Sign in

Ray Canzanese

@canzanese.com
248 followers 443 following 144 posts

Director of Netskope Threat Labs Resident of Philadelphia Graduate of Drexel University #cybersecurity #infosec Post mostly about cybersecurity stuff.

PostsRepliesMedia
Ray Canzanese @canzanese.com · 01/10/2026
We seem to have been tracking a constant onslaught of infostealers lately, but every now and then we come across an interesting crypto stealer.
000
Ray Canzanese @canzanese.com · 28/09/2026
2 days and 23 miles left to my cycling goal for Team Steve. Your donations support research like Dr. Moghimi's at Children's Hospital Los Angeles, developing a next-gen CAR T-cell therapy for acute myeloid leukemia (AML), which took Steve from us in 2005. give.curesearch.org/fundraiser/7...
000
Ray Canzanese @canzanese.com · 27/09/2026
support.citrix.com/support-home...
support.citrix.com
Loading...
001
Ray Canzanese @canzanese.com · 27/09/2026
support.citrix.com/support-home... just released
support.citrix.com
Loading...
000
Ray Canzanese @canzanese.com · 27/09/2026
ITW exploitation of two unpatched pre-authentication remote code execution (RCE) zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. sh3llc0d3.com/blog/inside-...
sh3llc0d3.com
Inside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit...
100
Ray Canzanese @canzanese.com · 21/09/2026
give.curesearch.org/fundraiser/7... We are biking to raisie funds for childhood leukemia research in honor of Steven Crowe, who passed away in 2005 after a brutal 9-month battle with acute myeloid leukemia, and we greatly appreciate anything you can donate!
001
Ray Canzanese @canzanese.com · 18/09/2026
The NICU. Those poor babies and their parents.
010
Ray Canzanese @canzanese.com · 17/09/2026
I was rejected from attending cybersecuritysummit.com Philadelphia because I work at a vendor that doesn't sponsor. I've never been to this conference, so I'm curious to hear from others -- What is it like? Just a bunch of vendor pitches?
cybersecuritysummit.com
The Official Cybersecurity Summit
The Cybersecurity Summit, ranked as one of the “Top 50 Must-Attend Conferences”, connect C-Level & Senior Executives responsible for protecting their company’s critical infrastructures with cutting-ed...
000
Ray Canzanese @canzanese.com · 07/09/2026
A good reminder that blocking or restricting browser extension installation can be a very effective risk reduction measure.
000
Ray Canzanese @canzanese.com · 06/09/2026
Looking forward to Jomboys break down of all the players that do this, complete with angle measurements, to show what BS this was.
010
Ray Canzanese @canzanese.com · 04/09/2026
We have seen steady growth in EtherHiding traffic since the beginning of the year. JC shares some great stats and breakdown of a recent campaign in his latest post.
000
Ray Canzanese @canzanese.com · 02/09/2026
NodeStealer is one of those malware families that just never seems to go away...
000
Ray Canzanese @canzanese.com · 27/08/2026
EtherHiding seems to be everywhere these days, the latest examplewe uncovered combines it with ClickFix to deliver the Amatera password stealer. www.netskope.com/blog/etherhi...
netskope.com
EtherHiding in the Browser: ClickFix Chain Ends in Amatera
Netskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a
000
Ray Canzanese @canzanese.com · 11/08/2026
Remember that AI sidebar extension that was stealing conversations? It is back, and less malicious this time around! After coming back "clean", they started layering in some adware. How long until the conversation stealing code comes back?
000
Ray Canzanese @canzanese.com · 05/08/2026
www.netskope.com/blog/npm-ste...
netskope.com
npm Stealer Reads Its C2 From an Ethereum Contract
Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan,
000
Reposted by Ray Canzanese
psparrows.bsky.social @psparrows.bsky.social · 05/08/2026
Here we are again! The Shai-Hulud supply chain attack resurfaces with 28 malicious npm packages across 4 unrelated namespaces, same credential-stealing playbook, one new trick: it reads its C2 address from an Ethereum smart contract instead of hardcoding it. www.netskope.com/blog/npm-ste...
netskope.com
npm Stealer Reads Its C2 From an Ethereum Contract
Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan,
011
Reposted by Ray Canzanese
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026
A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...
netskope.com
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network,
111
Ray Canzanese @canzanese.com · 28/07/2026
In focus in our 2026 AI report: A increase of DOWNSTREAM data policy violations, meaning that AI tools are returning data that consumers are not authorized to access. www.netskope.com/resources/th...
Log-scaled bar chart showing that upstream data policy violations dominate, but downstream violations are in a close second.
000
Ray Canzanese @canzanese.com · 23/07/2026
The top of the CyberGym leaderboard is already very crowded and K3 isn't even up there yet. But the most significant feature of this leaderboard is how close the GLM-5.2 is to the top of the board. I am very excited to see more open weights models near the top.
000
Ray Canzanese @canzanese.com · 23/07/2026
Get your bingo card ready!
000
Ray Canzanese @canzanese.com · 23/07/2026
Is it OK to hack each other now if we say "my bad" and blame AI?
000
Ray Canzanese @canzanese.com · 14/07/2026
My fingers are getting tired from clicking refresh on git.projectnightcrawler.dev/NightmareEcl.... Repo has been live for 11 hours now with no activity. Perhaps this is as close to bone-shattering as we are going to get?
git.projectnightcrawler.dev
LegacyHive
LegacyHive
000
Ray Canzanese @canzanese.com · 08/06/2026
Back to work after a vacation that included brief pauses for Infosecurity Europe and OrangeCon NL. As someone who has almost exclusively attended conferences in North America, it was great to see such a vibrant cybersecurity community on the other side of the pond!
032
Ray Canzanese @canzanese.com · 14/05/2026
Was anyone surprised by Microsoft's MDASH multi-model approach using Opus 4.6, Sonnet 4.6, and GPT-5.4 outperforming Mythos? We've been using multi-model approaches to basically everything we are doing with LLMs for a while with stellar results.
030
Ray Canzanese @canzanese.com · 12/05/2026
More Shai-Hulud attacks overnight hit tanstack and some other popular namespaces. Time to double check that nobody pulled the infected versions overnight and to start version pinning all your dependencies if you haven't already. www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud-Style npm Worm Hits @tanstack
The npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action
010
Ray Canzanese @canzanese.com · 11/05/2026
In the latest OpenClaw lure, we found a fake installer website shipping an infostealer, with at least three iterations of attacks so far this year. www.netskope.com/blog/opencla...
netskope.com
OpenClaw's Hologram: Fake Installer Ships Rust Infostealer
Netskope Threat Labs has found a fake OpenClaw installer delivering red-team-grade capabilities—all pointed at stealing credentials from over 250 crypto
040
Ray Canzanese @canzanese.com · 08/05/2026
DirtyFrag: Reliable root access confirmed on all major linux distributions (Ubuntu, RHEL, Fedora) due to two kernel bugs; one core CVE remains unpatched. PoC binaries appeared on VirusTotal within minutes. Read more: www.netskope.com/blog/dirtyfr...
netskope.com
DirtyFrag: Two Kernel Bugs Give Root on All Major Linux Distros
Summary DirtyFrag is a Linux local privilege escalation disclosed on May 7, 2026, exploiting two kernel page-cache write vulnerabilities–CVE-2026-43284
020
Ray Canzanese @canzanese.com · 30/04/2026
Shai-Hulud looks like it might be making a comeback. intercom-client@7.0.4 is compromised. www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud resurfaces: intercom-client@7.0.4 harvesting Github credentials
Summary The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic
010
Ray Canzanese @canzanese.com · 20/04/2026
Netskope Threat Labs has seen a steady stream of ClickFix attacks, but this one stood out because of its cross-platform support to target MacOS users. Jan Michael Alcantara wrote a great breakdown, including advice to ensure new MacOS protections are in place. www.netskope.com/blog/macos-c...
netskope.com
macOS ClickFix Campaign: AppleScript Stealers & New Terminal Protections
Summary Netskope Threat Labs is continuing its coverage of a ClickFix campaign targeting both Windows and macOS users. While our previous post focused on
000
Ray Canzanese @canzanese.com · 20/04/2026
Yes, I've talked to too many organizations who assume that spending more money on AI tokens is inherently valuable and token spend is used a proxy for efficiency.
010
Ray Canzanese @canzanese.com · 20/04/2026
fortune.com/article/why-... I see people talking about how AI is creating like 10x and 100x productivity gains, and then others talking about how it is just a few percentage points. I think that the truth is probably somewhere in the middle, but closer to the lower end.
fortune.com
Thousands of CEOs admit AI had no impact on employment or productivity—and it has economists resurrecting a paradox from 40 years ago | Fortune
In the 1980s, economist Robert Solow made an observation that reminded economists of today’s AI boom: “You can see the computer age everywhere but in the productivity statistics.”
110
Ray Canzanese @canzanese.com · 10/04/2026
Netskope's Hubert WS Lin (林悟生) is featured in Hitachi Systems Security Journal Vol. 77, where you can read all about his latest project, SaucePot, which he presented at Code Blue! お見事! www.hitachi-systems.com/report/speci...
000
Ray Canzanese @canzanese.com · 06/04/2026
The commoditization of ClickFix continues with a new MaaS Jan Michael Alcantara at Netskope Threat Labs has uncovered, this one featuring a nodeJS implementation, a modular windows RAT, and C2 over Tor. www.netskope.com/blog/from-cl...
netskope.com
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
Summary Netskope Threat Labs is tracking a new ClickFix campaign that targets Windows users. ClickFix became a prominent delivery vector in early 2025 for
110
Ray Canzanese @canzanese.com · 24/03/2026
Did the Docker scaffolding you used to install OpenClaw also install an infostealer? Netskope Threat Labs is tracking an AI-assisted lure factory to mass-generate over 300 polished, poisoned packages targeting developers looking for open-source AI tools. www.netskope.com/blog/opencla...
netskope.com
OpenClaw Trap: AI-Assisted Lure Factory Targets Developers & Gamers
Netskope Threat Labs identified a link to a malware campaign operating across at multiple GitHub repositories, spanning over 300 delivery packages,
111
Ray Canzanese @canzanese.com · 24/03/2026
On my way to #RSAC2026. Be sure to check out my colleague Gianpietro Cutolo's presentation on MCP security on Tuesday morning and stop by the Netskope booth 1127 in Moscone South. I hope to see you there! path.rsaconference.com/flow/rsac/us...
path.rsaconference.com
US26-Header
000
Ray Canzanese @canzanese.com · 12/03/2026
Phishing URL: invite[.]komiku[.]my[.]id/Teams/Windows/invite.php Notes: This is the latest in a wave of fake meeting invites delivering RMM tools that we have tracking. This time, it was a Datto RMM Agent. www.netskope.com/blog/attacke...
020
Ray Canzanese @canzanese.com · 12/03/2026
Shadow AI remains a significant challenge in the healthcare sector, with 32% of users opting for shadow AI apps, despite promising trends toward managed enterprise AI platform adoption. Read more in the new Netskope Threat Labs Healthcare Report. www.netskope.com/resources/th...
010
Ray Canzanese @canzanese.com · 12/03/2026
The Netskope AI Index let's you explore AI adoption trends for individual sectors, geos, and org sizes with weekly updates to track the latest trends. ai-index.netskope.com
000
Ray Canzanese @canzanese.com · 24/02/2026
We have seen the fake meeting invites slow down this week at Netskope Threat Labs, but they are still out there. The latest one I saw was a Teams meeting that downloaded a LogMeIn executable. www.netskope.com/blog/attacke...
netskope.com
Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures
Summary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications,
000
Ray Canzanese @canzanese.com · 23/02/2026
Since we at Netskope Threat Labs published our blog post about how to block/alert on OpenClaw installs, we have seen at least 65 new installs on managed devices. Playing with new tech is fun, but you need guardrails in place before you start running OpenClaw. www.netskope.com/blog/moltbot...
netskope.com
OpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Update 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the
100
Ray Canzanese @canzanese.com · 16/02/2026
Are RMMs just RATs now? www.netskope.com/blog/attacke...
netskope.com
Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures
Summary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications,
010
Ray Canzanese @canzanese.com · 16/02/2026
Didn't DOGE fix this already?
010
Ray Canzanese @canzanese.com · 10/02/2026
Stop installing OpenClaw in production systems. We are still seeing an unsettling number of new installs across multiple industries. Link has details on how to use Netskope to identify rogue installs and setup a block policy. www.netskope.com/blog/moltbot...
netskope.com
OpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Update 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the
010
Ray Canzanese @canzanese.com · 05/02/2026
Netskope Threat Labs is tracking a tech support scam campaign using malicious Bing ads to successfully drive traffic to the payloads hosted in Azure Blob Storage. www.netskope.com/blog/malicio...
netskope.com
Malicious Bing Ads Lead to Widespread Azure Tech Support Scams
Summary Starting on February 2 at around 16:00 UTC, Netskope Threat Labs was alerted to a spike of users across 48 different organizations clicking on
021
Ray Canzanese @canzanese.com · 03/02/2026
I'm really interested to know what the other 2/3 were. Porn? Clickbait? I can't remember the last time I've seen an ad on Facebook that wasn't utter garbage.
000
Ray Canzanese @canzanese.com · 03/02/2026
In all the containers, we have so far only seen two phone numbers so far: 1-866-520-2041 1-833-445-4045
000
Ray Canzanese @canzanese.com · 03/02/2026
Among the surprises in the report: (1) Japanese organizations are doing an excellent job reducing Shadow AI. (2) ChatGPT has been dethroned as the most popular AI App!
010
Ray Canzanese @canzanese.com · 30/01/2026
Updated this post today after they renamed it again to OpenClaw. More stuff to block...
000
Ray Canzanese @canzanese.com · 29/01/2026
MoltBot/ClawdBot is an open-source, self-hosted personal AI agent. It enables unauthenticated remote control by default and has privileged host access. For these reasons, we at Netskope recommend you review how it is being used at your org www.netskope.com/blog/moltbot...
netskope.com
MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection
Background MoltBot, previously known as ClawdBot, is an open-source, self-hosted personal AI agent that is run locally. It is advertised as a digital
110
Ray Canzanese @canzanese.com · 29/01/2026
I got my first E-ZPass phishing text message of the new year! These seem to have cooled off for a while and are not coming back strong. We've seen 48 new E-ZPass phishing domains targeting our customers at Netskope Threat Labs so far this year. The latest: ezpass[.]gov-hmp[.]cc
010