Sponsor of the Day:
Jerkmate
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/
DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
Mar 9, 2026 - DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound...
credential harvestingbrowserappboundencryption
https://www.aikido.dev/blog/npm-supply-chain-phishing-campaigns
Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages
Jan 28, 2026 - A targeted spear-phishing campaign used npm packages and jsDelivr as free phishing infrastructure, serving custom credential harvesters per victim
npm packagescredential harvestinggoneservingcustom
https://www.mimecast.com/threat-intelligence-hub/hospitality-focused-phishing-campaign-impersonates-expedia-and-cloudbeds/
Hospitality Phishing Alert: Expedia & Cloudbeds Credential Harvesting Campaign Exposed | Mimecast
A large-scale phishing campaign is targeting hospitality professionals by impersonating Expedia Partner Central and Cloudbeds. Learn how these attacks work,...
phishing alertcredential harvestingcampaign exposedhospitalityexpedia