Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: credential-theft (35 articles)Clear

Official MCP Python SDK flaw lets malicious servers steal client OAuth credentials

The maintainers of the official Model Context Protocol Python SDK disclosed a flaw that lets a malicious MCP server trick an application built on the SDK into handing over the OAuth credentials it uses to log in to a real service. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, because the SDK did not always verify where the authorization server was. Cycode, which reported it, exchanged the stolen material for a valid access token carrying the app's permissions, and noted the long-lived client secret keeps working until rotated. Fixes are in versions 1.30.0 and 2.2.0.

Check
Upgrade the MCP Python SDK to 1.30.0 or 2.2.0, then rotate any OAuth client secrets that MCP clients may have sent to untrusted servers.
Affected
Applications built on affected MCP Python SDK versions can be induced by a malicious MCP server to leak their OAuth client secret, authorization code, and PKCE key.
Fix
Update the SDK, rotate exposed client secrets, and connect MCP clients only to servers whose authorization endpoints you trust and validate.

Bitget says attacker used third party security product flaw to steal 388 million dollars

Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.

Check
Review third-party security products in privileged positions for patch status and blast radius, and treat their credentials as high-value targets requiring isolation.
Affected
Organizations relying on a vulnerable third-party security product can have its high-level credentials stolen and abused to command core backend systems.
Fix
Inventory and patch third-party security tooling, scope its access tightly, add out-of-band approval for high-value transfers, and monitor for anomalous internal commands.

Compromised GitHub Actions came back online still executing Mini Shai-Hulud credential malware

Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.

Check
Audit workflows for references to the two actions-cool actions, pin actions to trusted commit hashes, and rotate any CI/CD secrets exposed since September 16.
Affected
Pipelines referencing the affected actions-cool actions by version tag re-ran the May 18 payload after September 16, harvesting and exfiltrating CI/CD credentials.
Fix
Remove or repin the actions to vetted commits, rotate pipeline secrets, and prefer commit-hash pinning over mutable version tags for third-party actions.

Malicious npm package impersonates Twilio bug bounty probe to exfiltrate developer credentials

ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.

Check
Block and audit for tw-pkgprobe-7731 across developer and build environments, then rotate Twilio credentials and API keys exposed on any affected machine.
Affected
Developers integrating Twilio who installed the package inside a matching environment had environment variables and account-linked configuration harvested and sent to an attacker webhook.
Fix
Pin and vet npm dependencies, alert on packages that fingerprint the environment before acting, and restrict outbound webhooks from build and developer hosts.

Rogue external MFA provider in Entra captures user passwords during legitimate logins

Varonis Threat Labs detailed a post-compromise technique it calls TrustSink, in which an attacker holding a highly privileged Microsoft Entra account registers a rogue External Authentication Method as an external MFA provider. During normal sign-ins, Entra redirects users to the rogue provider to complete the second factor, and the attacker inserts a convincing Microsoft password prompt that captures the password in plaintext before returning a valid signed token, so the login completes with no error. In testing, every sign-in succeeded while the attacker server logged passwords with source IPs. Resetting a captured password does not remove the rogue provider, which persists in the configuration and works against any external provider model.

Check
Audit Entra External Authentication Methods for unrecognized providers, remove rogue entries, and tighten which roles can register or modify external MFA providers.
Affected
Tenants where an attacker already holds a highly privileged Entra role can have a rogue external MFA provider silently harvest every user's password during normal logins.
Fix
Restrict and monitor privileged Entra roles, alert on External Authentication Method changes, and review provider configuration after any privileged-account compromise.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.

Teams help desk impersonation delivers SynkLoader and a fake lock screen

Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.

Check
Tell staff to verify unsolicited IT-support messages in Teams through a known internal channel before installing anything, and hunt for unapproved MSI installs, new scheduled tasks, and in-memory PowerShell.
Affected
Organizations allowing external Teams messages, where an attacker impersonating IT support can deliver SynkLoader; it steals passwords via a fake lock screen and provides proxy, shell, and remote-desktop access toward likely ransomware.
Fix
Restrict or closely monitor external Teams communication, block untrusted MSI downloads and known command-and-control infrastructure, watch for suspicious scheduled tasks and Python or PowerShell activity, and train staff on help-desk impersonation lures.

Exploited MLflow SSRF flaw lets attackers steal cloud credentials from ML servers

Attackers began exploiting a critical unauthenticated flaw in MLflow, the popular open-source machine-learning platform, within hours of its disclosure. Tracked as CVE-2026-64849 and scored 9.3, the server-side request forgery bug lives in the model-registry webhook testing feature: an attacker hosts an endpoint that passes validation, then redirects MLflow to internal targets such as the cloud metadata service or loopback addresses, and MLflow returns their responses. That exposes cloud credentials, API tokens, and secrets. Because MLflow sits close to training data, artifacts, object storage, CI/CD, and inference pipelines, a compromise offers both credentials and a foothold for lateral movement. watchTowr's honeypots saw exploitation attempts almost immediately.

Check
Upgrade MLflow to version 3.15.0 or later immediately, and treat any internet-exposed instance on an earlier version as potentially probed, checking for signs of metadata access.
Affected
Organizations running MLflow before 3.15.0, especially cloud-hosted and internet-exposed (CVE-2026-64849); an unauthenticated attacker can coerce it into fetching internal targets and leak cloud credentials, tokens, and secrets.
Fix
Patch to 3.15.0, review webhook configurations for attacker URLs, inspect logs for webhook-test requests and metadata or loopback addresses, rotate credentials the server could reach, and restrict its network exposure.

GitHub issue title let an AI agent hijack Snowflake CI and steal a token

Researchers at Wiz found that a public Snowflake code repository could be hijacked through nothing more than a crafted GitHub issue title. A workflow that ran when issues were opened dropped the attacker-controlled title straight into a command, so an unauthenticated user could run code on the GitHub Actions runner and steal a Jira API token used by the automation. The notable twist is how the bug arrived: it was introduced days earlier by an AI tool meant to fix security issues, and an AI code reviewer approved the change. Snowflake fixed it by passing the title safely as an argument rather than expanding it into a command.

Check
Audit GitHub Actions workflows that run on untrusted input like issue titles or pull requests, and never interpolate that input directly into shell commands; pass it as environment variables or arguments.
Affected
Repositories whose workflows trigger on issues or pull requests and interpolate attacker-controlled text into commands; an unauthenticated user can run code on the runner and steal the secrets the workflow holds.
Fix
Sanitize untrusted workflow input, minimize the secrets and permissions each workflow can access, and do not assume AI-generated or AI-reviewed code is safe, since automated fixes and reviews miss injection flaws.

A single GitHub issue could reach CI secrets across major AI coding agents

Novee Security showed at Black Hat that a GitHub issue opened by an account with no repository access could reach the CI runners behind major AI coding agents in their default configurations, tested against Claude Code, Gemini CLI, and Codex. The strongest, a Gemini CLI container-launcher command injection scored 10.0, runs code on the CI host before the sandbox starts. In Claude Code, a validator that stripped quoted text let a payload in a Git flag reach the runner, and a separate flaw leaked an API key through a download counter. Untrusted issue content reaching an agent that holds secrets and tools in the same runtime is the shared weakness.

Check
Update Gemini CLI to 0.39.1 and Claude Code to 2.1.163, and review any workflow where an AI agent runs automatically on issues or pull requests from untrusted users.
Affected
Teams running AI coding agents on public repositories in default configurations (CVE-2026-12537, CVE-2026-54316); an unprivileged GitHub issue or pull request can reach CI runners and expose workflow secrets and tokens.
Fix
Patch the agents, restrict their tools with allowlists rather than blocklists, give triage and review agents read-only tokens, and keep separate agent runs from sharing writable directories.