CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026

2026-03-19T20:51:51Zc3bcc44d5105aa9d5f7d9efd4e7c2201073e0b3a782a48cb3bc54efa6a896802
claude-aiclaudy-dayclickfix-scamcode-obfuscationcredential-theftdetection-evasiondeveloper-toolsdotnet-aotfake-google-adsfake-vpn-siteshyrax-infostealeride-extensionmacsyncnon-human-identity-theftphishingsolana-blockchain-exfiltrationspycloud-reportstorm-2561supply-chainwindsurf-ide

What happened

Multiple active campaigns and research findings highlight a trend of targeted developer- and AI-tool-focused credential theft and stealthy info‑stealers. Key items: a malicious Windsurf IDE extension using the Solana blockchain to exfiltrate developer credentials (Bitdefender); “Claudy Day” flaws enabling data theft via fake Google Ads and malicious Claude AI ads; ClickFix campaigns (Windows and macOS) that trick users into mapping attacker-controlled drives and deploy MacSync or other malware via fake Claude tools and ads; Storm-2561 using fake Fortinet/ Ivanti VPN sites to deliver Hyrax infi

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
c3bcc44d5105aa9d5f7d9efd4e7c2201073e0b3a782a48cb3bc54efa6a896802
Enrichment time
2026-03-19T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.