<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Netskope Threat Labs</title><description>Security research on AI-enabled attacks, cloud-enabled attacks, web threats, and malware.</description><link>https://threatlabs.netskope.com/</link><language>en-us</language><item><title>Netskope Threat Labs Report: Asia 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-asia-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-asia-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations in Asia. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.</description><pubDate>Mon, 05 Oct 2026 01:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-asia-2026.png" length="0" type="image/png"/></item><item><title>$100k in Crypto Drained by the Underground Operation</title><link>https://threatlabs.netskope.com/blog/2026/09/underground-crypto-drain-operation/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/09/underground-crypto-drain-operation/</guid><description>A Vidar-class stealer injected into dllhost.exe takes its commands from rotating Cloudflare-fronted /api/machine gates, automatically drains crypto-exchange accounts, and rewrites the withdrawal confirmation email in the victim&apos;s webmail.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>Credential Theft</category><category>Crypto</category><enclosure url="https://threatlabs.netskope.com/og/2026/09/underground-crypto-drain-operation.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: France 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-france-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-france-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations in France. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.</description><pubDate>Tue, 29 Sep 2026 08:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-france-2026.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Retail 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-retail-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-retail-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting retail organizations. It covers the growing adoption of AI tools and the data security problems that come with them, and tracks the rise in data policy violations as sensitive information leaves the organization through unauthorized cloud services, personal apps, and AI platforms.</description><pubDate>Tue, 22 Sep 2026 17:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><category>Retail</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-retail-2026.png" length="0" type="image/png"/></item><item><title>A Fake Security Locker, Delivered by Google Ads</title><link>https://threatlabs.netskope.com/blog/2026/09/a-fake-security-locker-delivered-by-google-ads/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/09/a-fake-security-locker-delivered-by-google-ads/</guid><description>A cloud-hosted tech-support-scam kit shows a working online store to crawlers and sandboxes, but decrypts a hidden C2 and an OS-tailored fake security locker in the browser only after a real mouse moves.</description><pubDate>Mon, 14 Sep 2026 18:00:00 GMT</pubDate><dc:creator>John Carlo Marquez</dc:creator><category>Social Engineering</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/09/a-fake-security-locker-delivered-by-google-ads.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Australia &amp; New Zealand 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-australia-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-australia-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting ANZn organizations. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, in which sensitive information is increasingly leaked through unauthorized cloud services, personal applications, and AI platforms.</description><pubDate>Tue, 08 Sep 2026 22:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-australia-2026.png" length="0" type="image/png"/></item><item><title>Malware on the Blockchain: An Ongoing Campaign&apos;s New WebRTC Twist</title><link>https://threatlabs.netskope.com/blog/2026/09/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/09/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist/</guid><description>EtherHiding, a technique that uses BNB Smart Chain (BSC) testnet as takedown-resistant payload storage, has been seen across more than 5,400 compromised websites in the last few months.</description><pubDate>Mon, 31 Aug 2026 18:00:00 GMT</pubDate><dc:creator>John Carlo Marquez</dc:creator><category>Malware</category><category>Command and Control</category><category>Social Engineering</category><enclosure url="https://threatlabs.netskope.com/og/2026/09/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist.png" length="0" type="image/png"/></item><item><title>Python NodeStealer: AI-Assisted to Full Spyware</title><link>https://threatlabs.netskope.com/blog/2026/08/python-nodestealer/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/python-nodestealer/</guid><description>Since 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and Ads Manager accounts</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>AI</category><category>Credential Theft</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/python-nodestealer.png" length="0" type="image/png"/></item><item><title>EtherHiding in the Browser: ClickFix Chain Ends in Amatera</title><link>https://threatlabs.netskope.com/blog/2026/08/etherhiding-in-the-browser-clickfix-chain-ends-in-amatera/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/etherhiding-in-the-browser-clickfix-chain-ends-in-amatera/</guid><description>A WordPress mass-compromise campaign runs a malicious Service Worker that strips Content-Security-Policy and resolves its ClickFix payload from a Base smart contract, the first convergence of Service Worker delivery and blockchain dead-drop C2 that Netskope Threat Labs has observed. The decoded chain runs through an MP3/HTA polyglot, a fileless PowerShell stage, the Emmenhtal loader, and a steganographic image on a legitimate CDN, ending at the Amatera password stealer.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>Social Engineering</category><category>Credential Theft</category><category>Crypto</category><category>Command and Control</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/etherhiding-in-the-browser-clickfix-chain-ends-in-amatera.png" length="0" type="image/png"/></item><item><title>Blockchain Dead Drop Resolvers Explained</title><link>https://threatlabs.netskope.com/blog/2026/08/blockchain-dead-drop-resolvers-explained/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/blockchain-dead-drop-resolvers-explained/</guid><description>A practitioner primer on blockchain dead drop resolvers - how eight unrelated malware families across Ethereum, Solana, and TON use public smart contracts to fetch C2 addresses at runtime, and how to detect them.</description><pubDate>Tue, 18 Aug 2026 11:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>Command and Control</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/blockchain-dead-drop-resolvers-explained.png" length="0" type="image/png"/></item><item><title>AI Sidebar Extension Monetizes Its Own Updates</title><link>https://threatlabs.netskope.com/blog/2026/08/ai-sidebar-extension-monetizes-its-own-updates/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/ai-sidebar-extension-monetizes-its-own-updates/</guid><description>The Chrome extension &quot;AI Sidebar with DeepSeek AI&quot; that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping code to enterprise endpoints in July 2026. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks it pulled the rug again with a new update. Netskope Threat Labs analyzed the new build. While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/ai-sidebar-extension-monetizes-its-own-updates.png" length="0" type="image/png"/></item><item><title>Fake CAPTCHA, Real Business: Traffic Distribution for Hire</title><link>https://threatlabs.netskope.com/blog/2026/08/fake-captcha-real-business-traffic-distribution-for-hire/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/fake-captcha-real-business-traffic-distribution-for-hire/</guid><description>A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow&apos;s content delivery network, where Google indexes them as ordinary &quot;upgrade g…</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Social Engineering</category><category>Malware</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/fake-captcha-real-business-traffic-distribution-for-hire.png" length="0" type="image/png"/></item><item><title>npm Stealer Reads Its C2 From an Ethereum Contract</title><link>https://threatlabs.netskope.com/blog/2026/08/npm-stealer-reads-its-c2-from-an-ethereum-contract/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/npm-stealer-reads-its-c2-from-an-ethereum-contract/</guid><description>Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, @or-sdk, @onereach, and @umacloud) on 2026-08-04. T…</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>Social Engineering</category><category>Malware</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/npm-stealer-reads-its-c2-from-an-ethereum-contract.png" length="0" type="image/png"/></item><item><title>Developers in the Crosshairs: Fake AI Tools Deliver Infostealer</title><link>https://threatlabs.netskope.com/blog/2026/08/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/08/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer/</guid><description>In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique. As we tracked this infostealer, we uncovered o…</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>Credential Theft</category><category>Supply Chain</category><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/08/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer.png" length="0" type="image/png"/></item><item><title>Beyond Shadow AI: The Netskope AI Report</title><link>https://threatlabs.netskope.com/blog/2026/07/beyond-shadow-ai-the-netskope-ai-report/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/07/beyond-shadow-ai-the-netskope-ai-report/</guid><description>Future-proof your enterprise against agentic AI vectors and supply chain attacks. Read the Netskope AI Report 2026 to protect downstream data.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><dc:creator>Raymond Canzanese</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/07/beyond-shadow-ai-the-netskope-ai-report.png" length="0" type="image/png"/></item><item><title>Netskope AI Report: 2026</title><link>https://threatlabs.netskope.com/reports/2026/netskope-ai-report-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/netskope-ai-report-2026/</guid><description>The 2026 threat landscape has moved beyond shadow AI discovery into a phase of bidirectional, agentic risk. We are no longer just monitoring the prompts employees send to third-party models; we are now governing the integrity of the AI-driven supply chain. The rapid integration of the Model Context Protocol (MCP) effectively bridges our internal data stores with external agents, while the surge in autonomous coding tools like Cursor and Claude Code has drastically lowered the barrier for automated, malicious code execution. For security teams, this mandates a pivot from simple data to bidirectional inspection. We need to treat every agentic interaction as a potential execution vector, not just a data request.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><enclosure url="https://threatlabs.netskope.com/og/2026/netskope-ai-report-2026.png" length="0" type="image/png"/></item><item><title>World Cup Retrospective: Analyzing the Surge in Cyber Threats</title><link>https://threatlabs.netskope.com/blog/2026/07/world-cup-retrospective-analyzing-the-surge-in-cyber-threats/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/07/world-cup-retrospective-analyzing-the-surge-in-cyber-threats/</guid><description>High-profile events consistently attract opportunistic attackers, and the 2026 FIFA World Cup was a prime example of this trend. Because the tournament generated massive global interest and traffic, i…</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><dc:creator>John Carlo Marquez</dc:creator><category>Malware</category><category>Phishing</category><enclosure url="https://threatlabs.netskope.com/og/2026/07/world-cup-retrospective-analyzing-the-surge-in-cyber-threats.png" length="0" type="image/png"/></item><item><title>Threat Labs Report: India 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-india-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-india-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting Indian organizations. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-india-2026.png" length="0" type="image/png"/></item><item><title>macOS ClickFix Lures Deploy AppleScript Stealer &amp; Persistent RAT</title><link>https://threatlabs.netskope.com/blog/2026/06/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/06/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat/</guid><description>In April 2026, Netskope Threat Labs reported a ClickFix campaign delivering an AppleScript-based infostealer to macOS users, pilfering sensitive data through a persistent fake system dialog. Through o…</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>Credential Theft</category><category>Crypto</category><enclosure url="https://threatlabs.netskope.com/og/2026/06/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat.png" length="0" type="image/png"/></item><item><title>AI Agents and the OAuth Trust Problem at Scale</title><link>https://threatlabs.netskope.com/blog/2026/06/ai-agents-and-the-oauth-trust-problem-at-scale/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/06/ai-agents-and-the-oauth-trust-problem-at-scale/</guid><description>At Infosecurity Europe 2026, Netskope Threat Labs presented research on how OAuth authorization abuse has evolved from third-party supply chain breaches into a structural crisis for the agentic era. T…</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><dc:creator>Raymond Canzanese</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/06/ai-agents-and-the-oauth-trust-problem-at-scale.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Europe 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-europe-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-europe-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting European organizations. It addresses the increasing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-europe-2026.png" length="0" type="image/png"/></item><item><title>Shai-Hulud-Style npm Worm Hits @tanstack</title><link>https://threatlabs.netskope.com/blog/2026/05/shai-hulud-style-npm-worm-hits-tanstack/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/05/shai-hulud-style-npm-worm-hits-tanstack/</guid><description>The npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces have been compromised and use a cl…</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>Malware</category><category>Supply Chain</category><category>Credential Theft</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/05/shai-hulud-style-npm-worm-hits-tanstack.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Brazil 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-brazil-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-brazil-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting Brazilian organizations. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-brazil-2026.png" length="0" type="image/png"/></item><item><title>DirtyFrag: Two Kernel Bugs Give Root on All Major Linux Distros</title><link>https://threatlabs.netskope.com/blog/2026/05/dirtyfrag-two-kernel-bugs-give-root-on-all-major-linux-distros/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/05/dirtyfrag-two-kernel-bugs-give-root-on-all-major-linux-distros/</guid><description>DirtyFrag is a Linux local privilege escalation disclosed on May 7, 2026, exploiting two kernel page-cache write vulnerabilities–CVE-2026-43284 (xfrm-ESP, patched in mainline only) and CVE-2…</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Vulnerability</category><category>Malware</category><enclosure url="https://threatlabs.netskope.com/og/2026/05/dirtyfrag-two-kernel-bugs-give-root-on-all-major-linux-distros.png" length="0" type="image/png"/></item><item><title>OpenClaw&apos;s Hologram: Fake Installer Ships Rust Infostealer</title><link>https://threatlabs.netskope.com/blog/2026/05/openclaw-hologram-fake-installer-ships-rust-infostealer/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/05/openclaw-hologram-fake-installer-ships-rust-infostealer/</guid><description>Netskope Threat Labs has found a fake OpenClaw installer delivering red-team-grade capabilities—all pointed at stealing credentials from over 250 crypto wallet and password manager extensions. The dro…</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>Credential Theft</category><category>Crypto</category><enclosure url="https://threatlabs.netskope.com/og/2026/05/openclaw-hologram-fake-installer-ships-rust-infostealer.png" length="0" type="image/png"/></item><item><title>Shai-Hulud Resurfaces: Intercom-client@7.0.4 Harvesting Github Credentials</title><link>https://threatlabs.netskope.com/blog/2026/04/shai-hulud-intercom-client-7-0-4/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/04/shai-hulud-intercom-client-7-0-4/</guid><description>The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic drop-and-execute attack pattern to run an infostealer…</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>Malware</category><category>Supply Chain</category><category>Credential Theft</category><enclosure url="https://threatlabs.netskope.com/og/2026/04/shai-hulud-intercom-client-7-0-4.png" length="0" type="image/png"/></item><item><title>macOS ClickFix Campaign: AppleScript Stealers &amp; New Terminal Protections</title><link>https://threatlabs.netskope.com/blog/2026/04/macos-clickfix-campaign-applescript-stealers-new-terminal-protections/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/04/macos-clickfix-campaign-applescript-stealers-new-terminal-protections/</guid><description>Netskope Threat Labs is continuing its coverage of a ClickFix campaign targeting both Windows and macOS users. While our previous post focused on a modular NodeJS-based remote access trojan …</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>Credential Theft</category><category>Crypto</category><enclosure url="https://threatlabs.netskope.com/og/2026/04/macos-clickfix-campaign-applescript-stealers-new-terminal-protections.png" length="0" type="image/png"/></item><item><title>From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel</title><link>https://threatlabs.netskope.com/blog/2026/04/from-clickfix-to-maas-exposing-a-modular-windows-rat-and-its-admin-panel/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/04/from-clickfix-to-maas-exposing-a-modular-windows-rat-and-its-admin-panel/</guid><description>Netskope Threat Labs is tracking a new ClickFix campaign that targets Windows users. ClickFix became a prominent delivery vector in early 2025 for delivering malware like LegionLoader and Lu…</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>Crypto</category><enclosure url="https://threatlabs.netskope.com/og/2026/04/from-clickfix-to-maas-exposing-a-modular-windows-rat-and-its-admin-panel.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Financial Services 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-financial-services-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-financial-services-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within the financial services sector. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Financial Service &amp; Insurance</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-financial-services-2026.png" length="0" type="image/png"/></item><item><title>OpenClaw Trap: AI-Assisted Lure Factory Targets Developers &amp; Gamers</title><link>https://threatlabs.netskope.com/blog/2026/03/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/03/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers/</guid><description>Netskope Threat Labs identified a link to a malware campaign operating across at multiple GitHub repositories, spanning over 300 delivery packages, including an OpenClaw deployment, an AI developer to…</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate><dc:creator>Vini Egerland</dc:creator><category>Malware</category><category>Supply Chain</category><category>Credential Theft</category><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/03/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers.png" length="0" type="image/png"/></item><item><title>Threat Labs Report: Healthcare 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-healthcare-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-healthcare-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within the Healthcare sector. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><category>Healthcare &amp; Life Sciences</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-healthcare-2026.png" length="0" type="image/png"/></item><item><title>Attackers Weaponize Signed RMM Tools via Zoom, Meet, &amp; Teams Lures</title><link>https://threatlabs.netskope.com/blog/2026/02/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/02/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures/</guid><description>Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications, including Zoom, Microsoft Teams, and Google Meet. T…</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Phishing</category><category>Malware</category><enclosure url="https://threatlabs.netskope.com/og/2026/02/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures.png" length="0" type="image/png"/></item><item><title>Malicious Bing Ads Lead to Widespread Azure Tech Support Scams</title><link>https://threatlabs.netskope.com/blog/2026/02/malicious-bing-ads-lead-to-widespread-azure-tech-support-scams/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/02/malicious-bing-ads-lead-to-widespread-azure-tech-support-scams/</guid><description>Starting on February 2 at around 16:00 UTC, Netskope Threat Labs was alerted to a spike of users across 48 different organizations clicking on tech support scam links hosted in Azure Blob St…</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate><dc:creator>Raymond Canzanese</dc:creator><category>Phishing</category><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2026/02/malicious-bing-ads-lead-to-widespread-azure-tech-support-scams.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Japan 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-japan-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-japan-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within the Japan region. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-japan-2026.png" length="0" type="image/png"/></item><item><title>OpenClaw/MoltBot/ClawdBot: The Risky Personal AI Agent and Netskope Protection</title><link>https://threatlabs.netskope.com/blog/2026/01/moltbot-clawdbot-the-risky-personal-ai-agent-and-netskope-protection/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2026/01/moltbot-clawdbot-the-risky-personal-ai-agent-and-netskope-protection/</guid><description>Update 2026-01-30 (18:00Z): Following its second rename this week, ClawdBot is now known as OpenClaw. We have updated the paths in this guide to match the latest changes. Background OpenClaw, prev…</description><pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2026/01/moltbot-clawdbot-the-risky-personal-ai-agent-and-netskope-protection.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report — Canada 2026</title><link>https://threatlabs.netskope.com/reports/2026/threat-labs-report-canada-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/threat-labs-report-canada-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within Canada. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/threat-labs-report-canada-2026.png" length="0" type="image/png"/></item><item><title>Cloud and Threat Report: 2026</title><link>https://threatlabs.netskope.com/reports/2026/cloud-and-threat-report-2026/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2026/cloud-and-threat-report-2026/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations worldwide. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Generative AI</category><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2026/cloud-and-threat-report-2026.png" length="0" type="image/png"/></item><item><title>Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading</title><link>https://threatlabs.netskope.com/blog/2025/11/shai-hulud-2-0-aggressive-automated-one-of-fastest-spreading-npm-supply-chain-attacks-ever-observed/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/11/shai-hulud-2-0-aggressive-automated-one-of-fastest-spreading-npm-supply-chain-attacks-ever-observed/</guid><description>Shai-Hulud 2.0 is an aggressive, automated NPM supply chain attack. Get the full analysis on credential theft, GitHub backdoors, and IOCs.</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>Malware</category><category>Supply Chain</category><category>Credential Theft</category><enclosure url="https://threatlabs.netskope.com/og/2025/11/shai-hulud-2-0-aggressive-automated-one-of-fastest-spreading-npm-supply-chain-attacks-ever-observed.png" length="0" type="image/png"/></item><item><title>The Future of Malware is LLM-powered</title><link>https://threatlabs.netskope.com/blog/2025/11/the-future-of-malware-is-llm-powered/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/11/the-future-of-malware-is-llm-powered/</guid><description>Large language models (LLMs) have rapidly transformed industries, becoming invaluable tools for automation, coding assistance, and research. However, their widespread adoption raises several…</description><pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>AI</category><category>Malware</category><enclosure url="https://threatlabs.netskope.com/og/2025/11/the-future-of-malware-is-llm-powered.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Manufacturing 2025</title><link>https://threatlabs.netskope.com/reports/2025/threat-labs-report-manufacturing-2025/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2025/threat-labs-report-manufacturing-2025/</guid><description>The 2025 Netskope Threat Labs Manufacturing report details the increasing adoption of generative AI, trends in data policy violations, and malware distribution via cloud applications observed over the last year.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><category>Manufacturing</category><enclosure url="https://threatlabs.netskope.com/og/2025/threat-labs-report-manufacturing-2025.png" length="0" type="image/png"/></item><item><title>RedTiger: New Red Teaming Tool in the Wild Targeting Gamers and Discord Accounts</title><link>https://threatlabs.netskope.com/blog/2025/10/redtiger-new-red-teaming-tool-in-the-wild-targeting-gamers-and-discord-accounts/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/10/redtiger-new-red-teaming-tool-in-the-wild-targeting-gamers-and-discord-accounts/</guid><description>Gamers are a hot target for infostealers these days. This blog post is the second we have published this month about an infostealer targeting gamers, with the previous one describing a Pytho…</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate><dc:creator>Jan Michael Alcantara</dc:creator><category>Malware</category><category>Credential Theft</category><enclosure url="https://threatlabs.netskope.com/og/2025/10/redtiger-new-red-teaming-tool-in-the-wild-targeting-gamers-and-discord-accounts.png" length="0" type="image/png"/></item><item><title>New Python RAT Targets Gamers via Minecraft</title><link>https://threatlabs.netskope.com/blog/2025/10/new-python-rat-targets-gamers-via-minecraft/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/10/new-python-rat-targets-gamers-via-minecraft/</guid><description>During threat hunting activities, Netskope discovered a new, multi-function Python RAT that leverages the Telegram Bot API as a command and control (C2) channel, allowing attackers to exfilt…</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate><dc:creator>Nikhil Hegde</dc:creator><category>Cloud</category><enclosure url="https://threatlabs.netskope.com/og/2025/10/new-python-rat-targets-gamers-via-minecraft.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Asia 2025</title><link>https://threatlabs.netskope.com/reports/2025/threat-labs-report-asia-2025/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2025/threat-labs-report-asia-2025/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within the Asia region. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Sun, 19 Oct 2025 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Cloud Security</category><category>Generative AI</category><enclosure url="https://threatlabs.netskope.com/og/2025/threat-labs-report-asia-2025.png" length="0" type="image/png"/></item><item><title>Securing LLM Superpowers: The Invisible Backdoors in MCP</title><link>https://threatlabs.netskope.com/blog/2025/09/securing-llm-superpowers-the-invisible-backdoors-in-mcp/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/09/securing-llm-superpowers-the-invisible-backdoors-in-mcp/</guid><description>In the first two parts (1, 2) of this series, we broke down how the Model Context Protocol (MCP) works and explored attacks like tool poisoning and cross-server tool shadowing.


In this pos…</description><pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2025/09/securing-llm-superpowers-the-invisible-backdoors-in-mcp.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Retail 2025</title><link>https://threatlabs.netskope.com/reports/2025/threat-labs-report-retail-2025/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2025/threat-labs-report-retail-2025/</guid><description>This report analyzes the primary cybersecurity risk trends impacting organizations within the Retail sector. It addresses the increasing adoption of generative AI (genAI) tools and their associated data security challenges. Furthermore, it highlights the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and genAI platforms.</description><pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><category>Retail &amp; Hospitality</category><enclosure url="https://threatlabs.netskope.com/og/2025/threat-labs-report-retail-2025.png" length="0" type="image/png"/></item><item><title>Securing LLM Superpowers: When Tools Turn Hostile in MCP</title><link>https://threatlabs.netskope.com/blog/2025/09/securing-llm-superpowers-when-tools-turn-hostile-in-mcp/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/09/securing-llm-superpowers-when-tools-turn-hostile-in-mcp/</guid><description>In Part 1 of this blog series, we explored the architecture, capabilities, and risks of the Model Context Protocol (MCP). In this post, we will focus on two attack vectors in the MCP ecosyst…</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2025/09/securing-llm-superpowers-when-tools-turn-hostile-in-mcp.png" length="0" type="image/png"/></item><item><title>DNS Tunneling: The Blind Spot in Your Network Security Strategy</title><link>https://threatlabs.netskope.com/blog/2025/08/dns-tunneling-the-blind-spot-in-your-network-security-strategy/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/08/dns-tunneling-the-blind-spot-in-your-network-security-strategy/</guid><description>The Domain Name System (DNS) is a critical component of internet infrastructure, responsible for translating human-readable domain names into IP addresses. However, the ubiquitous nature and…</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><dc:creator>Hubert Lin</dc:creator><category>Malware</category><enclosure url="https://threatlabs.netskope.com/og/2025/08/dns-tunneling-the-blind-spot-in-your-network-security-strategy.png" length="0" type="image/png"/></item><item><title>Netskope Threat Labs Report: Australia 2025</title><link>https://threatlabs.netskope.com/reports/2025/threat-labs-report-australia-2025/</link><guid isPermaLink="true">https://threatlabs.netskope.com/reports/2025/threat-labs-report-australia-2025/</guid><description>This report examines the major cybersecurity risk trends affecting organizations across Australia. It covers the growing adoption of genAI tools and the data security challenges that accompany them, as well as the rising data policy violations involving sensitive data that is increasingly leaked through unapproved cloud services, personal apps, and genAI platforms. Additionally, it highlights the rise of phishing and the distribution of malware via cloud applications.</description><pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate><dc:creator>Netskope Threat Labs</dc:creator><category>Threat Protection</category><enclosure url="https://threatlabs.netskope.com/og/2025/threat-labs-report-australia-2025.png" length="0" type="image/png"/></item><item><title>Securing LLM Superpowers: Navigating the Wild West of MCP</title><link>https://threatlabs.netskope.com/blog/2025/08/securing-llm-superpowers-navigating-the-wild-west-of-mcp/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/08/securing-llm-superpowers-navigating-the-wild-west-of-mcp/</guid><description>The Model Context Protocol (MCP) is a standardized framework that enables large language models (LLMs) to interact with external tools, APIs, and data sources. While MCP offers powerful inte…</description><pubDate>Wed, 13 Aug 2025 00:00:00 GMT</pubDate><dc:creator>Gianpietro Cutolo</dc:creator><category>Malware</category><category>AI</category><category>Supply Chain</category><enclosure url="https://threatlabs.netskope.com/og/2025/08/securing-llm-superpowers-navigating-the-wild-west-of-mcp.png" length="0" type="image/png"/></item><item><title>Netskope BEAM: Open Source Detector for Supply Chain Compromise</title><link>https://threatlabs.netskope.com/blog/2025/08/netskope-beam-open-source-detector-for-supply-chain-compromise/</link><guid isPermaLink="true">https://threatlabs.netskope.com/blog/2025/08/netskope-beam-open-source-detector-for-supply-chain-compromise/</guid><description>Netskope Threat Labs is pleased to announce the release of a new open-source tool that detects supply chain attacks. Our new tool, Behavioral Evaluation of Application Metrics (BEAM), requires no endp…</description><pubDate>Thu, 07 Aug 2025 00:00:00 GMT</pubDate><dc:creator>Colin Estep</dc:creator><category>AI</category><enclosure url="https://threatlabs.netskope.com/og/2025/08/netskope-beam-open-source-detector-for-supply-chain-compromise.png" length="0" type="image/png"/></item></channel></rss>