
infostealer
38
MENTIONS
24
EPISODES
22
PODCASTS
Search complete. 38 mentions across 24 episodes found for "infostealer".
Sep 18, 2026
One Hacker, 42 Targets: Inside Anthropic's AI Threat Report | Ep 196
S
17:41Spencer AlessiHOST
So that's a big area of risk for organizations who do development or even just vibe coding, making sure that those repos are protected and locked down and that you scan those repos for secrets, like super important.
S
17:55Spencer AlessiHOST
But then also, this to me, I think we're going to see probably a lot more AI credentials in InfoStealer leaks and logs, because a lot of people are using AI and LLMs and ChatGPT and Codex and VS Code and Claude and all that.
S
18:12Spencer AlessiHOST
So if those machines get compromised, you know, potentially being able to steal AI credentials from those machines, personal computers, and then that could potentially lead to, you know, corporate access or access to environments and things like that, just like they have in the past for other credentials, like SaaS apps and stuff.
S
18:30Spencer AlessiHOST
So that to me is a big one that's not a surprise, but it's something to be mindful of.
Malware vs. Virus: What's Actually Attacking Your Machine
H
3:27Herman PoppleberryHOST
Modern attackers would rather deliver a Trojan once to a targeted machine than have a virus spreading wildly and triggering every antivirus engine on the planet.
H
3:37Herman PoppleberryHOST
The shift from viruses to trojans and infostealers is the shift from spread as far as possible to get in quietly and monetize.
C
3:45CornHOST
So let's talk about what's actually out there across operating systems.
C
3:50CornHOST
Daniel asked about variants on every OS.
H
8:33Herman PoppleberryHOST
So that's
C
8:34CornHOST
the landscape.
C
8:35CornHOST
Windows as the big target, macOS infostealers on the rise, Android vulnerable through sideloading, iOS locked down but not immune.
C
8:44CornHOST
Now Daniel's bigger question, is malware still a major exploit, or has phishing taken over?
Hackers Stealing Anthropic AI Claude Tokens - Vibe Coders are Cooked
E
20:08EliHOST
Well, they warned them their tokens were being stolen.
E
20:10EliHOST
Quote, we have recently become aware of a bad actor that is using common InfoStealer malware to steal Claude login sessions from people's computers, then using these login sessions to access Claude accounts and consume their usage.
E
20:22EliHOST
The email read, InfoStealers are a type of malware, blah, blah, blah.
E
20:26EliHOST
When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warn them that they may have malware.
E
20:35EliHOST
The Swartz quad account was reinstated after about two weeks.
GTIG From Prompting to Autonomy: Inside the Industrialization of Adversarial AI
S
47:33speaker_1HOST
Yeah.
S
47:33speaker_1HOST
A threat actor finds an exposed GitHub personal access token or uses an InfoStealer to grab a cloud API key from a developer's hidden config file.
S
47:42speaker_1HOST
They use that access to quietly infiltrate an organization's Amazon Web Services or Google Cloud environment.
S
47:48speaker_0HOST
So they are inside the corporate cloud.
Hunting software supply chain malware
J
65:23James WilsonHOST
When that thing starts, as you said, when it starts encrypting a bunch of files and doing that stuff, cool, catch that.
J
65:30James WilsonHOST
But we're talking about InfoStealers here that are looking, feeling, and acting like legitimate JavaScript that's executing, legitimate package installs and scripts, right? It's very difficult to even think about how you would apply the same heuristics and models in an EDR sense.
P
65:49Paul McCartyGUEST
even when you do have persistence, when you actually, when you've been unlucky enough to get out of cookie version five or invisible ferret, and you've got persistence on your machine, that process is just a node process.
P
66:01Paul McCartyGUEST
It's just a Python process and you're a developer probably.
153 Million Driver's Licenses Are for Sale
C
18:51Chris TarbellHOST
But I mean, not shocking, but yeah, horrible news.
C
18:55Chris TarbellHOST
So Anthropic warns InfoStealer malware is hijacking cloud sessions to drain usage.
C
19:00Chris TarbellHOST
So Anthropic is emailing some cloud users that commodity InfoStealers stole already authenticated cloud browser sessions from infected PCs and then relayed those sessions to burn through cloud.
C
19:13Chris TarbellHOST
included usage, and in some cases, build credit.
C
19:17Chris TarbellHOST
No password or 2FA prompt is required on the relay.
Cyber Security News for September 10 2026 - Daily DefSec Brief
J
2:36Jerry BellHOST
Alert on OAuth redirects pointing anywhere but Microsoft.
J
2:39Jerry BellHOST
Eight, InfoStealers are lifting session tokens and API keys for the model providers alongside passwords, and those tokens replay so the second factor never applies.
J
2:50Jerry BellHOST
Treat a Stealer hit as a reason to revoke AI provider sessions and rotate those keys.
J
2:55Jerry BellHOST
9.
07-Sep-2026 N-able, MikroTik and OpenAI Face Escalating Cyber Threats
S
2:51speaker_0NARRATOR
The tactic matters because it shows how simple text obfuscation can bypass keyword-based defenses, forcing organizations to normalize hidden characters and rely on broader detection signals.
S
3:05speaker_0NARRATOR
And finally, for today, Security researchers have identified four previously unreported RevStealer-linked modules that remain on infected Windows systems even after the main InfoStealer deletes itself, extending the threat beyond the initial theft of credentials and crypto assets.
S
3:25speaker_0NARRATOR
One module disables Windows Update and Microsoft Defender before launching a cryptocurrency miner, while others steal wallet data, hijack clipboard crypto addresses, or turn victims' machines into reverse proxies for attacker traffic.
S
3:42speaker_0NARRATOR
The findings matter because the malware can look removed while persistence, defense evasion, and financial abuse continue in the background.
Mainframe Chips, Rogue AI Agents, and Self-Reviewing Code
C
6:26CyrusHOST
But it's, again, a case of identity theft.
C
6:32CyrusHOST
Hudson Rock found InfoStealer linked Microsoft credentials associated with several organizations in the campaign and considers stolen credentials a likelihood.
C
6:40CyrusHOST
So again, a different independent organization kind of corroborates that information.
C
6:47CyrusHOST
So Azure becomes the place where the attacker enters after obtaining a trusted identity.
TikTok introduces voice comments and simplified polls
I
2:17Imran ShaikhHOST
That's according to an email the company sent to affected users last week, which has since been shared publicly on Reddit.
I
2:24Imran ShaikhHOST
As reported by Security Week, the AI giant points to customers' own computers rather than any breach at Anthropic, telling affected users that InfoStealer malware had harvested active-clawed login sessions from their own PCs.
I
2:39Imran ShaikhHOST
Once inside affected accounts, attackers could burn through usage limits and made unauthorized Claude charges.
I
2:45Imran ShaikhHOST
If your usage limits look like they refilled and then drained while you weren't using Claude, this was likely the cause, the email reads.
14 more episodes mention infostealer.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.