Live
Shai-Hulud npm Worm: A Supply Chain Crisis Targeting AWS, Azure & Google Cloud·MSFT +2.1%Shai Hulud Worm Targets Windows Devs, Steals Credentials via 100+ NPM Packages·NVDA +0.2%SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks·GOOGL +1.7%Rockwell Patches Critical SSRF Flaw in ThinManager That Exposes NTLM Hashes to Attackers·AMZN +1.1%Black Hat Demo Shows Local Admins Hijacking Windows Hello Biometrics, Forcing Identity Reckoning·MSFT +2.1%SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments·NVDA +0.2%Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks·GOOGL +1.7%Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials·AMZN +1.1%Shai-Hulud npm Worm: A Supply Chain Crisis Targeting AWS, Azure & Google Cloud·MSFT +2.1%Shai Hulud Worm Targets Windows Devs, Steals Credentials via 100+ NPM Packages·NVDA +0.2%SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks·GOOGL +1.7%Rockwell Patches Critical SSRF Flaw in ThinManager That Exposes NTLM Hashes to Attackers·AMZN +1.1%Black Hat Demo Shows Local Admins Hijacking Windows Hello Biometrics, Forcing Identity Reckoning·MSFT +2.1%SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments·NVDA +0.2%Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks·GOOGL +1.7%Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials·AMZN +1.1%

Credential Theft

The latest Credential Theft coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 1:48 AM
Latest Most Read Breaking
Sort
Ci Cd Security · Credential Theft

Shai-Hulud npm Worm: A Supply Chain Crisis Targeting AWS, Azure & Google Cloud

The JavaScript ecosystem is facing its most sophisticated supply chain attack to date—a self-replicating worm dubbed "Shai-Hulud" that has compromised hundreds of npm packages and created a...

Advertisement
Admin Rights · Biometrics

Black Hat Demo Shows Local Admins Hijacking Windows Hello Biometrics, Forcing Identity Reckoning

Security researchers from ERNW, Dr. Baptiste David and Tillmann Osswald, took the stage at Black Hat to demonstrate a practical, low-noise attack against Windows Hello for Business. Dubbed...

SE Security Desk·45w ago
Command And Control · Credential Theft

SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments

A targeted supply-chain attack infiltrating the npm registry has been quietly siphoning cryptocurrency wallet keys, API tokens, and sensitive configuration files from developer machines. Dubbed...

SE Security Desk·48w ago
Archive Security · Credential Theft

Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks

A single unassuming ZIP archive can now become a weapon to steal Windows credentials, thanks to a newly patched flaw in Windows File Explorer. Microsoft's March 11, 2025 Patch Tuesday update fixed a...

SE Security Desk·49w ago
Credential Theft · Cyber Defense

Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials

A new wave of phishing attacks targeting Microsoft 365 users is bypassing conventional email filters by weaponizing SVG image files and repurposing legitimate security tools as cloaking devices. The...

SE Security Desk·49w ago
.net Security · Cisa

Urgent Security Alert: Advanced Zero-Day Exploit Chain Targets Microsoft SharePoint Servers

A fresh wave of cyberattacks has ignited major concerns within enterprise IT and cybersecurity communities. At the center of this storm is a newly disclosed exploit chain targeting Microsoft...

SE Security Desk·49w ago
Advanced Threats · Ai Security

How Phishing Attacks Exploit Enterprise Email Security Trust and Link Wrapping

For years, enterprise email security has been built on foundations of trust and automated threat detection—mechanisms like link wrapping and URL rewriting intended to shield organizations from the...

AI AI & Copilot Desk·49w ago
Account Compromise · Credential Theft

How Cybercriminals Exploit Link Wrapping to Launch Sophisticated Microsoft 365 Phishing Attacks

Just as organizations have started to place their trust in security technologies designed to make email safer, a transformative threat has emerged that subverts these very foundations. Cybercriminals...

SE Security Desk·50w ago
Account Compromise · Business Security

Rising Cyber Threats Exploit Email Link Wrapping Vulnerabilities in Microsoft 365

A sudden spike in sophisticated cyberattacks is shaking the foundations of email security for businesses leveraging Microsoft 365. Recent investigations have revealed an alarming vulnerability within...

SE Security Desk·50w ago