credential theft
Beyond Market Intelligence keeps credential theft in one place: 3 stories so far. The section currently leads with “Three Artifactory Flaws Allow Rapid Admin Takeover on Self-Hosted Systems”, “When session cookies bypass 2FA and SSO, your data needs a smarter guard.”, and “The npm supply chain attack that earned its trust before striking.”. Three Artifactory vulnerabilities under active exploitation let attackers bypass authentication on self-hosted systems and seize admin control in under five minutes. Session-cookie theft is not a login-page attack, and it will not be stopped by another layer of MFA. Acme AI is the next-generation, AI-powered spreadsheet platform built to replace Excel and redefine how analysts, data scientists, and enterprise teams work… The list below is every credential theft story on Beyond Market Intelligence, newest first.

Three Artifactory Flaws Allow Rapid Admin Takeover on Self-Hosted Systems
Three Artifactory vulnerabilities under active exploitation let attackers bypass authentication on self-hosted systems and seize admin control in under five minutes. That speed should concern any team running these deployments. The exploits enable credential theft, arbitrary code execution, and anti-forensics measures, consequences that compound fast. If data security risks feel familiar, our coverage of how AI agents shared user images on public hosting sites offers a related look at exposure points. This is a reminder that self-hosted tools demand immediate attention.

When session cookies bypass 2FA and SSO, your data needs a smarter guard.
Session-cookie theft is not a login-page attack, and it will not be stopped by another layer of MFA. Anthropic's disclosure shows infostealers replaying stolen Claude sessions into paid accounts, bypassing two-factor entirely because the checkpoint already passed. What makes this notable is the exposure: those replayed sessions could reach connected services, including corporate Gmail, through OAuth grants no admin console can revoke. The accounts were self-serve and card-billed, outside enterprise identity control. That is the gap worth closing, not just the cookie jar.

The npm supply chain attack that earned its trust before striking.
The keyv worm didn't fake its security check. It earned one. That's the part that should unsettle every security team. The poisoned releases shipped with valid provenance signatures because they ran through the maintainer's own pipeline. Valid credentials, not a broken control, did the damage. The trust signals built to secure the supply chain were satisfied by an attacker holding the right account. That's not a bug in the machinery. It's the shape of the exposure.