Researchers find a yearlong ongoing supply-chain attack targeting malicious and benevolent security personnel and stealing over 390K WordPress credentials
Threat actors spread info stealing malware through 1) GitHub-hosted PoC exploits for CVE vulns and 2) phishing emails targeteting 2,700 addresseses scraped from the arXiv research platform. The professional grade istealer stole 390,009 creds, likely from bad guys. — arstechnic…