#credential — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #credential, aggregated by home.social.
-
The LiteLLM attack's true reach: terabytes of credentials tied to 434,000 pipelines
Follow us and never miss a story.
https://1ban.news/litellm-credential-leak-434000-pipelines-2026/
#1ban #litellm #credential #leak #434000 #tech
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm - https://www.redpacketsecurity.com/chaindrop-supply-chain-compromise-anatomy-of-a-self-propagating-worm/
#threatintel
#npm Supply Chain Attack
#Shai-Hulud Worm
#Credential Theft
#CI/CD Security
#Threat Intelligence -
ChainDrop supply chain compromise: Anatomy of a self-propagating worm - https://www.redpacketsecurity.com/chaindrop-supply-chain-compromise-anatomy-of-a-self-propagating-worm/
#threatintel
#npm Supply Chain Attack
#Shai-Hulud Worm
#Credential Theft
#CI/CD Security
#Threat Intelligence -
ACR Stealer: Two observed intrusion chains amid increased threat activity - https://www.redpacketsecurity.com/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
#threatintel
#ACR Stealer
#ClickFix
#WebDAV
#PowerShell
#Credential theft -
ACR Stealer: Two observed intrusion chains amid increased threat activity - https://www.redpacketsecurity.com/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
#threatintel
#ACR Stealer
#ClickFix
#WebDAV
#PowerShell
#Credential theft -
OneCLI – OSS credential gateway that keeps secrets out of AI agents
https://github.com/onecli/onecli
Comments: https://news.ycombinator.com/item?id=49023427
#HackerNews #OneCLI #OSS #credential #gateway #AI #secrets #security #open-source
-
OneCLI – OSS credential gateway that keeps secrets out of AI agents
https://github.com/onecli/onecli
Comments: https://news.ycombinator.com/item?id=49023427
#HackerNews #OneCLI #OSS #credential #gateway #AI #secrets #security #open-source
-
Need to securely pass secrets to shell scripts in Jenkins? Use `withCredentials` in Declarative Pipelines. This snippet binds a Secret text credential to `SECRET_API_KEY`, masking it in console logs. Jenkins 2.176+ with Credentials Binding Plugin 1.24+ required. #jenkins #declarative-pipeline #credential-binding
https://www.valtersit.com/vault/secure-credential-injection-using-withcredentials-binding-12cbc2/
-
DCSync attack: Extract all user password hashes from a Domain Controller by simulating replication via MS-DRSR. Requires Replication-Get-Changes-All privileges. Works on Windows Server 2008 R2+ DCs. #credential-access #dcsync #ValtersIT
https://www.valtersit.com/vault/extract-password-hashes-from-active-directory-via-dcsync-79bb71/
-
For the 2nd time in weeks, #Microsoft packages laced with #credential stealer
Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.
In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
#security -
For the 2nd time in weeks, #Microsoft packages laced with #credential stealer
Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.
In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
#security -
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealingcampaign - https://www.redpacketsecurity.com/preinstall-to-persistence-inside-the-red-hat-npm-miasma-credential-stealingcampaign/
#threatintel
#npm-supply-chain
#credential-theft
#Miasma
#supply-chain-security
#redhat-cloud-services -
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealingcampaign - https://www.redpacketsecurity.com/preinstall-to-persistence-inside-the-red-hat-npm-miasma-credential-stealingcampaign/
#threatintel
#npm-supply-chain
#credential-theft
#Miasma
#supply-chain-security
#redhat-cloud-services -
Typosquatted npm packages used to steal cloud and CI/CD secrets - https://www.redpacketsecurity.com/typosquatted-npm-packages-used-to-steal-cloud-and-ci-cd-secrets/
#threatintel
#typosquatting
#npm
#supply-chain-attack
#cloud-security
#credential-theft -
Typosquatted npm packages used to steal cloud and CI/CD secrets - https://www.redpacketsecurity.com/typosquatted-npm-packages-used-to-steal-cloud-and-ci-cd-secrets/
#threatintel
#typosquatting
#npm
#supply-chain-attack
#cloud-security
#credential-theft -
CVE-2026-34474: Pre-auth #credential disclosure in #ZTE #H298A / #H108N via #ETHCheat...The short version: an ETHCheat branch returns credential-bearing #HTML before #authentication. The captured fields include the #admin #password, WLAN PSK, and ESSID, and a companion wizard #endpoint #exposes serial data.
-
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5and Confluence - https://www.redpacketsecurity.com/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5and-confluence/
#threatintel
#edge-appliances
#linux-intrusion
#confluence
#credential-relay
#mitre-attack-techniques -
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5and Confluence - https://www.redpacketsecurity.com/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5and-confluence/
#threatintel
#edge-appliances
#linux-intrusion
#confluence
#credential-relay
#mitre-attack-techniques -
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft - https://www.redpacketsecurity.com/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/
#threatintel
#antv
#npm-supply-chain
#github-actions
#credential-theft
#supply-chain-security -
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft - https://www.redpacketsecurity.com/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/
#threatintel
#antv
#npm-supply-chain
#github-actions
#credential-theft
#supply-chain-security -
Undermining the trust boundary: Investigating a stealthy intrusion throughthird-party compromise - https://www.redpacketsecurity.com/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-throughthird-party-compromise/
#threatintel
#trusted-relationships
#third-party-risk
#credential-theft
#persistence
#intrusion-detection -
Undermining the trust boundary: Investigating a stealthy intrusion throughthird-party compromise - https://www.redpacketsecurity.com/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-throughthird-party-compromise/
#threatintel
#trusted-relationships
#third-party-risk
#credential-theft
#persistence
#intrusion-detection -
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTMtoken compromise - https://www.redpacketsecurity.com/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitmtoken-compromise/
#threatintel
#aiTM-phishing
#credential-theft
#phishing-attack
#adversary-in-the-middle
#cybersecurity-awareness -
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTMtoken compromise - https://www.redpacketsecurity.com/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitmtoken-compromise/
#threatintel
#aiTM-phishing
#credential-theft
#phishing-attack
#adversary-in-the-middle
#cybersecurity-awareness -
Containing a domain compromise: How predictive shielding shut down lateralmovement - https://www.redpacketsecurity.com/containing-a-domain-compromise-how-predictive-shielding-shut-down-lateralmovement/
#threatintel
#Predictive Shielding
#Domain Compromise
#Credential-Based Attacks
#Active Directory Security
#Incident Response -
Containing a domain compromise: How predictive shielding shut down lateralmovement - https://www.redpacketsecurity.com/containing-a-domain-compromise-how-predictive-shielding-shut-down-lateralmovement/
#threatintel
#Predictive Shielding
#Domain Compromise
#Credential-Based Attacks
#Active Directory Security
#Incident Response -
Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise - https://www.redpacketsecurity.com/dissecting-sapphire-sleet-s-macos-intrusion-from-lure-to-compromise/
#threatintel
#sapphire-sleet
#macos
#social-engineering
#credential-harvest
#exfiltration -
Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise - https://www.redpacketsecurity.com/dissecting-sapphire-sleet-s-macos-intrusion-from-lure-to-compromise/
#threatintel
#sapphire-sleet
#macos
#social-engineering
#credential-harvest
#exfiltration -
Thousands of consumer #routers hacked by Russia's #military
The Russian military is once again #hacking home and small office routers in widespread operations that send unwitting users to sites that harvest #passwords and #credential tokens for use in #espionage campaigns, researchers said Tuesday.
#russia #security #privacy #gru -
Thousands of consumer #routers hacked by Russia's #military
The Russian military is once again #hacking home and small office routers in widespread operations that send unwitting users to sites that harvest #passwords and #credential tokens for use in #espionage campaigns, researchers said Tuesday.
#russia #security #privacy #gru -
Guidance for detecting, investigating, and defending against the Trivy supplychain compromise - https://www.redpacketsecurity.com/guidance-for-detecting-investigating-and-defending-against-the-trivy-supplychain-compromise/
#threatintel
#trivy
#supply chain attack
#github actions
#ci/cd security
#credential theft -
Guidance for detecting, investigating, and defending against the Trivy supplychain compromise - https://www.redpacketsecurity.com/guidance-for-detecting-investigating-and-defending-against-the-trivy-supplychain-compromise/
#threatintel
#trivy
#supply chain attack
#github actions
#ci/cd security
#credential theft -
🚨 Oh look, another day, another #PyPI disaster! 🎉 This time it's 'litellm', because who doesn't love their credentials being "borrowed"? 🤦♂️ Maybe they should've named it litell-uh-oh instead. 🙄
https://github.com/BerriAI/litellm/issues/24512 #Litellm #Security #Disaster #Credential #Theft #OpenSource #Drama #HackerNews #ngated -
🚨 Oh look, another day, another #PyPI disaster! 🎉 This time it's 'litellm', because who doesn't love their credentials being "borrowed"? 🤦♂️ Maybe they should've named it litell-uh-oh instead. 🙄
https://github.com/BerriAI/litellm/issues/24512 #Litellm #Security #Disaster #Credential #Theft #OpenSource #Drama #HackerNews #ngated -
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credentialtheft - https://www.redpacketsecurity.com/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credentialtheft/
#threatintel
#storm-2561
#credential-theft
#seo-poisoning
#fake-vpn-client
#vpn-security -
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credentialtheft - https://www.redpacketsecurity.com/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credentialtheft/
#threatintel
#storm-2561
#credential-theft
#seo-poisoning
#fake-vpn-client
#vpn-security -
Infostealers without borders: macOS, Python stealers, and platform abuse - https://www.redpacketsecurity.com/infostealers-without-borders-macos-python-stealers-and-platform-abuse/
#threatintel
#macOS
#Infostealer
#Python
#Cross-platform
#Credential-theft -
Infostealers without borders: macOS, Python stealers, and platform abuse - https://www.redpacketsecurity.com/infostealers-without-borders-macos-python-stealers-and-platform-abuse/
#threatintel
#macOS
#Infostealer
#Python
#Cross-platform
#Credential-theft -
🚨🚀 Breaking News: #Microsoft can't tell a #fake domain from a real one, so they've been sending your imaginary emails to Japan! 🎌🤖 Apparently, Outlook's idea of "autodiscover" is to discover how to #leak your credentials like a sieve. 🤦♂️
https://tinyapps.org/blog/microsoft-mishandling-example-com.html #Outlook #Security #Issues #Domains #Credential #Japan #HackerNews #ngated -
🚨🚀 Breaking News: #Microsoft can't tell a #fake domain from a real one, so they've been sending your imaginary emails to Japan! 🎌🤖 Apparently, Outlook's idea of "autodiscover" is to discover how to #leak your credentials like a sieve. 🤦♂️
https://tinyapps.org/blog/microsoft-mishandling-example-com.html #Outlook #Security #Issues #Domains #Credential #Japan #HackerNews #ngated -
Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against thesupply chain attack - https://www.redpacketsecurity.com/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-thesupply-chain-attack/
#threatintel
#supply-chain-security
#npm-security
#CI/CD-security
#credential-management
#defender-for-cloud -
Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against thesupply chain attack - https://www.redpacketsecurity.com/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-thesupply-chain-attack/
#threatintel
#supply-chain-security
#npm-security
#CI/CD-security
#credential-management
#defender-for-cloud -
Alireza Heidari presented 'Simple and Secure Credential Handling for Tools' in Galaxy on Day 2 of European Galaxy Days.
@galaxyfreiburg
#credential #EGD2025 #credential_handling #galaxyproject #secure_credential #eosc #fair #open_science -
Alireza Heidari presented 'Simple and Secure Credential Handling for Tools' in Galaxy on Day 2 of European Galaxy Days.
@galaxyfreiburg
#credential #EGD2025 #credential_handling #galaxyproject #secure_credential #eosc #fair #open_science -
#Pentagon Introduces New Restrictions on #Reporter Access
The #DepartmentofDefense will force reporters to pledge not to gather or use any information that had not been formally authorized for release, or risk losing their #credential to cover the #military.
#Trump #journalism #journalist #dodhttps://www.nytimes.com/2025/09/20/business/media/pentagon-restrictions-reporters-hegseth-trump.html
-
High-severity #vulnerability in #Passwordstate #credential manager. #Patch now .
#security #highseverity #privacy -
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate – Source:thehackernews.com https://ciso2ciso.com/credential-theft-and-remote-access-surge-as-allakore-purerat-and-hijack-loader-proliferate-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Credential