Credential Theft
The latest Credential Theft coverage — news, analysis, and updates from the WindowsNews.AI desk.
Shai-Hulud npm Worm: A Supply Chain Crisis Targeting AWS, Azure & Google Cloud
The JavaScript ecosystem is facing its most sophisticated supply chain attack to date—a self-replicating worm dubbed "Shai-Hulud" that has compromised hundreds of npm packages and created a...
Shai Hulud Worm Targets Windows Devs, Steals Credentials via 100+ NPM Packages
A self-propagating worm has infiltrated the npm ecosystem, infecting hundreds of JavaScript packages and transforming developer machines and CI pipelines into automated platforms for credential theft...
SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks
Microsoft has released patches for a critical information-disclosure vulnerability in SQL Server that could allow an authenticated attacker to read sensitive memory contents over the network. Tracked...
Rockwell Patches Critical SSRF Flaw in ThinManager That Exposes NTLM Hashes to Attackers
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reissued a high-severity advisory on September 9, 2025, for a server-side request forgery (SSRF) vulnerability in Rockwell...
Black Hat Demo Shows Local Admins Hijacking Windows Hello Biometrics, Forcing Identity Reckoning
Security researchers from ERNW, Dr. Baptiste David and Tillmann Osswald, took the stage at Black Hat to demonstrate a practical, low-noise attack against Windows Hello for Business. Dubbed...
SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments
A targeted supply-chain attack infiltrating the npm registry has been quietly siphoning cryptocurrency wallet keys, API tokens, and sensitive configuration files from developer machines. Dubbed...
Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks
A single unassuming ZIP archive can now become a weapon to steal Windows credentials, thanks to a newly patched flaw in Windows File Explorer. Microsoft's March 11, 2025 Patch Tuesday update fixed a...
Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials
A new wave of phishing attacks targeting Microsoft 365 users is bypassing conventional email filters by weaponizing SVG image files and repurposing legitimate security tools as cloaking devices. The...
Urgent Security Alert: Advanced Zero-Day Exploit Chain Targets Microsoft SharePoint Servers
A fresh wave of cyberattacks has ignited major concerns within enterprise IT and cybersecurity communities. At the center of this storm is a newly disclosed exploit chain targeting Microsoft...
How Phishing Attacks Exploit Enterprise Email Security Trust and Link Wrapping
For years, enterprise email security has been built on foundations of trust and automated threat detection—mechanisms like link wrapping and URL rewriting intended to shield organizations from the...
How Cybercriminals Exploit Link Wrapping to Launch Sophisticated Microsoft 365 Phishing Attacks
Just as organizations have started to place their trust in security technologies designed to make email safer, a transformative threat has emerged that subverts these very foundations. Cybercriminals...
Rising Cyber Threats Exploit Email Link Wrapping Vulnerabilities in Microsoft 365
A sudden spike in sophisticated cyberattacks is shaking the foundations of email security for businesses leveraging Microsoft 365. Recent investigations have revealed an alarming vulnerability within...