This site uses cookies for analytics via Microsoft Clarity. We only enable it after your consent. See our Privacy Policy.
Sujith Quintelier
  • Resume
  • Archives
  • Taxonomy
    • Tags
    • Categories
    • Series
  • Tools
    • CIDR Calculator
    • Certification Renewal Tracker
    • Tech Radar
    • UBB Simulator
  • Updates
  • Legal
    • Contact
    • About
    • Privacy
    • Cookies
  • linkedin
  • github
  • twitter
  • mastodon
  • bsky
  • facebook
  • instagram
  • buymeacoffee

  • Toggle theme

Back to updates

Credential-Theft - 1

2026 (3)

August (1)

security: ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Security Blog

2026-08-04

Microsoft describes ChainDrop, a credential-stealing worm embedded in 400+ compromised npm packages that spread by republishing malicious updates across software ecosystems. The post outlines the attack chain, affected environments, and guidance for detection, hunting, and remediation.

July (2)

security: CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog

2026-07-31

Microsoft says Storm-2945, a sub-cluster of Midnight Blizzard, has been compromising sign-in portals at hospitality organizations since May 2026 to deliver malware to travelers and steal credentials. The campaign is named CaptiveCrunch and targets travelers worldwide.

security: ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Security Blog

2026-07-16

Microsoft Defender Experts observed increased ACR Stealer activity from late April to mid-June 2026 across customer environments. The campaigns used ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.

© Copyright 2018-Present Sujith Quintelier All Rights Reserved • RSS

Privacy • Cookies • Contact

Based on Bootstrap. Icons from Bootstrap Icons and Font Awesome. Web fonts from Google.

Source Code