Sign in

Ray Canzanese

@canzanese.com
248 followers 443 following 144 posts

Director of Netskope Threat Labs Resident of Philadelphia Graduate of Drexel University #cybersecurity #infosec Post mostly about cybersecurity stuff.

PostsRepliesMedia
Ray Canzanese @canzanese.com · 01/10/2026
We seem to have been tracking a constant onslaught of infostealers lately, but every now and then we come across an interesting crypto stealer.
000
Ray Canzanese @canzanese.com · 28/09/2026
2 days and 23 miles left to my cycling goal for Team Steve. Your donations support research like Dr. Moghimi's at Children's Hospital Los Angeles, developing a next-gen CAR T-cell therapy for acute myeloid leukemia (AML), which took Steve from us in 2005. give.curesearch.org/fundraiser/7...
000
Ray Canzanese @canzanese.com · 27/09/2026
ITW exploitation of two unpatched pre-authentication remote code execution (RCE) zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. sh3llc0d3.com/blog/inside-...
sh3llc0d3.com
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
100
Ray Canzanese @canzanese.com · 21/09/2026
give.curesearch.org/fundraiser/7... We are biking to raisie funds for childhood leukemia research in honor of Steven Crowe, who passed away in 2005 after a brutal 9-month battle with acute myeloid leukemia, and we greatly appreciate anything you can donate!
001
Ray Canzanese @canzanese.com · 18/09/2026
The NICU. Those poor babies and their parents.
010
Ray Canzanese @canzanese.com · 17/09/2026
I was rejected from attending cybersecuritysummit.com Philadelphia because I work at a vendor that doesn't sponsor. I've never been to this conference, so I'm curious to hear from others -- What is it like? Just a bunch of vendor pitches?
cybersecuritysummit.com
The Official Cybersecurity Summit
The Cybersecurity Summit, ranked as one of the “Top 50 Must-Attend Conferences”, connect C-Level & Senior Executives responsible for protecting their company’s critical infrastructures with cutting-ed...
000
Ray Canzanese @canzanese.com · 04/09/2026
We have seen steady growth in EtherHiding traffic since the beginning of the year. JC shares some great stats and breakdown of a recent campaign in his latest post.
000
Ray Canzanese @canzanese.com · 02/09/2026
NodeStealer is one of those malware families that just never seems to go away...
000
Ray Canzanese @canzanese.com · 27/08/2026
EtherHiding seems to be everywhere these days, the latest examplewe uncovered combines it with ClickFix to deliver the Amatera password stealer. www.netskope.com/blog/etherhi...
netskope.com
EtherHiding in the Browser: ClickFix Chain Ends in Amatera
Netskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a
000
Ray Canzanese @canzanese.com · 11/08/2026
Remember that AI sidebar extension that was stealing conversations? It is back, and less malicious this time around! After coming back "clean", they started layering in some adware. How long until the conversation stealing code comes back?
000
Reposted by Ray Canzanese
psparrows.bsky.social @psparrows.bsky.social · 05/08/2026
Here we are again! The Shai-Hulud supply chain attack resurfaces with 28 malicious npm packages across 4 unrelated namespaces, same credential-stealing playbook, one new trick: it reads its C2 address from an Ethereum smart contract instead of hardcoding it. www.netskope.com/blog/npm-ste...
netskope.com
npm Stealer Reads Its C2 From an Ethereum Contract
Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan,
011
Reposted by Ray Canzanese
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026
A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...
netskope.com
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network,
111
Ray Canzanese @canzanese.com · 28/07/2026
In focus in our 2026 AI report: A increase of DOWNSTREAM data policy violations, meaning that AI tools are returning data that consumers are not authorized to access. www.netskope.com/resources/th...
Log-scaled bar chart showing that upstream data policy violations dominate, but downstream violations are in a close second.
000
Ray Canzanese @canzanese.com · 23/07/2026
The top of the CyberGym leaderboard is already very crowded and K3 isn't even up there yet. But the most significant feature of this leaderboard is how close the GLM-5.2 is to the top of the board. I am very excited to see more open weights models near the top.
000
Ray Canzanese @canzanese.com · 23/07/2026
Is it OK to hack each other now if we say "my bad" and blame AI?
000
Ray Canzanese @canzanese.com · 14/07/2026
My fingers are getting tired from clicking refresh on git.projectnightcrawler.dev/NightmareEcl.... Repo has been live for 11 hours now with no activity. Perhaps this is as close to bone-shattering as we are going to get?
git.projectnightcrawler.dev
LegacyHive
LegacyHive
000
Ray Canzanese @canzanese.com · 08/06/2026
Back to work after a vacation that included brief pauses for Infosecurity Europe and OrangeCon NL. As someone who has almost exclusively attended conferences in North America, it was great to see such a vibrant cybersecurity community on the other side of the pond!
032
Ray Canzanese @canzanese.com · 14/05/2026
Was anyone surprised by Microsoft's MDASH multi-model approach using Opus 4.6, Sonnet 4.6, and GPT-5.4 outperforming Mythos? We've been using multi-model approaches to basically everything we are doing with LLMs for a while with stellar results.
030
Ray Canzanese @canzanese.com · 12/05/2026
More Shai-Hulud attacks overnight hit tanstack and some other popular namespaces. Time to double check that nobody pulled the infected versions overnight and to start version pinning all your dependencies if you haven't already. www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud-Style npm Worm Hits @tanstack
The npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action
010
Ray Canzanese @canzanese.com · 11/05/2026
In the latest OpenClaw lure, we found a fake installer website shipping an infostealer, with at least three iterations of attacks so far this year. www.netskope.com/blog/opencla...
netskope.com
OpenClaw's Hologram: Fake Installer Ships Rust Infostealer
Netskope Threat Labs has found a fake OpenClaw installer delivering red-team-grade capabilities—all pointed at stealing credentials from over 250 crypto
040
Ray Canzanese @canzanese.com · 08/05/2026
DirtyFrag: Reliable root access confirmed on all major linux distributions (Ubuntu, RHEL, Fedora) due to two kernel bugs; one core CVE remains unpatched. PoC binaries appeared on VirusTotal within minutes. Read more: www.netskope.com/blog/dirtyfr...
netskope.com
DirtyFrag: Two Kernel Bugs Give Root on All Major Linux Distros
Summary DirtyFrag is a Linux local privilege escalation disclosed on May 7, 2026, exploiting two kernel page-cache write vulnerabilities–CVE-2026-43284
020
Ray Canzanese @canzanese.com · 30/04/2026
Shai-Hulud looks like it might be making a comeback. intercom-client@7.0.4 is compromised. www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud resurfaces: intercom-client@7.0.4 harvesting Github credentials
Summary The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic
010
Ray Canzanese @canzanese.com · 20/04/2026
Netskope Threat Labs has seen a steady stream of ClickFix attacks, but this one stood out because of its cross-platform support to target MacOS users. Jan Michael Alcantara wrote a great breakdown, including advice to ensure new MacOS protections are in place. www.netskope.com/blog/macos-c...
netskope.com
macOS ClickFix Campaign: AppleScript Stealers & New Terminal Protections
Summary Netskope Threat Labs is continuing its coverage of a ClickFix campaign targeting both Windows and macOS users. While our previous post focused on
000
Ray Canzanese @canzanese.com · 20/04/2026
fortune.com/article/why-... I see people talking about how AI is creating like 10x and 100x productivity gains, and then others talking about how it is just a few percentage points. I think that the truth is probably somewhere in the middle, but closer to the lower end.
fortune.com
Thousands of CEOs admit AI had no impact on employment or productivity—and it has economists resurrecting a paradox from 40 years ago | Fortune
In the 1980s, economist Robert Solow made an observation that reminded economists of today’s AI boom: “You can see the computer age everywhere but in the productivity statistics.”
110
Ray Canzanese @canzanese.com · 10/04/2026
Netskope's Hubert WS Lin (林悟生) is featured in Hitachi Systems Security Journal Vol. 77, where you can read all about his latest project, SaucePot, which he presented at Code Blue! お見事! www.hitachi-systems.com/report/speci...
000
Ray Canzanese @canzanese.com · 06/04/2026
The commoditization of ClickFix continues with a new MaaS Jan Michael Alcantara at Netskope Threat Labs has uncovered, this one featuring a nodeJS implementation, a modular windows RAT, and C2 over Tor. www.netskope.com/blog/from-cl...
netskope.com
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
Summary Netskope Threat Labs is tracking a new ClickFix campaign that targets Windows users. ClickFix became a prominent delivery vector in early 2025 for
110
Ray Canzanese @canzanese.com · 24/03/2026
Did the Docker scaffolding you used to install OpenClaw also install an infostealer? Netskope Threat Labs is tracking an AI-assisted lure factory to mass-generate over 300 polished, poisoned packages targeting developers looking for open-source AI tools. www.netskope.com/blog/opencla...
netskope.com
OpenClaw Trap: AI-Assisted Lure Factory Targets Developers & Gamers
Netskope Threat Labs identified a link to a malware campaign operating across at multiple GitHub repositories, spanning over 300 delivery packages,
111
Ray Canzanese @canzanese.com · 24/03/2026
On my way to #RSAC2026. Be sure to check out my colleague Gianpietro Cutolo's presentation on MCP security on Tuesday morning and stop by the Netskope booth 1127 in Moscone South. I hope to see you there! path.rsaconference.com/flow/rsac/us...
path.rsaconference.com
US26-Header
000
Ray Canzanese @canzanese.com · 12/03/2026
Phishing URL: invite[.]komiku[.]my[.]id/Teams/Windows/invite.php Notes: This is the latest in a wave of fake meeting invites delivering RMM tools that we have tracking. This time, it was a Datto RMM Agent. www.netskope.com/blog/attacke...
020
Ray Canzanese @canzanese.com · 12/03/2026
Shadow AI remains a significant challenge in the healthcare sector, with 32% of users opting for shadow AI apps, despite promising trends toward managed enterprise AI platform adoption. Read more in the new Netskope Threat Labs Healthcare Report. www.netskope.com/resources/th...
010
Ray Canzanese @canzanese.com · 12/03/2026
The Netskope AI Index let's you explore AI adoption trends for individual sectors, geos, and org sizes with weekly updates to track the latest trends. ai-index.netskope.com
000
Ray Canzanese @canzanese.com · 24/02/2026
We have seen the fake meeting invites slow down this week at Netskope Threat Labs, but they are still out there. The latest one I saw was a Teams meeting that downloaded a LogMeIn executable. www.netskope.com/blog/attacke...
netskope.com
Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures
Summary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications,
000
Ray Canzanese @canzanese.com · 23/02/2026
Since we at Netskope Threat Labs published our blog post about how to block/alert on OpenClaw installs, we have seen at least 65 new installs on managed devices. Playing with new tech is fun, but you need guardrails in place before you start running OpenClaw. www.netskope.com/blog/moltbot...
netskope.com
OpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Update 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the
100
Ray Canzanese @canzanese.com · 16/02/2026
Are RMMs just RATs now? www.netskope.com/blog/attacke...
netskope.com
Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures
Summary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications,
010
Ray Canzanese @canzanese.com · 10/02/2026
Stop installing OpenClaw in production systems. We are still seeing an unsettling number of new installs across multiple industries. Link has details on how to use Netskope to identify rogue installs and setup a block policy. www.netskope.com/blog/moltbot...
netskope.com
OpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Update 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the
010
Ray Canzanese @canzanese.com · 05/02/2026
Netskope Threat Labs is tracking a tech support scam campaign using malicious Bing ads to successfully drive traffic to the payloads hosted in Azure Blob Storage. www.netskope.com/blog/malicio...
netskope.com
Malicious Bing Ads Lead to Widespread Azure Tech Support Scams
Summary Starting on February 2 at around 16:00 UTC, Netskope Threat Labs was alerted to a spike of users across 48 different organizations clicking on
021
Ray Canzanese @canzanese.com · 03/02/2026
Among the surprises in the report: (1) Japanese organizations are doing an excellent job reducing Shadow AI. (2) ChatGPT has been dethroned as the most popular AI App!
010
Ray Canzanese @canzanese.com · 29/01/2026
MoltBot/ClawdBot is an open-source, self-hosted personal AI agent. It enables unauthenticated remote control by default and has privileged host access. For these reasons, we at Netskope recommend you review how it is being used at your org www.netskope.com/blog/moltbot...
netskope.com
MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Background MoltBot, previously known as ClawdBot, is an open-source, self-hosted personal AI agent that is run locally. It is advertised as a digital
110
Ray Canzanese @canzanese.com · 29/01/2026
I got my first E-ZPass phishing text message of the new year! These seem to have cooled off for a while and are not coming back strong. We've seen 48 new E-ZPass phishing domains targeting our customers at Netskope Threat Labs so far this year. The latest: ezpass[.]gov-hmp[.]cc
010
Ray Canzanese @canzanese.com · 27/01/2026
Netskope's 2026 Canada report shows the number of genAI users has increased 3.3x year-over-year, causing a proportional rise in the amount of sensitive data (including intellectual property, secrets, regulated data, and source code) sent to genAI apps. www.netskope.com/resources/th...
010
Ray Canzanese @canzanese.com · 26/01/2026
#RSAC2026 is less than 2 months away! Gianpietro Cutolo from Netskope Threat Labs will be there presenting his latest research on MCP security! I hope to see you there! www.netskope.com/netskope-thr...
netskope.com
Netskope Threat Labs
The Netskope Threat Labs discovers, analyzes, and designs defenses against the latest cloud threats affecting enterprises.
000
Ray Canzanese @canzanese.com · 23/01/2026
“X is a post-apocalyptic cesspool of bots, pedophilia and political illiteracy.” That might be my favorite quote about X. www.politico.com/news/magazin...
politico.com
MAGA Is Discovering the Downsides of X
And it’s not just Elon.
010
Ray Canzanese @canzanese.com · 06/01/2026
First Netskope Threat Labs report of 2026: GenAI users have tripled, prompts have increased six-fold, and data violations have doubled, but 50% of orgs lack enforceable data policies. Meanwhile, personal apps, phishing, and malware remain persistent challenges. www.netskope.com/resources/cl...
netskope.com
Cloud and Threat Report: 2026
Learn how organizations are tackling the evolving cybersecurity landscape, including malware, genAI, AI Agents, and data security.
030
Ray Canzanese @canzanese.com · 26/11/2025
Is writing malware that generates all of its malicious routines on the fly from prompts using ChatGPT possible? Read more on the Netskope Threat Labs blog. www.netskope.com/blog/the-fut...
netskope.com
The Future of Malware is LLM-powered
Summary Large language models (LLMs) have rapidly transformed industries, becoming invaluable tools for automation, coding assistance, and research.
010
Ray Canzanese @canzanese.com · 13/11/2025
Netskope's manufacturing threat report highlights growing incidents of sensitive data exposure as AI apps gain popularity, malware coming in over trusted cloud apps, and more... www.netskope.com/resources/th...
netskope.com
Netskope Threat Labs Report: Manufacturing 2025
Learn how organizations in the Manufacturing sector are tackling the evolving cybersecurity landscape, including malware, genAI, AI Agents, and data security.
020
Ray Canzanese @canzanese.com · 12/11/2025
If you are in Tokyo for Code Blue next week, checkout Hubert Lin's workshop. It is a lot of fun! #netskope #infosec
020
Ray Canzanese @canzanese.com · 12/11/2025
Netskope Threat Labs' newest member is Vini Egerland! I look forward to sharing some of the awesome projects Vini is cooking up in the near future!
000
Ray Canzanese @canzanese.com · 23/10/2025
Our Netskope Private Access team has an opening for a Distinguished Engineer in the US. Please reach out if you have questions: www.linkedin.com/jobs/view/42...
linkedin.com
Netskope hiring Distinguished Engineer, NPA in Santa Clara, CA | LinkedIn
Posted 10:11:57 AM. About NetskopeToday, there's more data and users outside the enterprise than inside, causing the…See this and similar jobs on LinkedIn.
020
Ray Canzanese @canzanese.com · 09/10/2025
TRUMP NATIONAL COMMITTEE JFC is spaming texts urging recipients to fill out the census. This is not the census, it is a pretext to trick victims into recurring donations. Initial link is to us-25[.]net, which redirects to winred[.]com, complete with dark patterns, emotion, and urgency.
110
Ray Canzanese @canzanese.com · 25/09/2025
The Netskope Threat Labs team is #hiring experienced researchers in Brazil, Spain, and Portugal! The team is a fully remote team focused on innovation and thought leadership, researching problems including supply chain security, AI security, and command and control. www.netskope.com/company/care...
021