#credentialharvesting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.
-
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code […] The post Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel appeared first on Cyber Security News .
Pulse ID: 6abfc5f68ae4b5eaef02990e
Pulse Link: https://otx.alienvault.com/pulse/6abfc5f68ae4b5eaef02990e
Pulse Author: CyberHunter_NL
Created: 2026-10-02 14:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code […] The post Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel appeared first on Cyber Security News .
Pulse ID: 6abfc5f68ae4b5eaef02990e
Pulse Link: https://otx.alienvault.com/pulse/6abfc5f68ae4b5eaef02990e
Pulse Author: CyberHunter_NL
Created: 2026-10-02 14:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code […] The post Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel appeared first on Cyber Security News .
Pulse ID: 6abfc5f68ae4b5eaef02990e
Pulse Link: https://otx.alienvault.com/pulse/6abfc5f68ae4b5eaef02990e
Pulse Author: CyberHunter_NL
Created: 2026-10-02 14:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code […] The post Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel appeared first on Cyber Security News .
Pulse ID: 6abfc5f68ae4b5eaef02990e
Pulse Link: https://otx.alienvault.com/pulse/6abfc5f68ae4b5eaef02990e
Pulse Author: CyberHunter_NL
Created: 2026-10-02 14:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.
Pulse ID: 6abf5aa04b47ef1458d7472a
Pulse Link: https://otx.alienvault.com/pulse/6abf5aa04b47ef1458d7472a
Pulse Author: AlienVault
Created: 2026-10-02 07:17:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.
Pulse ID: 6abf5aa04b47ef1458d7472a
Pulse Link: https://otx.alienvault.com/pulse/6abf5aa04b47ef1458d7472a
Pulse Author: AlienVault
Created: 2026-10-02 07:17:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.
Pulse ID: 6abf5aa04b47ef1458d7472a
Pulse Link: https://otx.alienvault.com/pulse/6abf5aa04b47ef1458d7472a
Pulse Author: AlienVault
Created: 2026-10-02 07:17:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.