Infostealers harvested 1.7 billion credentials during the first six months of 2026, according to Flashpoint research. The data underscores the continued prevalence and effectiveness of infostealer malware as a primary vector for large-scale credential theft. This volume of compromised credentials significantly expands the attack surface available to threat actors for lateral movement and account takeover campaigns.
MacSync Stealer, a macOS infostealer, is being distributed through fraudulent download pages impersonating Claude Code, exploiting users searching for the legitimate tool. Huntress SOC analysts have reverse engineered the malware and released a detailed technical analysis of its capabilities and delivery mechanism.
Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.
A worm dubbed ChainDrop, using the Shai-Hulud variant, has compromised 444 npm packages and propagated through both tarballs and developer tool hooks to evade standard security detection mechanisms. The attack demonstrates a sophisticated supply chain infiltration method targeting the npm ecosystem at scale. The worm's ability to spread through multiple infection vectors highlights the challenges in securing dependency management systems against determined adversaries.
Tenable's Research Special Operations team has identified a cluster of seven agentic AI incidents spanning November 2025 through August 2026, anchored by Taiwan's July 2026 autonomous AI attack that mapped 21 government systems, compromised 85 accounts, and exfiltrated 2,564 personnel records in four days. The cluster reveals that multiple unrelated threat actors—including JADEPUFFER and knaithe/KnYuan—have independently weaponized open-source AI agent frameworks to autonomously exploit common identity and authentication misconfigurations at machine speed, demonstrating that near-autonomous offensive AI has transitioned from theoretical risk to operational reality. Organizations face dual exposure: being targeted by autonomous agents that can self-discover and exploit weak credentials and exposed federation endpoints within minutes, and governance gaps in controlling their own deployed AI agents that cannot be quickly terminated or purpose-limited.
New York City lawmakers and privacy advocates are pushing for stricter regulations on biometric surveillance systems used at public venues like Madison Square Garden, with the effort dubbed "Ban the Scan." The coalition, which includes politicians and musicians, is calling for tighter restrictions on how such facial recognition and scanning technologies can be deployed at entertainment and gathering spaces.
Metasploit Framework 6.5 introduces 13 new exploit modules targeting critical vulnerabilities across WordPress, Ghost CMS, Joomla, SonicWall, and Linux systems, alongside support for malleable HTTP profiles and Windows AArch64 payloads. The release includes significant enhancements to the Model Context Protocol (MCP) server functionality, improved Kerberos ticket tracing, and multi-fetch payload capabilities, alongside 15 bug fixes addressing validation, port conflict handling, and SMB service registration issues.
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here. I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET. I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2026; my talk is on Wednesday, September 23. I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD. I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21. The list is maintained on this page.
Researchers have confirmed that the extortion group ExfilSquad has successfully stolen and leaked sensitive data from at least 13 organizations, with the stolen datasets distributed through torrent channels. The verification of ExfilSquad's access to this data across multiple victims indicates an active and ongoing extortion campaign targeting a broad range of targets.