Ray Canzanese @canzanese.com · 28/09/20262 days and 23 miles left to my cycling goal for Team Steve. Your donations support research like Dr. Moghimi's at Children's Hospital Los Angeles, developing a next-gen CAR T-cell therapy for acute myeloid leukemia (AML), which took Steve from us in 2005. give.curesearch.org/fundraiser/7... 000
Ray Canzanese @canzanese.com · 21/09/2026give.curesearch.org/fundraiser/7... We are biking to raisie funds for childhood leukemia research in honor of Steven Crowe, who passed away in 2005 after a brutal 9-month battle with acute myeloid leukemia, and we greatly appreciate anything you can donate! 001
Ray Canzanese @canzanese.com · 04/09/2026We have seen steady growth in EtherHiding traffic since the beginning of the year. JC shares some great stats and breakdown of a recent campaign in his latest post. 000
Ray Canzanese @canzanese.com · 28/07/2026In focus in our 2026 AI report: A increase of DOWNSTREAM data policy violations, meaning that AI tools are returning data that consumers are not authorized to access. www.netskope.com/resources/th... 000
Ray Canzanese @canzanese.com · 23/07/2026The top of the CyberGym leaderboard is already very crowded and K3 isn't even up there yet. But the most significant feature of this leaderboard is how close the GLM-5.2 is to the top of the board. I am very excited to see more open weights models near the top. 000
Ray Canzanese @canzanese.com · 08/06/2026Back to work after a vacation that included brief pauses for Infosecurity Europe and OrangeCon NL. As someone who has almost exclusively attended conferences in North America, it was great to see such a vibrant cybersecurity community on the other side of the pond! 032
Ray Canzanese @canzanese.com · 14/05/2026Was anyone surprised by Microsoft's MDASH multi-model approach using Opus 4.6, Sonnet 4.6, and GPT-5.4 outperforming Mythos? We've been using multi-model approaches to basically everything we are doing with LLMs for a while with stellar results. 030
Ray Canzanese @canzanese.com · 10/04/2026Netskope's Hubert WS Lin (林悟生) is featured in Hitachi Systems Security Journal Vol. 77, where you can read all about his latest project, SaucePot, which he presented at Code Blue! お見事! www.hitachi-systems.com/report/speci... 000
Ray Canzanese @canzanese.com · 12/03/2026Phishing URL: invite[.]komiku[.]my[.]id/Teams/Windows/invite.php Notes: This is the latest in a wave of fake meeting invites delivering RMM tools that we have tracking. This time, it was a Datto RMM Agent. www.netskope.com/blog/attacke... 020
Ray Canzanese @canzanese.com · 12/03/2026Shadow AI remains a significant challenge in the healthcare sector, with 32% of users opting for shadow AI apps, despite promising trends toward managed enterprise AI platform adoption. Read more in the new Netskope Threat Labs Healthcare Report. www.netskope.com/resources/th... 010
Ray Canzanese @canzanese.com · 12/03/2026The Netskope AI Index let's you explore AI adoption trends for individual sectors, geos, and org sizes with weekly updates to track the latest trends. ai-index.netskope.com 000
Ray Canzanese @canzanese.com · 27/01/2026Netskope's 2026 Canada report shows the number of genAI users has increased 3.3x year-over-year, causing a proportional rise in the amount of sensitive data (including intellectual property, secrets, regulated data, and source code) sent to genAI apps. www.netskope.com/resources/th... 010
Ray Canzanese @canzanese.com · 12/11/2025If you are in Tokyo for Code Blue next week, checkout Hubert Lin's workshop. It is a lot of fun! #netskope #infosec 020
Ray Canzanese @canzanese.com · 12/11/2025Netskope Threat Labs' newest member is Vini Egerland! I look forward to sharing some of the awesome projects Vini is cooking up in the near future! 000
Ray Canzanese @canzanese.com · 09/10/2025TRUMP NATIONAL COMMITTEE JFC is spaming texts urging recipients to fill out the census. This is not the census, it is a pretext to trick victims into recurring donations. Initial link is to us-25[.]net, which redirects to winred[.]com, complete with dark patterns, emotion, and urgency. 110
Ray Canzanese @canzanese.com · 25/09/2025The Netskope Threat Labs team is #hiring experienced researchers in Brazil, Spain, and Portugal! The team is a fully remote team focused on innovation and thought leadership, researching problems including supply chain security, AI security, and command and control. www.netskope.com/company/care... 021
Ray Canzanese @canzanese.com · 25/09/2025GitHub status is green, but I'm getting the uniorn. Is it just me? 010
Ray Canzanese @canzanese.com · 18/09/2025$NTSK is officially trading! I've been here for 7 years, and at my previous company (acquired by Netskope) for another 3 -- 10 years spent building products, enabling the field, and ultimately building a research team that I am extremely proud of! netskope.com/threat-labs 000
Ray Canzanese @canzanese.com · 11/09/2025In honor of Steven Crowe, who passed away after a brutal battle with acute myeloid leukemia, we fund groundbreaking research. Thanks to your past support, two projects are making a huge impact! Please join us in continuing this life-saving work. give.curesearch.org/fundraiser/6... 000
Ray Canzanese @canzanese.com · 09/08/2025Just over an hour to go until "Whispers Through the Firewall" at the Red Team Village. Hubert WS Lin (林悟生) shares how to use TCP source port numbers as a covert data exfiltration channel. #DEFCON33 #Netskope 011
Ray Canzanese @canzanese.com · 07/08/2025Dagmawi Mulugeta and Colin Estep take the BlackHat stage in less than 2 hours! Come learn about Netskope's newest open source threat detection tool. #bhusa #blackhat 010
Ray Canzanese @canzanese.com · 29/07/2025I'm hiring a fully remote threat research position for Netskope Threat Labs and will be in Vegas for BlackHat next week. Please DM me if you are interested in the role and want to meet up in person. I have positions open in Brazil and Spain. 000
Ray Canzanese @canzanese.com · 14/07/2025@defcon.bsky.social Red Team Village schedule hot off the presses. Netskope Threat Labs' own Hubert Lin will be running his reverse port knocking workshop Saturday morning at 11! Hope to see you there. www.netskope.com/netskope-thr... 000
Ray Canzanese @canzanese.com · 10/07/2025Weird spam email this morning. No links. No images. Just some text. Is this some kind of bizarre marketing campaign? 000
Ray Canzanese @canzanese.com · 26/06/2025Fake DeepSeek installers are delivering the Sainbox RAT and Hidden rootkit. Our latest blog details how this campaign, attributed to the Silver Fox group, works. #malware #RAT #rootkit #infosec www.netskope.com/blog/deepsee... 010
Ray Canzanese @canzanese.com · 17/06/2025Does your security stack protect you against the latest generation of fake CAPTCHAs that evade browser-based defenses by tricking the victim into downloading the payload using the RUN dialog in Windows to download LegionLoader, LummaStealer, and more... www.netskope.com/blog/lumma-s.... 020
Ray Canzanese @canzanese.com · 12/06/2025I received what I was certain was an iCloud phishing email this morning, but after 6 total redirects, it turns out it was actually just really scammy marketing for Total Drive. I assume that the name is short-hand for "I totally shouldn't trust this company with any of my data." 020
Ray Canzanese @canzanese.com · 10/06/202529% of Netskope customers have completely blocked Elon Musks's Grok AI and 61% have controls to limit its use. What is your strategy? #genai #infosec www.netskope.com/blog/to-grok... 010
Ray Canzanese @canzanese.com · 13/05/2025These E-ZPass #phishing emails are never-ending. This one wasn't as well-targeted (wrong state and one that I rarely drive through). Site required a key (included in phishing link I was sent) and a mobile browser user-agent string. hjyu[.]husndbuhdfytoef[.]cfd 000
Ray Canzanese @canzanese.com · 25/04/2025Mimecast flagged this photo of me during the AI panel at Secure World Philadelphia as "Possible Pornographic Image (90% probability)". I guess my takes were too hot. I'll tone it down next time. 000
Ray Canzanese @canzanese.com · 09/04/2025Missed opportunity for "Make cryptocurrency fraud great again" as a subject line. www.justice.gov/dag/media/13... 000
Ray Canzanese @canzanese.com · 20/03/2025Leandro breaks down a new sample of the Elysium ransomware used by Ghost/Cring/Crypt3r d1c5e7b8e937625891707f8b4b594314 100
Ray Canzanese @canzanese.com · 14/03/2025More toll phishing. This one registered on Alibaba Cloud 2 days ago, a good reminder that blocking newly registered domains is a good idea. If not, make sure uwetjtmy[.]xin is on your blocklist. Already reported to Alibaba for take down. #phishing #infosec 000
Ray Canzanese @canzanese.com · 10/03/2025Financial services report released by Netskope Threat Labs. Explore the latest data on genAI, personal app risks, and social engineering threats in the financial services sector. #Cybersecurity #Finance #infosec #Netskope www.netskope.com/netskope-thr... 010
Ray Canzanese @canzanese.com · 25/02/2025More toll #phishing coming in, this one for E-ZPass. Text message contains a Bitly link that forwards to a URL on nwfpp[.]shop. 000
Ray Canzanese @canzanese.com · 25/02/2025More toll #phishing #scams spreading via SMS. This one using thetollroads-paytollasj[.]world. Reported the domain to the Alibaba and Cloudflare. 000
Ray Canzanese @canzanese.com · 18/02/2025Analysis of a new Golang backdoor that abuses Telegram for C2. #malware #backdoor f84ca2a61f648542f970e7120de116d2 www.netskope.com/blog/telegra... 020
Ray Canzanese @canzanese.com · 13/02/2025@netskope.com Threat Labs latest: Analysis of a #phishing campaign using SEO poisoning, Webflow, and fake CAPTCHAs to steal credit card numbers. www.netskope.com/blog/new-phi... 010
Ray Canzanese @canzanese.com · 12/02/2025Today, we released our Japan Threat Report. Japanese organizations have been more effective than the rest of the world at reducing the risks surrounding Generative AI and personal app use. Read the full report to learn how. www.netskope.com/netskope-thr... 100
Ray Canzanese @canzanese.com · 30/01/2025I'm very excited to share that @netskope.com Threat Labs' Hubert Lin was accepted to present at RSAC 2025! I look forward to seeing many of you there! #RSAC2025 020
Ray Canzanese @canzanese.com · 29/01/2025@netskope.com Threat Labs just published our Canada Threat Report. One area that Canada stood out was in aggressive GenAI app adoption and the data risks that come with it. www.netskope.com/netskope-thr... 010
Ray Canzanese @canzanese.com · 28/01/2025Help me finish this sentence. Freezing these cybersecurity grants (of which I listed just a few) is good for the country because ____________________. 110
Ray Canzanese @canzanese.com · 07/01/2025Our 2025 @netskope.com Cloud and Threat report highlights a year-over-year tripling in how many people are clicking on phishing links, with cloud services (especially Microsoft) being the top target 🤔 www.netskope.com/netskope-thr... #infosec #sase #phishing 020
Ray Canzanese @canzanese.com · 17/10/2024Netskope Threat Labs is #hiring in Northern Ireland! We are looking for someone who wants to work at the intersection of data analysis and threat research. Go for a swim in our datalake! #threatresearch #infosec #cybersecurity www.netskope.com/company/care... 010
Ray Canzanese @canzanese.com · 15/10/2024Netskope Threat Labs is #hiring in Spain! Do you love data analysis and threat research? Come join our team of researchers! #infosec #cybersecurity #threatresearch www.netskope.com/company/care... 000
Ray Canzanese @canzanese.com · 04/10/2024Latest Netskope Threat Labs Report highlights Insurance industry: cloud apps serve as a conduit for half of malware downloads, with Grandoreiro banker Trojan and AgentTesla Infostealer most common #cybersecurity #threatintelligence #malwareanalysis www.netskope.com/netskope-thr... 020