Rust Developers Hit by Fake Job Call Scam
Rust team members and crate owners are being targeted by attackers who pose as recruiters to hijack credentials and push malicious packages.
30 results for “theft”
Rust team members and crate owners are being targeted by attackers who pose as recruiters to hijack credentials and push malicious packages.
CrowdSec says about 300 repositories were hit and links the theft to a May 2026 TanStack supply chain attack.
A joint advisory says North Korean recruiters posed as hiring managers, using bogus coding tests to breach 30,000 devices and 7,000 crypto wallets.
A new Android malware family linked to suspected China-based actors uses a generative AI engine to automate credential and bank data theft.
Elastic Security Labs details a Brazilian banking malware toolkit that abuses browser extension installs and Ethereum smart contracts to steal credentials and sessions.
Google's threat intelligence unit reports that espionage and criminal groups are stealing models, prompts, and API keys to power their own AI operations.
A cross-store Twitch extension sent OAuth tokens for roughly 31,000 users to operator proxies, Socket reports.
A fintech breach via fake government emails exposes sensitive customer data, raising questions about verification controls.
New Pistachio research argues click rate alone misleads, and that credential leaks and reporting matter just as much.
Microsoft ties passkey-themed social engineering to extortion gangs that blend into Microsoft 365 traffic to steal files and email.
Anthropic says threat groups tied to ShinyHunters, Russia, and China misused Claude for credential harvesting, malware, and espionage.
ShinyHunters claims a Florida DMV breach, threatening to release 200,000 records by September 11.
FBI, NSA and CISA warn of industrial-scale distillation campaigns targeting US frontier models.
CrowdStrike uncovers Brazil-based threat actor Slim Spider stealing cloud credentials to access cryptocurrency custody secrets.
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.
Executives targeted in vishing attacks that steal tokens and extort victims.
Mathspace discloses a data breach affecting over 1 million students, staff, and parents after a Metabase vulnerability.
A complex JavaScript-based malware that can replay stolen browser sessions to breach Google accounts keeps evolving, researchers warn.
Multiple lawsuits target IDScan after alleged breach exposed 153M driver's licenses for sale on dark web.
Attackers exploit two PaperCut flaws to steal credentials from schools and universities in the U.S. and Europe.
A dark web service is selling 153M+ driver's license images, prompting an FBI inquiry.
Healthcare giant McKesson confirms data theft as ShinyHunters threat to leak by September 1.
Berlin refuses to pay Rhysida after data theft from its state network, saying it won't yield to blackmail.
LACMA's 2025 breach exposed social security and medical data; notifications sent.
A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.
Mirage2FA campaign hit 4,532 companies, bypassing MFA and stealing sessions.
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.
An open database from ClarityCheck exposed 9M+ facial images, risking identity theft and phishing.