Credential Theft
The latest Credential Theft coverage — news, analysis, and updates from the WindowsNews.AI desk.
Messaging Apps as Cyberattack Vectors: Protecting Microsoft 365 Credentials
In an era where remote work and digital communication dominate the corporate landscape, hackers have found a new gateway to infiltrate systems and steal sensitive information: messaging apps....
Patch CVE-2025-24054 now: NTLM credential theft risk demands urgent Windows mitigation in 2023
Introduction NTLM (New Technology LAN Manager) has been a cornerstone of Windows network authentication for decades, but its legacy status comes with significant security risks that have grown more...
Enhancing Windows Security: Strategies to Harden NTLM Authentication and Safeguard Credentials in 2025
Introduction In the ever-evolving landscape of cybersecurity, legacy protocols like NTLM (NT LAN Manager) continue to pose significant security risks. Despite being deprecated, NTLM remains prevalent...
From Low-Risk Flaw to Global Cyber Pandemic: The Rapid Exploitation of Windows Vulnerability CVE-2025-24054
Introduction In March 2025, Microsoft released a security update addressing CVE-2025-24054, a vulnerability in Windows NTLM authentication initially deemed "less likely" to be exploited. However,...
RemoteMonologue: How Windows DCOM and NTLM Enable Fileless Credential Theft
In the shadowy corridors of cybersecurity, a new technique dubbed "RemoteMonologue" is turning trusted Windows protocols into silent accomplices for credential theft—without leaving a trace on...
Microsoft 365 BEC Attacks Surge: How Hackers Exploit Collaboration Tools
For Microsoft 365's 345 million global users, the familiar ping of an email notification now carries unprecedented risk. A new wave of Business Email Compromise (BEC) attacks is exploiting the...
ClickFix Attack: How OAuth Exploits Threaten Microsoft 365 Security
The digital workspace has become a battleground where convenience clashes with vulnerability, and the ClickFix attack represents one of the most insidious threats to emerge in recent years. This...
Microsoft 365 OAuth Phishing: Key Threats and Zero Trust Defenses
Microsoft 365 has become a prime target for cybercriminals leveraging OAuth phishing attacks, a sophisticated form of credential theft that bypasses traditional security measures. These attacks...
Phishing Attacks Exploit Microsoft Copilot: A Growing Cybersecurity Concern
Introduction As organizations increasingly integrate AI-powered tools like Microsoft Copilot into their workflows, cybercriminals are exploiting these technologies to launch sophisticated phishing...
IBM ACS Credential Flaw Puts Mainframe Access at Risk on Windows 11
A newly discovered vulnerability in IBM's Access Client Solutions (ACS) software poses a significant security risk for Windows 11 users, potentially exposing sensitive credentials to attackers. This...
Sneaky Log Phishing Kit: How It Bypasses Microsoft 365 MFA and Steals Credentials
The digital shadows where cybercrime thrives have birthed a new weapon: an insidious phishing kit dubbed "Sneaky Log," surgically engineered to bypass Microsoft 365's formidable defenses and steal...
Microsoft Azure OpenAI Breach: How Cybercriminals Exploited AI Services for Credential Theft
Microsoft's Azure OpenAI services have become the latest target in a sophisticated credential theft campaign, exposing vulnerabilities in enterprise AI implementations. Security researchers have...