Ray Canzanese @canzanese.com · 01/10/2026We seem to have been tracking a constant onslaught of infostealers lately, but every now and then we come across an interesting crypto stealer. 000
Ray Canzanese @canzanese.com · 28/09/20262 days and 23 miles left to my cycling goal for Team Steve. Your donations support research like Dr. Moghimi's at Children's Hospital Los Angeles, developing a next-gen CAR T-cell therapy for acute myeloid leukemia (AML), which took Steve from us in 2005. give.curesearch.org/fundraiser/7... 000
Ray Canzanese @canzanese.com · 27/09/2026support.citrix.com/support-home...support.citrix.comLoading... 001
Ray Canzanese @canzanese.com · 27/09/2026support.citrix.com/support-home... just releasedsupport.citrix.comLoading... 000
Ray Canzanese @canzanese.com · 27/09/2026ITW exploitation of two unpatched pre-authentication remote code execution (RCE) zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. sh3llc0d3.com/blog/inside-...sh3llc0d3.comInside the NetScaler Zero-Day Siege: Chained Pre-Auth RCEs Weaponized in the Wild (watchTowr Disclosure) | Shellcode (Sh3llc0d3)A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploit... 100
Ray Canzanese @canzanese.com · 21/09/2026give.curesearch.org/fundraiser/7... We are biking to raisie funds for childhood leukemia research in honor of Steven Crowe, who passed away in 2005 after a brutal 9-month battle with acute myeloid leukemia, and we greatly appreciate anything you can donate! 001
Ray Canzanese @canzanese.com · 17/09/2026I was rejected from attending cybersecuritysummit.com Philadelphia because I work at a vendor that doesn't sponsor. I've never been to this conference, so I'm curious to hear from others -- What is it like? Just a bunch of vendor pitches?cybersecuritysummit.comThe Official Cybersecurity SummitThe Cybersecurity Summit, ranked as one of the “Top 50 Must-Attend Conferences”, connect C-Level & Senior Executives responsible for protecting their company’s critical infrastructures with cutting-ed... 000
Ray Canzanese @canzanese.com · 07/09/2026A good reminder that blocking or restricting browser extension installation can be a very effective risk reduction measure. 000
Ray Canzanese @canzanese.com · 06/09/2026Looking forward to Jomboys break down of all the players that do this, complete with angle measurements, to show what BS this was. 010
Ray Canzanese @canzanese.com · 04/09/2026We have seen steady growth in EtherHiding traffic since the beginning of the year. JC shares some great stats and breakdown of a recent campaign in his latest post. 000
Ray Canzanese @canzanese.com · 02/09/2026NodeStealer is one of those malware families that just never seems to go away... 000
Ray Canzanese @canzanese.com · 27/08/2026EtherHiding seems to be everywhere these days, the latest examplewe uncovered combines it with ClickFix to deliver the Amatera password stealer. www.netskope.com/blog/etherhi...netskope.comEtherHiding in the Browser: ClickFix Chain Ends in AmateraNetskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a 000
Ray Canzanese @canzanese.com · 11/08/2026Remember that AI sidebar extension that was stealing conversations? It is back, and less malicious this time around! After coming back "clean", they started layering in some adware. How long until the conversation stealing code comes back? 000
Ray Canzanese @canzanese.com · 05/08/2026www.netskope.com/blog/npm-ste...netskope.comnpm Stealer Reads Its C2 From an Ethereum ContractNetskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, 000
Reposted by Ray Canzanesepsparrows.bsky.social @psparrows.bsky.social · 05/08/2026Here we are again! The Shai-Hulud supply chain attack resurfaces with 28 malicious npm packages across 4 unrelated namespaces, same credential-stealing playbook, one new trick: it reads its C2 address from an Ethereum smart contract instead of hardcoding it. www.netskope.com/blog/npm-ste...netskope.comnpm Stealer Reads Its C2 From an Ethereum ContractNetskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, 011
Reposted by Ray CanzaneseNetskope Threat Labs @netskopethreatlabs.com · 04/08/2026A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...netskope.comFake CAPTCHA, Real Business: Traffic Distribution for HireA single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network, 111
Ray Canzanese @canzanese.com · 28/07/2026In focus in our 2026 AI report: A increase of DOWNSTREAM data policy violations, meaning that AI tools are returning data that consumers are not authorized to access. www.netskope.com/resources/th... 000
Ray Canzanese @canzanese.com · 23/07/2026The top of the CyberGym leaderboard is already very crowded and K3 isn't even up there yet. But the most significant feature of this leaderboard is how close the GLM-5.2 is to the top of the board. I am very excited to see more open weights models near the top. 000
Ray Canzanese @canzanese.com · 23/07/2026Is it OK to hack each other now if we say "my bad" and blame AI? 000
Ray Canzanese @canzanese.com · 14/07/2026My fingers are getting tired from clicking refresh on git.projectnightcrawler.dev/NightmareEcl.... Repo has been live for 11 hours now with no activity. Perhaps this is as close to bone-shattering as we are going to get?git.projectnightcrawler.devLegacyHiveLegacyHive 000
Ray Canzanese @canzanese.com · 08/06/2026Back to work after a vacation that included brief pauses for Infosecurity Europe and OrangeCon NL. As someone who has almost exclusively attended conferences in North America, it was great to see such a vibrant cybersecurity community on the other side of the pond! 032
Ray Canzanese @canzanese.com · 14/05/2026Was anyone surprised by Microsoft's MDASH multi-model approach using Opus 4.6, Sonnet 4.6, and GPT-5.4 outperforming Mythos? We've been using multi-model approaches to basically everything we are doing with LLMs for a while with stellar results. 030
Ray Canzanese @canzanese.com · 12/05/2026More Shai-Hulud attacks overnight hit tanstack and some other popular namespaces. Time to double check that nobody pulled the infected versions overnight and to start version pinning all your dependencies if you haven't already. www.netskope.com/blog/shai-hu...netskope.comShai-Hulud-Style npm Worm Hits @tanstackThe npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action 010
Ray Canzanese @canzanese.com · 11/05/2026In the latest OpenClaw lure, we found a fake installer website shipping an infostealer, with at least three iterations of attacks so far this year. www.netskope.com/blog/opencla...netskope.comOpenClaw's Hologram: Fake Installer Ships Rust InfostealerNetskope Threat Labs has found a fake OpenClaw installer delivering red-team-grade capabilities—all pointed at stealing credentials from over 250 crypto 040
Ray Canzanese @canzanese.com · 08/05/2026DirtyFrag: Reliable root access confirmed on all major linux distributions (Ubuntu, RHEL, Fedora) due to two kernel bugs; one core CVE remains unpatched. PoC binaries appeared on VirusTotal within minutes. Read more: www.netskope.com/blog/dirtyfr...netskope.comDirtyFrag: Two Kernel Bugs Give Root on All Major Linux DistrosSummary DirtyFrag is a Linux local privilege escalation disclosed on May 7, 2026, exploiting two kernel page-cache write vulnerabilities–CVE-2026-43284 020
Ray Canzanese @canzanese.com · 30/04/2026Shai-Hulud looks like it might be making a comeback. intercom-client@7.0.4 is compromised. www.netskope.com/blog/shai-hu...netskope.comShai-Hulud resurfaces: intercom-client@7.0.4 harvesting Github credentialsSummary The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic 010
Ray Canzanese @canzanese.com · 20/04/2026Netskope Threat Labs has seen a steady stream of ClickFix attacks, but this one stood out because of its cross-platform support to target MacOS users. Jan Michael Alcantara wrote a great breakdown, including advice to ensure new MacOS protections are in place. www.netskope.com/blog/macos-c...netskope.commacOS ClickFix Campaign: AppleScript Stealers & New Terminal ProtectionsSummary Netskope Threat Labs is continuing its coverage of a ClickFix campaign targeting both Windows and macOS users. While our previous post focused on 000
Ray Canzanese @canzanese.com · 20/04/2026Yes, I've talked to too many organizations who assume that spending more money on AI tokens is inherently valuable and token spend is used a proxy for efficiency. 010
Ray Canzanese @canzanese.com · 20/04/2026fortune.com/article/why-... I see people talking about how AI is creating like 10x and 100x productivity gains, and then others talking about how it is just a few percentage points. I think that the truth is probably somewhere in the middle, but closer to the lower end.fortune.comThousands of CEOs admit AI had no impact on employment or productivity—and it has economists resurrecting a paradox from 40 years ago | FortuneIn the 1980s, economist Robert Solow made an observation that reminded economists of today’s AI boom: “You can see the computer age everywhere but in the productivity statistics.” 110
Ray Canzanese @canzanese.com · 10/04/2026Netskope's Hubert WS Lin (林悟生) is featured in Hitachi Systems Security Journal Vol. 77, where you can read all about his latest project, SaucePot, which he presented at Code Blue! お見事! www.hitachi-systems.com/report/speci... 000
Ray Canzanese @canzanese.com · 06/04/2026The commoditization of ClickFix continues with a new MaaS Jan Michael Alcantara at Netskope Threat Labs has uncovered, this one featuring a nodeJS implementation, a modular windows RAT, and C2 over Tor. www.netskope.com/blog/from-cl...netskope.comFrom ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin PanelSummary Netskope Threat Labs is tracking a new ClickFix campaign that targets Windows users. ClickFix became a prominent delivery vector in early 2025 for 110
Ray Canzanese @canzanese.com · 24/03/2026Did the Docker scaffolding you used to install OpenClaw also install an infostealer? Netskope Threat Labs is tracking an AI-assisted lure factory to mass-generate over 300 polished, poisoned packages targeting developers looking for open-source AI tools. www.netskope.com/blog/opencla...netskope.comOpenClaw Trap: AI-Assisted Lure Factory Targets Developers & GamersNetskope Threat Labs identified a link to a malware campaign operating across at multiple GitHub repositories, spanning over 300 delivery packages, 111
Ray Canzanese @canzanese.com · 24/03/2026On my way to #RSAC2026. Be sure to check out my colleague Gianpietro Cutolo's presentation on MCP security on Tuesday morning and stop by the Netskope booth 1127 in Moscone South. I hope to see you there! path.rsaconference.com/flow/rsac/us...path.rsaconference.comUS26-Header 000
Ray Canzanese @canzanese.com · 12/03/2026Phishing URL: invite[.]komiku[.]my[.]id/Teams/Windows/invite.php Notes: This is the latest in a wave of fake meeting invites delivering RMM tools that we have tracking. This time, it was a Datto RMM Agent. www.netskope.com/blog/attacke... 020
Ray Canzanese @canzanese.com · 12/03/2026Shadow AI remains a significant challenge in the healthcare sector, with 32% of users opting for shadow AI apps, despite promising trends toward managed enterprise AI platform adoption. Read more in the new Netskope Threat Labs Healthcare Report. www.netskope.com/resources/th... 010
Ray Canzanese @canzanese.com · 12/03/2026The Netskope AI Index let's you explore AI adoption trends for individual sectors, geos, and org sizes with weekly updates to track the latest trends. ai-index.netskope.com 000
Ray Canzanese @canzanese.com · 24/02/2026We have seen the fake meeting invites slow down this week at Netskope Threat Labs, but they are still out there. The latest one I saw was a Teams meeting that downloaded a LogMeIn executable. www.netskope.com/blog/attacke...netskope.comAttackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams LuresSummary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications, 000
Ray Canzanese @canzanese.com · 23/02/2026Since we at Netskope Threat Labs published our blog post about how to block/alert on OpenClaw installs, we have seen at least 65 new installs on managed devices. Playing with new tech is fun, but you need guardrails in place before you start running OpenClaw. www.netskope.com/blog/moltbot...netskope.comOpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope ProtectionUpdate 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the 100
Ray Canzanese @canzanese.com · 16/02/2026Are RMMs just RATs now? www.netskope.com/blog/attacke...netskope.comAttackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams LuresSummary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications, 010
Ray Canzanese @canzanese.com · 10/02/2026Stop installing OpenClaw in production systems. We are still seeing an unsettling number of new installs across multiple industries. Link has details on how to use Netskope to identify rogue installs and setup a block policy. www.netskope.com/blog/moltbot...netskope.comOpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope ProtectionUpdate 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the 010
Ray Canzanese @canzanese.com · 05/02/2026Netskope Threat Labs is tracking a tech support scam campaign using malicious Bing ads to successfully drive traffic to the payloads hosted in Azure Blob Storage. www.netskope.com/blog/malicio...netskope.comMalicious Bing Ads Lead to Widespread Azure Tech Support ScamsSummary Starting on February 2 at around 16:00 UTC, Netskope Threat Labs was alerted to a spike of users across 48 different organizations clicking on 021
Ray Canzanese @canzanese.com · 03/02/2026I'm really interested to know what the other 2/3 were. Porn? Clickbait? I can't remember the last time I've seen an ad on Facebook that wasn't utter garbage. 000
Ray Canzanese @canzanese.com · 03/02/2026In all the containers, we have so far only seen two phone numbers so far: 1-866-520-2041 1-833-445-4045 000
Ray Canzanese @canzanese.com · 03/02/2026Among the surprises in the report: (1) Japanese organizations are doing an excellent job reducing Shadow AI. (2) ChatGPT has been dethroned as the most popular AI App! 010
Ray Canzanese @canzanese.com · 30/01/2026Updated this post today after they renamed it again to OpenClaw. More stuff to block... 000
Ray Canzanese @canzanese.com · 29/01/2026MoltBot/ClawdBot is an open-source, self-hosted personal AI agent. It enables unauthenticated remote control by default and has privileged host access. For these reasons, we at Netskope recommend you review how it is being used at your org www.netskope.com/blog/moltbot...netskope.comMoltBot/ClawdBot: The Risky Personal AI Agent and Netskope ProtectionBackground MoltBot, previously known as ClawdBot, is an open-source, self-hosted personal AI agent that is run locally. It is advertised as a digital 110
Ray Canzanese @canzanese.com · 29/01/2026I got my first E-ZPass phishing text message of the new year! These seem to have cooled off for a while and are not coming back strong. We've seen 48 new E-ZPass phishing domains targeting our customers at Netskope Threat Labs so far this year. The latest: ezpass[.]gov-hmp[.]cc 010