Fetching from the wire…
Public story · 2026-09-26 · high
170,298 stolen credential logs show victims reusing passwords across government, military, and dev platforms.
Why now: The paper posted to arXiv on September 26.
Researchers built a dataset from 170,298 infostealer victims, pulling credentials out of malware logs and anonymizing them for study. The paper says it's the first victim-level infostealer dataset released under controlled access rather than sold or dumped raw.
The breach list runs wider than gaming accounts and streaming logins, though those dominate by volume. Government, military, remote-access, and development platforms all show up. So do credentials tied to law enforcement domains and all eight Ivy League universities, meaning people with access to sensitive systems are getting hit by the same commodity malware as everyone else.
The overlap is what should worry security teams. Victims in this dataset show up again in phishing and ransomware populations, which suggests infostealer infections aren't a separate problem from those bigger attacks. They're often the entry point.
What the paper doesn't settle is how much of this reuse is old passwords sitting in old logs versus active credentials right now. Infostealer logs get resold and recirculated for months after the original infection, so a credential's presence in the dataset doesn't tell you it still works.
For anyone running security for an org with .edu or .gov-adjacent users, password reuse across personal and institutional accounts is the mechanism here, not sophisticated targeting. The fix is the boring one. Credential monitoring against known-compromised lists catches more than another phishing training module.
Each link below shares sources, entities, or timing with this story.
arXiv 2608.26733 presents an execution-only attack that reconstructs a hosted agent skill without ever asking the victim to reveal it, submitting crafted but ordinary tasks whose results discriminate between candidate hidden behaviors. At the weakest access level, final respon...
arXiv 2609.25809 studied 12 checkpoints across nine architecture families on 11 benchmarks and found per-token expert selection far more redundant than assumed. The change is a single integer, and it gave 1.2-1.7x measured speedup on two serving backends.
arXiv 2609.19244 is the first end-to-end study of agentic web search across ChatGPT, Claude, Grok and DeepSeek, pairing real user interactions with controlled API experiments on the same models. Invocation rates varied substantially and more frequent searching did not yield be...
arXiv 2609.18526 tested four boundaries in consumer local-LLM serving stacks. A 24-hour AFL++ campaign of over 12 million executions found no parser crashes and no successful malformed GGUF loads. Runtime memory failed anyway: prompts were recovered after inference because mul...
It refines C/C++ CodeQL queries by synthesizing programs whose execution disagrees with the query verdict, treating that disagreement as ground truth for an LLM repair loop, with no labeled dataset or vulnerability templates. Refined queries detected up to 119.8% more true pos...
Researchers built a controlled corpus of 4,200 full-paper manuscripts derived from 120 anonymized ICLR 2026 submissions, had two LLM rewriters push six rhetorical dimensions in opposing directions while preserving the reported science, then had five LLM reviewers grade them (a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.