Password Spraying Attacks Rise As Attackers Target Microsoft Azure MFA Gaps
Huntress has reported a 155x increase in password spraying attacks during 2026, with attackers exploiting Azure CLI access and gaps in MFA protection.
Huntress has reported a 155x increase in password spraying attacks during 2026, with attackers exploiting Azure CLI access and gaps in MFA protection.
CloudSEK has revealed that malicious LiteLLM releases linked to the Trivy supply chain attack may have exposed more than 2,100 organizations by stealing cloud credentials, API keys, and other sensitive secrets.
A security researcher has disclosed three patched vulnerabilities in OpenClaw that could enable credential theft, privilege escalation, and arbitrary code execution through a WhatsApp to host attack chain.
Researchers have uncovered RedWing, a new Android malware operation distributed through Telegram that enables cybercriminals to steal banking credentials, intercept one time codes, and remotely control infected devices.
Researchers have uncovered QuimaRAT, a new Java based malware as a service platform that targets Windows, Linux, and macOS with modular plugins, credential theft, persistence, and remote control capabilities.
Security researchers have identified Umbrij malware used by ToddyCat APT to exploit OAuth tokens and browser sessions via Google API, enabling covert access to Gmail corporate communications.
Security researchers have discovered PamStealer, a macOS infostealer using fake Maccy websites, AppleScript loaders, and PAM validation to steal login passwords and sensitive data.
Kaspersky has uncovered the StrikeShark campaign using the newly identified SharkLoader malware to deploy Cobalt Strike across government, diplomatic, and enterprise organizations by exploiting multiple public facing vulnerabilities.
Kaspersky has urged Pakistani companies to adopt digital risk protection services after new research revealed that user behavior continues to drive infostealer infections and credential theft incidents.
CISA has issued an advisory after the FortiBleed campaign compromised 86,644 FortiGate devices worldwide, exposing organizations across telecom, government, and education sectors to credential theft and unauthorized access.