Archive for the Commentary Category

FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology

Posted in Commentary with tags on July 21, 2026 by itnerd

FusionAuth today announced the appointment of Jamey Miller to SVP of Engineering and Technology. He will be responsible for scaling engineering to support the company’s accelerated growth and increasing enterprise adoption, maintaining product quality and platform reliability, and positioning engineering for AI.

Miller has more than 25 years of experience scaling global SaaS R&D organizations across product, engineering, security, IT, and support, with deep experience in both cloud and self-hosted/on-premises deployment models. He has a proven track record of leading R&D in PE-backed and high-growth environments, including periods of rapid scaling, M&A integration, and operational transformation.

Most recently, Miller served as Chief Product & Technology Officer at global enterprise SaaS company Confience, where he improved delivery predictability and platform security while integrating the acquisition of Brazilian software firm LabSoft. Earlier, as EVP of R&D and Operations at Convercent, he helped guide the company to its acquisition by OneTrust, then went on to serve as VP of R&D Operations there, driving scale and cost efficiencies across a 400-person R&D organization.

Miller holds an MBA from the University of Portland, a M.S. in Marketing from the University of Colorado and a Bachelor of Science in Business Administration from Colorado State University. 

Leaseweb Acquires ITQ’s VMware VCSP Customer Base 

Posted in Commentary with tags on July 21, 2026 by itnerd

Leaseweb, a leading cloud services and Infrastructure as a Service (IaaS) provider, has announced the acquisition of the Broadcom VMware white label VCSP customer base of ITQ, a leading European Broadcom IT Services company. The move follows the recently announced strategic partnership between the two companies, under which ITQ selected Leaseweb as its infrastructure partner for VMware Cloud Foundation (VCF) services for its VCSP partners, in a significant expansion of Leaseweb’s VCF platform across Europe.

As part of the acquisition, 51 VCSP customers will transition to Leaseweb’s VCF platform, collectively accounting for approximately 35,000 cores. This brings Leaseweb’s core count to 65,000, positioning it as the largest VMware Pinnacle Partner in the Netherlands and reinforcing its position within the Broadcom partner ecosystem.

The acquired white label VCSP partners, previously operating under the Broadcom VMware Advantage Partner program, will be able to continue to market their proposition under Leaseweb’s Broadcom VMware VCSP Pinnacle Partner status. As an Authorized Pinnacle VCSP, Leaseweb transacts directly with Broadcom, providing these partners with a fully authorized and long-term platform for their VMware businesses. Partners will also continue to have access to ITQ’s VMware expertise as part of the ongoing partnership between the two organizations.

In addition to the acquired customer base, Leaseweb and ITQ are actively engaging with global non-renewing Broadcom VMware VCSP partners, offering a supported path forward for their VMware businesses under Leaseweb’s Pinnacle Partner infrastructure. Under the partnership, Leaseweb will act as provider for VMware VCF 9.x infrastructure, with ITQ serving as knowledge partner, bringing industry-leading VMware advisory and implementation expertise to support customers through migration and deployment

For more information, please visit: www.leaseweb.com

Liquibase Expands Global Partner Ecosystem

Posted in Commentary with tags on July 21, 2026 by itnerd

Liquibase today announced a major expansion of its global partner ecosystem and the appointment of Phil Robinson as Vice President of Global Channels and Alliances. The move builds on strong momentum for Liquibase Secure and growing enterprise demand for governed database change as AI, modernization, security, and compliance reshape software delivery.

Robinson brings more than two decades of channel, alliance, and enterprise open-source experience to Liquibase. Most recently, he served as Vice President of Global Channels at Digital.ai, where he helped redesign and relaunch the company’s channel program globally. Before that, he spent more than eight years at Atlassian, where he built and scaled global alliance programs with GSIs and Federal SIs, including Accenture, Deloitte, PwC, and Capgemini. His experience also includes leadership roles at Magento, Alfresco, and Hewlett Packard Enterprise across open source, cloud, systems integration, and enterprise software.

Trusted by 20 of the Fortune 100 and supported by a global community with more than 100 million downloads, Liquibase is investing in partners to help enterprises close the database delivery gap and build new services around Database Change Governance.

Robinson will lead Liquibase’s global partner strategy across partner recruitment, enablement, joint marketing, and partner-led services around Database Change Governance, while deepening the company’s engagement with cloud marketplaces and government partners.

AI is exposing the database delivery gap

Modern application and data delivery has accelerated in waves. Agile increased release velocity. Cloud spread applications, databases, and data platforms across more teams, tools, and environments. Enterprises responded by investing in CI/CD, automated testing, infrastructure-as-code, and security controls. But database change often remained governed through tickets, manual reviews, disconnected scripts, and processes that varied across teams, tools, and database platforms.

That disconnect has made the database one of the last major constraints on modern application and data delivery. Application code, infrastructure, and security increasingly move together, while database change is still treated as a separate process in many organizations. The result is fragmented governance, slower releases, and limited visibility into what changed, who approved it, and whether it is safe to deploy.

AI is not creating the database delivery gap. It is exposing it. As AI assistants and agents generate more software, they also increase the volume and speed of database change flowing through delivery systems that were never designed to operate at that scale. The challenge is no longer simply automating deployments. It is keeping database change synchronized with application code, infrastructure, and security before it reaches production.

The governance gap is widening. According to Liquibase’s 2026 State of Database Change Governance Report, 96% of organizations now have AI interacting with production databases, and 70% ship database changes weekly or faster. Yet only 28% enforce governance through automated controls and evidence, while 39% say they cannot reliably track what changed where.

For partners, this represents a significant opportunity to help customers modernize database delivery, govern AI-assisted development, strengthen compliance, reduce production risk, and bring database change into the same DevSecOps practices already established for application code. As enterprises look to scale AI safely, they need partners who can help modernize the processes that AI is exposing as bottlenecks.

Database Change Governance provides the control plane that keeps database change synchronized with application code, infrastructure, and security across the software delivery lifecycle. Liquibase Secure operationalizes that control plane across development teams, CI/CD pipelines, AI agents, and more than 65 database platforms, enabling enterprises to accelerate software delivery without sacrificing governance.

Why this is a partner opportunity now

For partners, this shift is a chance to become indispensable to their most complex customers. As database change outruns the ability to govern it, enterprises need a partner who can restore control at the exact point where developer velocity, compliance, and AI readiness collide. Liquibase provides an opportunity for partners to turn that challenge into a repeatable practice spanning advisory, implementation and managed services, reaching every environment a customer runs, from mainframe to cloud to lakehouse.

At the center of the opportunity is Liquibase Secure, which helps enterprises automate, secure, and govern database change across complex environments. With policy checks to deliver standardized change, advanced drift detection, structured audit trails, always-on evidence gathering, and more, Liquibase Secure gives developers, platform teams, security leaders, and compliance teams a governed path for every database change.

Liquibase already works with a robust group of consulting, cloud, public sector, and technology partners. Under Robinson’s leadership, the company plans to expand partner coverage both geographically and into specific industry sectors, creating clear paths for partners to build solutions and deliver Liquibase Secure, Database

Organizations interested in joining the Liquibase partner ecosystem can learn more at liquibase.com/partners.

Cascade raises $3.5M to help construction firms predict the future and win more projects

Posted in Commentary with tags on July 21, 2026 by itnerd

In construction, the most expensive projects are the ones a firm never sees. Somewhere right now, a bond has been filed, a site has changed hands, and the winner of a nine-figure project is already being decided, months before an RFP exists. Cascade, the AI pursuit platform for architecture, engineering and construction (AEC) firms, is changing that. Today, the company announced it has raised $3.5 million from Andreessen Horowitz Speedrun, Ada Ventures, Blitzscaling Ventures, Indico Capital, shuckerVC, G2C Ventures and Snowball VC.

The traction has come fast. In a few months, Cascade has signed AEC customers whose work spans some of the world’s most notorious projects – including JFK, LaGuardia, data centers and nuclear reactors. 

The signs arrive years before the bid

Long before an RFP, a multi million dollar project leaves traces. A bond filing is a project taking shape. A property changing hands is a developer moving. A line in a county capital plan is a building that does not exist yet, and a firm somewhere is going to win it. Cascade detects these events continuously across bond filings, permits, capital plans, property transactions, earnings transcripts, budget announcements and meeting minutes, and connects them to what they signal: where work is forming, what kind, and who is positioned to win it.

The tools the industry relies on read none of this. 

Cascade closes the gap. It anticipates projects as they form, scores each one for fit so firms pursue the work they are most likely to win, and surfaces warm paths in through relationships already sitting in Outlook and other software. Every customer makes the system sharper: each pursuit teaches it which signals matter, which firms are credible for which work, and where teaming opportunities exist.

Built by Amazon and Google operators, pulled in by the market

Cascade was founded by Hannia Zia and Joana Ferreira, two former Google operators who met at UnlikelyAI, the startup founded by the inventor of Amazon Alexa. There, Hannia served as VP of Product and Joana led the AI platform, building a knowledge graph of the world’s information and training LLM agents to navigate it.

Their route into construction was personal as much as commercial. Joana grew up in a Portuguese town built on construction and carpentry. Hannia’s father tried to start a construction business, but it failed. Hannia’s conversations with CFOs in New York produced Cascade’s first customer, Munoz Engineering, and a conference in Denver quickly brought the next. 

The funding will accelerate adoption and deepen Cascade’s network across the industry. Even building a house takes twenty companies coming together, and multimillion-dollar projects take an order of magnitude more. As more firms join, Cascade matches them to each other: partners to bid with, connections in new regions, teaming opportunities across the US. The platform gets stronger with every firm that joins, and so does every firm on it.

The team’s overall ambition runs the full arc of a project. Cascade intends to be there at the first trace of work forming, through the pursuit, the win and the build, until the day of handoff.

Teleport Establishes Agent Trust with New Identity Security Capabilities

Posted in Commentary with tags on July 21, 2026 by itnerd

Teleport today announced that it has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. Together, these capabilities give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure.

The announcement follows Teleport’s recent white paper, From Zero Trust to Agent Trust, which argues that zero trust is necessary but insufficient to govern agents operating at scale. The paper extends the three core principles of zero trust into three corresponding principles of agent trust:

  • Verify explicitly → Enforce continuously.
    Agents need a unique, attestable identity and must operate inside a trusted runtime that architecturally enforces their operational, execution, and communication boundaries.
  • Use least privileged access → Bound collective autonomy.
    Individually authorized actions can still be collectively destructive when taken by a swarm of agents acting in parallel. Bounding collective autonomy means actions that are safe individually but risky in aggregate require escalation before they execute.
  • Assume breach → Assume misalignment.
    Agents can drift from their original objective through adversarial manipulation or through unintentional causes, like context shift over time. Enterprises must continuously monitor for that drift and be able to intervene in real time. Teleport’s new capabilities are delivered through Beams, Teleport’s trusted runtime for agents, working in concert with its Identity Security platform, now extended to address agentic behavior:
  • Beams Session Summaries are a summary of an AI agent’s actions: its identity, privileges, tool and API calls, LLM prompts, responses, and reasoning digested into a short human readable summary of what it was doing and what it was thinking. This establishes a behavioral baseline for evaluating agent activity against its declared objective.
  • Agentic Classifiers provide policy for humans, agents or groups of agents to be evaluated against company specific criteria, enabling agent behavior to be flagged that is inconsistent with an agent’s declared objective.
  • Risk Scoring automatically summarizes SSH, Kubernetes, and database sessions, classifies them by risk level and maps actions to the MITRE ATT&CK framework. Infrastructure and Security teams can now automate or manually search across sessions for specific commands, resources, or behaviors.
    Together, these three capabilities in concert with Beams lay the foundation for the agent trust principles: they give agents a cryptographic, continuously monitored identity; they make collective and individual risk visible before action is taken; and they give enterprises the tooling to detect and respond to misalignment as it happens, turning “assume misalignment” from a design principle into a running practice.

Availability

Teleport will preview these capabilities at Black Hat USA 2026 (August 4–6, Mandalay Bay, Las Vegas) at booth #5114. The capabilities will be available for hands-on customer experience this fall. Customers can request to join the technology preview here.

For a deeper discussion on the new Identity Security capabilities, read the blog.

Deepgram Delivers Real-Time Voice AI at the Edge for Use with Snapdragon

Posted in Commentary with tags on July 21, 2026 by itnerd

Deepgram today announced an initiative to bring enterprise-grade speech recognition directly onto PCs powered by Snapdragon® processors. By optimizing Deepgram’s Nova-3 speech-to-text model on the Qualcomm® Hexagon™ NPU in the Snapdragon X Series platform, Deepgram is enabling developers and device manufacturers to deliver real-time voice experiences with greater speed, privacy, and reliability, without relying on a cloud connection. This effort opens the door to further integration of voice into a new generation of intelligent applications across automotive, mobile, AI PC, XR, industrial edge, IoT, and wearable devices.

Many voice AI solutions have historically relied on a cloud-based architecture. Before a response could be delivered, each interaction required audio to leave the device, travel to the cloud, be processed somewhere else, and then return. With this approach, delays and privacy concerns are sometimes introduced, which limit where voice AI can realistically be deployed. Deepgram is fundamentally changing that model, enabling speech recognition to happen directly on the device itself. The result is an entirely new world of applications and user experiences that feel like a natural conversation, whether it is running in a vehicle, on an AI PC, inside an XR headset, or at the edge of a network where connectivity cannot be guaranteed.

Nova-3 advances Deepgram’s industry-leading accuracy, extending its capabilities to a broader range of real-world enterprise use cases and challenging audio conditions. It is the first voice AI model to offer real-time multilingual transcription. Deepgram is also the first to provide users with demonstrably effective and highly accurate self-serve customization – enabling instant vocabulary adaptation without model retraining. Superior accuracy: Nova-3 leads transcription accuracy with a 6.89% word error rate on real-world production audio, a 24.7% lower error rate than the next-best competitor.

To learn more, please visit: https://deepgram.com/partners/qualcomm.

Did BTS star j-hope just give fans a first look at Samsung’s next foldable?

Posted in Commentary with tags on July 21, 2026 by itnerd

Samsung has already confirmed that new Galaxy devices are on the way later this week. But some BTS fans think they might have spotted one in the wild already.

Videos from a BTS sound check in Paris are fueling speculation, as j-hope is seen using what appears to be an unreleased Samsung smartphone. Samsung hasn’t confirmed any product details, but that hasn’t stopped tech enthusiasts from dissecting the device’s size and shape, wondering whether the clips offer a first look at what’s coming next.

If you haven’t seen the videos yet, you can check them out here and here.

Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly

Posted in Commentary with tags on July 21, 2026 by itnerd

Black Kite today released its newest report, 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record, examining how ransomware is evolving, who is being targeted, and the externally visible risk signals organizations exhibited before they became publicly disclosed ransomware victims.

Black Kite identified 7,551 publicly disclosed ransomware victims between April 1, 2025 and March 31, 2026, up 24.9% over the previous reporting period. But the annual figure hides a sharper trend: after tracking close to the prior year’s pace through the first half of the reporting period, ransomware victim counts accelerated 60% in the second half, closing with 861 victims in March 2026 – the highest monthly total in four years.

The report identified three key trends that defined this year’s ransomware landscape:

  • Expansion at the bottom: More than 60 new groups entered during the reporting period, more than one per week, bringing the total to 146 active groups by June 2026.
  • Concentration at the top: Despite the influx of new entrants, the five largest actors still controlled 43.6% of all victims. Qilin alone claimed 1,300+ victims, nearly twice as many as its nearest rival.
  • Acceleration in the second half: While the first half tracked close to the prior year baseline, the second half outpaced it by 60%, closing with 861 victims in March 2026, the highest monthly total in four years of tracking.

Many of the year’s most consequential attacks moved through trusted vendor platforms, including SaaS integrations, enterprise applications, OAuth connections, and support workflows.

Black Kite’s before-and-after security posture comparison also found that exposure often remained after incidents were disclosed: stealer log exposure increased 175%, while 43.5% of victims still carried critical vulnerabilities in the latest assessment.

The report concludes that AI did not redefine ransomware during the reporting period. Instead, it lowered the cost of the work around the attack by making reconnaissance faster, phishing and vishing more convincing, victim research more scalable, scripts cleaner, translation easier, and extortion messaging cheaper to produce. While AI did not create this year’s acceleration, it lowered the barrier to entry enough that more actors could participate, suggesting ransomware operations could be scaling in anticipation of what comes next: AI-accelerated vulnerability discovery, faster exploitation cycles, and social engineering at scale.

Key findings from the report:

  • 7,551 publicly disclosed ransomware victims identified, up 24.9% year over year.
  • 60% acceleration in ransomware activity during the second half of the reporting period.
  • 146 active groups by June 2026, including 61 new groups entering during the reporting period.
  • Qilin claimed more than 1,300 victims, nearly two-times as many as its nearest rival.
  • 43.5% of victims still carried critical patch vulnerabilities in the latest assessment, 30.8% carried KEV exposure, and 18.5% carried FocusTag® signals.
  • 175% higher stealer log exposure in the before and after security posture comparison.
  • Oracle E-Business Suite (EBS) and Salesforce ecosystem integrations defined several of the year’s most visible supply chain incidents.

The report recommends prioritizing vulnerabilities known to be exploited in the wild, extending third-party cyber risk management beyond questionnaire-based assessments, and hardening the human layer against vishing and help desk impersonation. The report also recommends strengthening identity verification, help desk escalation paths, employee reporting, vendor verification, and executive impersonation controls.

To read the report, visit https://blackkite.com/reports/2026-ransomware-report/.

To learn how Black Kite’s Ransomware Susceptibility Index (RSI™) provides early warning of ransomware risk and helps organizations proactively identify susceptible third parties, visit https://blackkite.com/platform/ransomware-susceptibility-index

Methodology

The report covers the period from April 1, 2025 through March 31, 2026. The primary dataset includes 7,551 publicly disclosed ransomware victims identified through leak site monitoring and validated by the Black Kite Research Group™. Before and after security postures, current state exposure analysis, and post-period April-June 2026 activity are treated as separate scopes. Post-period data is used as supplementary context and excluded from primary year over year calculations.

Hugging Face Breached by Autonomous AI Agent

Posted in Commentary with tags on July 20, 2026 by itnerd

Open-source AI and machine learning platform Hugging Face said it detected and responded to an intrusion into part of its production infrastructure. They said it was different from anything they had previously handled in that it was driven end to end, by an autonomous AI agent system that accessed to a limited set of internal datasets and to several credentials used by their services,

Hugging Face has posted details here: https://huggingface.co/blog/security-incident-july-2026

Rohit Valia, CEO of cybersecurity company Tumeryk, provided the following comments: 

“Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”

If you use Hugging Face, you might want to see if you are at risk. And you might want to do it sooner rather than later.

UPDATE: Two more comments came in staring with Gidi Cohen, CEO & Co-Founder, Bonfy.AI:

“This incident should be a wake-up call, not because AI was involved, but because it shows how fast AI-native attacks are outpacing security programs.

An autonomous agent didn’t use fancy tricks, it just exploited familiar gaps in the system like code execution paths, credentials, and lateral movement. The difference is speed. Thousands of coordinated actions across short-lived environments shrank the response window from days to hours.

The bigger issue is defense. Hugging Face found its own response constrained by model guardrails. This s a new imbalance we see everywhere: the attacker operates without limits, while defenders (security personnel or security platforms) rely on tools that can refuse to help. If your company’s response tech stack isn’t fully under your control, your security posture isn’t either.

From this case, we have three takeaways for leaders: 1) “Data as code” is now a real attack surface. 2) Speed is the new risk multiplier. 3) You need internal, controllable AI for incident response, not just external APIs.

Security is shifting from hardening systems to operating at the speed of agents with tools you own. Organizations that plan for both sides of AI (attacker and defender) will set a new baseline for resilience.”

Toghrul Tahirov, Head of AI Governance,  Polygraf AI

“What stands out to me in this Hugging Face incident is that the attack reportedly began with something organizations routinely trust: data entering an AI processing pipeline. Once AI agents can execute code and access infrastructure, a malicious dataset is no longer just bad content. It can become an entry point for credential theft and lateral movement. This is a reminder that AI systems must be treated as privileged software, not as just a smarter generation of the chatbots we’re used to.

My professional opinion is that secure AI adoption requires controls around the entire interaction: inspect untrusted data, isolate execution, minimize permissions, use short-lived credentials, restrict network access, and maintain clear audit trails. Organizations also need incident-response tools they can operate privately without exposing sensitive evidence. The answer is not to avoid AI agents, but to ensure governance and security ar

UPDATE #2: More commentary starting with John Strand, Owner, Black Hills Information Security, Inc.

“There are plenty of jokes to be made about autonomous AI agents attacking a website that hosts autonomous AI agents, but that’s not the part that concerns me. What caught my attention was the claim that everything had been verified as clean despite hosting more than 45,000 models. At that scale, what does ‘verified clean’ really mean? Validating tens of thousands of models is an enormous challenge. That’s the reality we’re going to keep running into with software supply chain attacks. Whether it’s Hugging Face or any other platform hosting code that developers depend on, proving that everything is truly clean is only going to get harder as these ecosystems continue to grow.” 

Donald McFarlane, Advisory Board Member, Xcape, Inc. 

“This incident underscores how AI is changing the economics of cyber offense. AI-enabled tools allow attackers to automate reconnaissance, accelerate exploitation, and operate at machine speed. Just as leaders who eschewed advances such as longbows, RADAR, or drones have repeatedly found themselves facing defeat, defenders cannot afford to ignore AI. We must leverage AI to modernize cyber defense so as to increase attackers’ costs while reducing defenders’ workload. Meanwhile, organizations continue to need strong identity controls, segmentation, containment and resilience. 

“Although Hugging Face reports no evidence that public models or the software supply chain were modified, incidents like this highlight the importance of protecting not only infrastructure, but also the credentials, private repositories, datasets, and deployment pipelines that support modern AI development.” 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs

“Dataset processing pipelines get the same level of security scrutiny that CI/CD hooks and build functions get, which is almost none. Teams pour AppSec effort into the application layer and treat the infrastructure that ingests and transforms data as plumbing. The attacker exploited a remote code loader and a template injection in that plumbing, then let an autonomous agent framework chain them across 17,000 actions in a weekend. 

“A human attacker running that campaign needs a team and weeks. The agent framework did it with short-lived sandboxes and command-and-control staged on public services. Keeping pace requires AI-assisted incident response, and Hugging Face found out what happens when you reach for it mid-breach. 

“Hugging Face’s team fed attack logs to commercial frontier models, and safety filters blocked the analysis because the logs contained real exploit payloads. They ran GLM 5.2, an open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Opus 4.6 for security work and haven’t upgraded because newer models’ guardrails increasingly block legitimate analysis of exploit code and attack artifacts. 

“Machine-speed exploitation requires machine-speed response, and that response can’t run on models that refuse to examine the evidence.” 

Waseem Ahmed, Head of Engineering, Secure.com:

   “For years we talked about the agentic attacker as a someday problem. Hugging Face just made it today’s problem. One agent, no human at the keyboard, credentials stolen and infrastructure crossed in a single weekend.

   “The response is as telling as the attack. Hugging Face used AI to reconstruct the full attacker timeline in hours rather than days — processing thousands of events that would have taken a human team far longer to sequence. AI ran the attack. AI ran the investigation. That is the new baseline.

   “The part that should concern every security team: you cannot out-click an attacker operating at machine speed across 45,000 models and 50,000 customer environments. The only viable answer is defence that runs at the same speed and never clocks out — AI that watches, triages, and acts alongside your team every hour of every day.

   “Fight autonomous attacks with autonomous defence, or you will always be a step behind.”

DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs

Posted in Commentary with tags on July 20, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) published an in-depth analysis of the latest ClickFake interview campaign, a North Korean social engineering operation targeting cryptocurrency and Web3 professionals with fake job interviews. 

In this campaign, operators pose as recruiters to walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. 

Key points include: 

  • Famous Chollima (aka Wagemole) is a North Korean-aligned threat actor that has been highly active through the Contagious Interview and the latest ClickFake Interview campaigns.
  • For ClickFake Interview the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix empowered fake skill assessments.
  • Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors.
  • The final payloads target both Windows, by deploying PylangGhost RAT, and macOS, by deploying GolangGhost RAT alongside a credential-harvesting SwiftUI application.
  • PylangGhost and GolangGhost consist of six interconnected modules: a main orchestrator, a configuration holder, an archive helper, a command launcher, a C2 component, and a stealer.
  • Both payload chains download the runtimes needed to run in victim environments: Python’s interpreter for PylangGhost and Golang’s compiler for GolangGhost.
  • In the latest variation of PylangGhost, the attackers also compiled their payloads as Python dynamic modules with Nuitka to further complicate detection and analysis.
  • Famous Chollima actors register multiple domains for their fake skill assessments, predominantly on Hostinger and NameCheap registrars, emphasizing speed and scale, rather than operational security and infrastructure resilience.

For full details, this study can be read here: https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/