacing human response capabilities.

2026-04-22

Russian APT token theft; Gentlemen ransomware claims 1,570 victims

Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.

2026-04-20

Defender zero-day; protobuf.js RCE; APT28 hits Ukrainian government

Critical Microsoft Defender zero-days actively exploited, 68% of cloud breaches from unmanaged service accounts, Russian state actors harvesting Office tokens, protobuf.js RCE with public exploit, APT28 targeting Ukrainian government.

2026-04-19

Microsoft Defender zero-days; 68% cloud breaches from ghost identities

Critical Microsoft Defender zero-days under active exploitation, 68% of cloud breaches from unmanaged service accounts, and Russian state-sponsored token harvesting campaigns demand immediate action.

2026-04-08

APT28 DNS hijack via routers; Iran hits PLCs; Docker RCE

Russian APT28 conducting large-scale DNS hijacking via compromised routers for token theft; Iranian hackers targeting U.S. critical infrastructure PLCs; critical Docker and Flowise vulnerabilities under active exploitation.

2026-04-03

Next.js, Cisco IMC, Progress ShareFile exploited; $280M DPRK theft

Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.