T1552 - Unsecured Credentials is a mitre_attack tracked by ThreatCluster, appearing in 5 threat clusters built from 5 intelligence report mentions.
T1552 - Unsecured Credentials is a mitre_attack tracked across 5 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed June 7, 2026; most recent activity July 24, 2026.
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
Kubernetes runtime threats exploit vulnerabilities in container orchestration systems, particularly targeting misconfigured pods and excessive privileges. The NSA and CISA have highlighted these vulnerabilities, which…
Cybernews researchers uncovered an exposed Elasticsearch database containing 24 billion records, including usernames, email addresses, and plaintext passwords. The data is primarily sourced from infostealer malware logs…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
T1552 - Unsecured Credentials is a mitre_attack tracked by ThreatCluster, appearing in 5 threat clusters built from 5 intelligence report mentions.
The most recent intelligence report mentioning T1552 - Unsecured Credentials on ThreatCluster is dated July 24, 2026. Activity was first observed June 7, 2026, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, T1552 - Unsecured Credentials most frequently co-occurs with TeamPCP, Data Breach, Malware, Supply Chain Attack, Miasma Worm Campaign, among 12 tracked related entities.
The most significant recent cluster is “LiteLLM Supply Chain Attack Exposes Critical Credentials” (3 articles · Updated June 12, 2026). T1552 - Unsecured Credentials appears across 5 threat clusters in total, listed above with sources.
T1552 - Unsecured Credentials appears in 5 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.