Stripe is a technology platform tracked across 12 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed December 31, 2025; most recent activity July 16, 2026.
The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…
A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into…
In 2026, the API management market is projected to generate approximately $9.7 billion, making APIs a critical attack surface. A notable incident involved a legacy Stripe API endpoint that was exploited in a…
Suno, an AI music generation startup, was hacked, revealing unauthorized scraping of music data from platforms like YouTube Music, Deezer, and Genius. The breach occurred through a supply chain attack that compromised…
A study analyzing 10 million websites has uncovered nearly 2,000 exposed API credentials across 10,000 webpages. Researchers from Stanford, led by Nurullah Demir, utilized the tool TruffleHog to identify 1,748 valid…
Threat actors have targeted customers of the HungerRush point-of-sale (POS) platform, demanding ransom in exchange for not exposing sensitive restaurant and customer data. The extortion campaign began with emails sent…
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
Threat actors are increasingly using Vercel's generative AI tool, v0[.]dev, to create realistic phishing websites that mimic well-known brands. Cofense has observed a rise in campaigns utilizing this tool, which allows…
Substack has disclosed a security breach that exposed user email addresses and phone numbers due to a hack that occurred in October 2025. The breach went undetected for four months, with CEO Chris Best confirming that…
The European Space Agency (ESA) has confirmed a breach involving servers outside its corporate network. The compromised servers contained unclassified information related to collaborative engineering activities. ESA is…