New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, ...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
177 articles found
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, ...
The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 11...
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws...
Security researchers have revealed a vulnerability chain known as “SalesBleed,” associated with Salesforce’s Agentforce. This vulnerability could allow attac...
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultima...
ShinyHunters claims it stole 2 TB of sensitive data on thousands of current and former FBI agents.
OpenAI’s new ChatGPT Computer History feature for macOS aims to enhance AI assistance by making it more context-aware. However, it also creates a potential r...
The TASK#STOMP campaign begins with an encoded Visual Basic Script (VBScript) executed by wscript.exe, with the initial access vector likely being phishing o...
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and ...
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers...
The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appe...
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability...
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell comm...
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive ...
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S.
ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS to deface the Clop Tor site with ASCII art of its Umbreon logo.
HEAVYGRAM is a versatile tool capable of remote command execution, system and network information discovery, data exfiltration, screenshot capture, and estab...
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data f...