Infostealer malware is increasingly being used as a bridge between compromised developer workstations and enterprise cloud environments. Lumma, RedLine, and Vidar are among the prominent families harvesting browser credentials, session cookies, API keys, cloud credentials, and developer secrets. Telemetry indicates that these infections can expose reusable identities capable of providing direct access to enterprise services without exploiting public-facing infrastructure. Infostealers are commonly delivered through phishing, malicious advertisements, ClickFix lures, pirated software, gaming cheats, and trojanized dependencies. After execution, they collect browser passwords, authentication cookies, SSH keys, cloud CLI credentials, source-control tokens, cryptocurrency data, and secrets stored in local files or environment variables. Cloud environments including AWS, Azure, and Google Cloud are particularly exposed. Attackers can target AWS credential files and CLI caches, Azure CLI and Entra ID artifacts, and GCP credential databases and service-account files. GitHub and GitLab tokens may provide access to private repositories, CI/CD pipelines, package registries, and deployment workflows. Stolen session cookies are especially significant because they may enable authenticated-session hijacking without requiring the victim's password or directly defeating MFA. The threat also extends to AI development environments, where stolen OpenAI, Anthropic, Gemini, Hugging Face, and other API credentials can enable unauthorized usage or access to connected workflows.
The threat actor known as JADEPUFFER, tracked by Microsoft as Storm-3168, has been observed carrying out destructive operations in a Microsoft Azure environment using compromised s...
Cybersecurity researchers have disclosed Carbonato, a botnet that targets Docker daemons exposed without authentication on TCP port 2375. It compromises vulnerable hosts by launchi...
Norwegian Cruise Line’s access-control system has been affected by a vulnerability tracked as CVE-2026-75907, which can allow unauthorized access through replay of an NFC keycard...