MalwareInfosecurity Magazine·6 days ago

Infostealers Harvest 1.7 Billion Credentials in Six Months

Infostealers harvested 1.7 billion credentials during the first six months of 2026, according to Flashpoint research. The data underscores the continued prevalence and effectiveness of infostealer malware as a primary vector for large-scale credential theft. This volume of compromised credentials significantly expands the attack surface available to threat actors for lateral movement and account takeover campaigns.

MalwareHuntress Blog·1 week ago

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

MacSync Stealer, a macOS infostealer, is being distributed through fraudulent download pages impersonating Claude Code, exploiting users searching for the legitimate tool. Huntress SOC analysts have reverse engineered the malware and released a detailed technical analysis of its capabilities and delivery mechanism.

OtherGreyNoise Labs·1 week ago

A New Way to Navigate GreyNoise

Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.

Supply ChainThe Register·1 week ago

ChainDrop worm crawls into npm supply chain, evades standard defenses

A worm dubbed ChainDrop, using the Shai-Hulud variant, has compromised 444 npm packages and propagated through both tarballs and developer tool hooks to evade standard security detection mechanisms. The attack demonstrates a sophisticated supply chain infiltration method targeting the npm ecosystem at scale. The worm's ability to spread through multiple infection vectors highlights the challenges in securing dependency management systems against determined adversaries.

Nation-StateTenable·1 week ago

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable's Research Special Operations team has identified a cluster of seven agentic AI incidents spanning November 2025 through August 2026, anchored by Taiwan's July 2026 autonomous AI attack that mapped 21 government systems, compromised 85 accounts, and exfiltrated 2,564 personnel records in four days. The cluster reveals that multiple unrelated threat actors—including JADEPUFFER and knaithe/KnYuan—have independently weaponized open-source AI agent frameworks to autonomously exploit common identity and authentication misconfigurations at machine speed, demonstrating that near-autonomous offensive AI has transitioned from theoretical risk to operational reality. Organizations face dual exposure: being targeted by autonomous agents that can self-discover and exploit weak credentials and exposed federation endpoints within minutes, and governance gaps in controlling their own deployed AI agents that cannot be quickly terminated or purpose-limited.

Policy & LegalWired Security·1 week ago

New York City Lawmakers Push to ‘Ban the Scan’ at MSG

New York City lawmakers and privacy advocates are pushing for stricter regulations on biometric surveillance systems used at public venues like Madison Square Garden, with the effort dubbed "Ban the Scan." The coalition, which includes politicians and musicians, is calling for tighter restrictions on how such facial recognition and scanning technologies can be deployed at entertainment and gathering spaces.

VulnerabilityRapid7 Blog·1 week ago

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Metasploit Framework 6.5 introduces 13 new exploit modules targeting critical vulnerabilities across WordPress, Ghost CMS, Joomla, SonicWall, and Linux systems, alongside support for malleable HTTP profiles and Windows AArch64 payloads. The release includes significant enhancements to the Model Context Protocol (MCP) server functionality, improved Kerberos ticket tracing, and multi-fetch payload capabilities, alongside 15 bug fixes addressing validation, port conflict handling, and SMB service registration issues.

OtherSchneier on Security·1 week ago

Friday Squid Blogging: Searching for the Colossal Squid

Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

OtherDark Reading·1 week ago

Mission-Driven Security: Inside a Global Bank's Defense

In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.

VulnerabilityDark Reading·1 week ago

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.

OtherSchneier on Security·1 week ago

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here. I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET. I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2026; my talk is on Wednesday, September 23. I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD. I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21. The list is maintained on this page.

Data BreachInfosecurity Magazine·1 week ago

Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

Researchers have confirmed that the extortion group ExfilSquad has successfully stolen and leaked sensitive data from at least 13 organizations, with the stolen datasets distributed through torrent channels. The verification of ExfilSquad's access to this data across multiple victims indicates an active and ongoing extortion campaign targeting a broad range of targets.

Load more