Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

WhatsApp API Loophole Exposes 3.5 Billion Accounts to Mass Scraping
Researchers have disclosed a significant flaw in WhatsApp’s contact discovery mechanism that allowed the massive enumeration of over 3.5 billion active accounts, enabling the harvesting of profile metadata on a global scale. While message content remained encrypted, this unrestricted scraping vector highlights critical risks in the exposure of user data via standard APIs.
Key takeaways:
🔓 The Vulnerability: A lack of sufficient rate limiting in the contact discovery API allowed researchers to query up to 100 million phone numbers per hour, verifying active accounts without triggering blocks.
📸 Data Exposed: The “enumeration” attack successfully harvested public profile images for 57% of users and “About” text for 29%, allowing for the creation of massive, verified datasets linking faces to phone numbers.
⚠️ The Risk: While end-to-end encryption protects actual messages, this metadata is a goldmine for threat actors, facilitating targeted smishing (SMS phishing) campaigns and identity linking.
🛡️ Mitigation Status: Meta has acknowledged the findings and reportedly implemented stricter rate limiting and anti-scraping measures to mitigate this specific enumeration technique.
Grafana Enterprise Flaw Allows Full Admin Takeover
Grafana Labs has issued a warning for a maximum severity vulnerability (CVE-2025-41115) in Grafana Enterprise that allows attackers to hijack administrator accounts through the SCIM provisioning feature. If you use Grafana Enterprise with SCIM enabled, immediate action is required to prevent unauthorized privilege escalation.
Key takeaways:
🔥 Max Severity Flaw: CVE-2025-41115 allows a malicious SCIM client to provision a user with a numeric externalId (e.g., “1”) that maps directly to an internal admin user.uid, granting full control.
🎯 Affected Versions: This vulnerability impacts Grafana Enterprise versions 12.0.0 through 12.2.1, specifically when enableSCIM and user_sync_enabled are both set to true.
🛡️ Immediate Mitigation: Admins must upgrade to patched Enterprise versions (12.3.0, 12.2.1, 12.1.3, or 12.0.6) or disable SCIM functionality immediately.
☁️ Cloud & OSS Safe: Grafana OSS users are not impacted, and Grafana Cloud environments (including Azure/Amazon managed services) have already been patched by the vendor.
🕵️ Detection: The flaw exploits a logic error in how external IDs are mapped to internal user IDs, a feature currently in “Public Preview”.
CrowdStrike Foils Insider Threat Attempt by “Scattered Lapsus$ Hunters”
CrowdStrike has terminated a “suspicious insider” caught sharing internal screenshots and attempting to provide network access to the “Scattered Lapsus$ Hunters” hacking collective. While the threat actors claimed to have paid the insider for access, CrowdStrike’s internal monitoring detected the activity and revoked access before any systems were compromised.
Key takeaways
🕵️ Insider Caught: CrowdStrike identified and fired an insider for sharing pictures of internal systems with external threat actors.
💰 Failed Buyout: The hacking group, a coalition involving Scattered Spider and Lapsus$, claimed they agreed to pay the insider $25,000 for access.
🛡️ Proactive Defense: Security teams detected the unauthorized activity and cut off the insider’s network access before stolen SSO cookies could be utilized.
✅ Zero Impact: CrowdStrike confirmed that its systems remained secure and no customer data was compromised during the incident.
⚖️ Legal Action: The company has referred the case to law enforcement agencies for further investigation.
Malicious Blender Files Distributing Stealc Malware
Cybercriminals are actively targeting the 3D modeling community by hiding the “Stealc” infostealer inside compromised .blend files on popular asset platforms like CGTrader. When opened with scripts enabled, these files execute code that steals sensitive data, including cryptocurrency wallets and browser credentials.
Key takeaways:
🕵️♂️ Hidden Danger: Attackers embed malicious Python scripts (often named Rig_Ui.py) inside otherwise functional 3D models.
⚠️ The Trigger: The malware executes immediately if the “Auto Run Python Scripts” feature is enabled in Blender, a common setting for complex rigs.
🦠 The Payload: The script deploys Stealc V2, an aggressive infostealer capable of harvesting data from over 23 browsers and 15 desktop wallets.
🛡️ Immediate Action: Disable “Auto Run Python Scripts” in your Blender settings (Edit > Preferences > Save & Load) to block automatic execution.
💡 Best Practice: Treat third-party .blend files with the same caution as executable files; inspect scripts before allowing them to run.
New ClickFix Campaign Mimics Windows Update to Drop Malware
A sophisticated new ClickFix campaign is tricking users with highly realistic fake Windows Update screens that lead to severe malware infections. Victims are socially engineered into manually executing malicious PowerShell commands, often unleashing stealthy info-stealers hidden within image files.
Key takeaways:
🛑 The Lure: Attackers display a convincing full-screen fake Windows Update animation that claims to be “fixing” an issue.
🎣 The Trap: The site instructs victims to press specific keys (often Win + R, then Ctrl + V) to paste and run a malicious command to “complete” the update.
🖼️ Steganography: To evade antivirus detection, the malicious code is often hidden inside the pixel data of PNG images.
🦠 The Payload: This campaign primarily distributes info-stealers like Lumma and Rhadamanthys, which harvest credentials and cryptocurrency wallets.
🛡️ Defense: Legitimate Windows Updates will never ask you to run a command in the Run dialog or PowerShell manually.
Critical Fluent Bit Flaws Expose Cloud Infrastructure to RCE and Takeover
Researchers have uncovered five severe vulnerabilities in the widely used Fluent Bit telemetry agent that allow attackers to execute remote code, crash services, and manipulate logs to hide their tracks. These flaws pose a significant threat to cloud and Kubernetes environments, enabling deep infrastructure compromise through tag manipulation and authentication bypasses.
Key takeaways:
🚨 5 Critical Vulnerabilities: The flaws include Path Traversal (CVE-2025-12972) and Stack Buffer Overflow (CVE-2025-12970), leading to RCE and DoS risks.
☁️ Cloud & Kubernetes Risk: Attackers can exploit these defects to hijack cloud infrastructure, disrupt services, and tamper with critical data across major providers like AWS and GCP.
🔓 Auth Bypass: A missing authentication check in the in_forward plugin allows attackers to inject false telemetry and flood security logs with fake events.
🕵️♂️ Stealthy Intrusions: Vulnerabilities in tag-matching logic enable attackers to reroute logs or overwrite arbitrary files to erase evidence of their attack.
🛠️ Patch Immediately: Users are urged to upgrade to Fluent Bit versions 4.1.1 or 4.0.12 and restrict access to configuration files.
Shai-Hulud Worm Infects 500+ npm Packages to Leak Secrets
A sophisticated self-propagating worm dubbed “Shai-Hulud” has launched a massive supply chain attack against the npm ecosystem, compromising over 500 packages to harvest and expose sensitive developer credentials. Unlike typical attacks, this malware actively uses stolen credentials to infect other packages maintained by the victim, creating a cascading cycle of compromise.
Key takeaways:
🦠 Self-Propagating Worm: The malware automatically spreads by using stolen npm tokens to inject malicious code into other packages owned by the compromised developer.
🔓 Massive Secret Theft: It utilizes tools like TruffleHog to scan for and steal secrets, including keys for AWS, Google Cloud, Azure, npm, and GitHub.
🌐 Public Exfiltration: Stolen credentials are audaciously exfiltrated by creating new public GitHub repositories named “Shai-Hulud” on the victim’s own account.
⚠️ Destructive Potential: Newer variants have been observed with “dead man’s switch” capabilities that can wipe data if the malware loses access to its command infrastructure.
🛡️ Immediate Action: Developers should audit their package.json scripts, check for unauthorized “Shai-Hulud” repositories, and immediately rotate any exposed credentials.
FBI Warns: Bank Support Impersonation Scams Steal $262 Million
The FBI has issued a critical warning regarding a surge in Account Takeover (ATO) fraud, where cybercriminals have stolen over $262 million this year by impersonating financial institution support teams. These sophisticated social engineering attacks trick victims into surrendering login credentials and MFA codes, allowing attackers to drain accounts and transfer funds to cryptocurrency wallets.
Key takeaways:
💸 Massive Financial Impact: Since January 2025, the IC3 has received over 5,100 complaints related to these scams, with total losses exceeding $262 million.
🎭 Deceptive Tactics: Attackers impersonate bank employees or law enforcement, often using “fraud alerts” about fake charges to panic victims into sharing One-Time Passcodes (OTPs) or clicking phishing links.
🕸️ SEO Poisoning: Criminals are utilizing Search Engine Optimization (SEO) poisoning and purchasing ads to make fake bank support websites appear at the top of search results, trapping users seeking legitimate help.
🔄 Sophisticated Handoffs: To increase credibility, scammers often transfer victims from a fake bank agent to a co-conspirator posing as a government official or law enforcement officer.
🛡️ Defense Strategy: Remember that legitimate financial institutions will never ask for your password or OTP. If you receive a suspicious call, hang up immediately and verify by calling the number on the back of your card.
Internet Crime Complaint Center (IC3)
Code Beautifiers Leaking Secrets from Banks, Gov, and Tech Giants
A new report reveals that developers using popular online “code beautifier” tools are inadvertently exposing massive amounts of sensitive data. Sites like JSONFormatter and CodeBeautify, used to format code, have been found leaking credentials through public “Recent Links” pages and predictable URL structures.
Key takeaways:
🔓 Mechanism of Leak: When users “save” their code to share or format it, these sites often generate public URLs. Researchers found they could easily scrape these links to harvest confidential data.
🏦 High-Value Targets: The exposed data spans critical sectors, including banking, government, healthcare, aerospace, and major tech companies.
🗝️ Critical Secrets Exposed: The leak includes Active Directory credentials, API keys (AWS, GitHub), database connection strings, private keys, and even PII.
🕵️ Active Exploitation: Researchers planted fake “canary” credentials and found unauthorized actors attempting to use them within 48 hours, proving attackers are actively monitoring these sites.
CISA Alert: Spyware Campaigns Hijacking Signal & WhatsApp to Target High-Value Users
CISA has issued an urgent warning regarding active spyware campaigns leveraging sophisticated tactics—including zero-click exploits and “linked device” hijacking—to compromise Signal and WhatsApp accounts of high-ranking officials and activists. Threat actors are bypassing encryption protections to exfiltrate sensitive data from government, military, and civil society targets across the US, Europe, and the Middle East.
Key takeaways:
🔓 Account Hijacking: Attackers are exploiting the “linked devices” feature in Signal and WhatsApp, often using social engineering to trick victims into scanning QR codes that grant persistent access to their messages.
🕵️ Fake Apps & Malware: Campaigns like ProSpy, ToSpy, and ClayRat use spoofed versions of popular apps (e.g., Signal, TikTok, Google Photos) to deploy remote access trojans (RATs) on Android devices.
📱 Zero-Day Exploits: The attacks utilize vulnerability chains, including a Samsung flaw (CVE-2025-21042) to deploy LANDFALL spyware and iOS/WhatsApp exploits (CVE-2025-43300, CVE-2025-55177) for stealthy infection.
🛡️ Mitigation: CISA urges high-risk individuals to regularly check “Linked Devices” lists, enable “Lockdown Mode” on iPhones, restart phones periodically, and switch to FIDO-based phishing-resistant authentication.
U.S. Cybersecurity and Infrastructure Security Agency (CISA)
ShadowV2 Botnet Exploits AWS Outage as Cover for Attacks
Researchers at Darktrace have identified ‘ShadowV2,’ a sophisticated botnet that leveraged the chaos of a recent AWS outage to test its capabilities against misconfigured Docker APIs. By striking when defenders were distracted by service disruptions, attackers deployed a potent DDoS-as-a-Service platform with reduced risk of detection.
Key takeaways:
🚨 Opportunistic Timing: The attackers utilized the operational noise of the AWS outage as a “smokescreen,” launching infection waves when security teams were focused on restoring availability rather than threat hunting.
🎯 Targeting Misconfigurations: The campaign specifically scans for and exploits exposed Docker API endpoints (often on port 2375) within AWS EC2 instances to gain initial access and build custom malicious containers.
☁️ Hiding in Plain Sight: ShadowV2 hosts its Command & Control (C2) infrastructure on GitHub Codespaces, allowing its malicious traffic to blend in seamlessly with legitimate development activity, making blocking difficult.
🦠 DDoS-for-Hire Capabilities: Once established, the botnet offers a “Cybercrime-as-a-Service” platform, capable of launching advanced attacks like HTTP/2 Rapid Reset floods against rented targets.
🛡️ Defense Priority: Organizations must ensure Docker APIs are not exposed to the public internet and should implement strict authentication measures to prevent unauthorized container access.
Multiple London Councils Hit by Major Cyberattack Disrupting Critical Services
The Royal Borough of Kensington and Chelsea, Westminster City Council, and Hammersmith & Fulham are battling a serious cyber incident that has knocked shared IT systems offline and triggered emergency protocols. The attack has disrupted essential services and phone lines, prompting a multi-agency response to protect resident data.
Key takeaways:
🏛️ Shared Infrastructure Targeted: The attack exploited IT systems shared between the three boroughs, highlighting the cascading risks of interconnected public sector networks.
🛑 Service Blackout: Critical services, including council tax portals, parking fines, and contact centers, have been disrupted or taken offline as a precaution to contain the threat.
📉 Emergency Mode: All affected councils have invoked business continuity plans to ensure support for vulnerable residents continues despite the digital blackout.
🕵️ High-Level Response: The National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) are actively assisting, while the Information Commissioner’s Office (ICO) has been notified of potential data compromise.
⚠️ Ongoing Investigation: While the specific nature of the attack (e.g., ransomware) is unconfirmed, IT teams are working around the clock to restore systems safely.
RomCom Threat Actor Pivots to SocGholish for Malware Delivery
A new campaign linked to the Russian-aligned threat actor RomCom (Unit 29155) has been observed using the SocGholish (FakeUpdates) framework to target organizations. This marks the first time RomCom payloads have been deployed via this widespread fake update mechanism to deliver the Mythic Agent malware.
Key takeaways:
⚡ New Tactic: This is the first observed instance of RomCom leveraging the SocGholish JavaScript loader, typically used by financial cybercrime groups, to distribute its espionage tools.
🎯 Targeted Espionage: The campaign specifically targeted a U.S.-based civil engineering company that had previously worked for a city with close ties to Ukraine, highlighting a continued focus on geopolitical interests.
⏱️ Rapid Attack Chain: The time from the initial “fake update” infection to the delivery of the RomCom loader was observed to be less than 30 minutes.
🛡️ Selective Delivery: The malware verifies the victim’s Active Directory domain against a known value before delivering the final payload to ensure precise targeting.
🕵️ Attribution: The activity is attributed with medium-to-high confidence to Unit 29155 of Russia’s GRU, also known as Void Rabisu or Tropical Scorpius.
OpenAI API Users Exposed in Third-Party Mixpanel Breach
OpenAI has disclosed a data breach affecting a subset of its API customers after its analytics vendor, Mixpanel, was compromised via a targeted smishing attack. While critical credentials like API keys and passwords remain secure, personal contact details and usage metadata were exposed, raising concerns about future social engineering attempts.
Key takeaways:
🔒 Scope of Impact: The breach specifically affects ChatGPT API users; standard ChatGPT users and other products were not compromised.
🕵️♂️ Data Exposed: Attackers accessed names, email addresses, approximate locations, and device details, but no payment info, passwords, or API keys were stolen.
📲 Root Cause: The incident stemmed from a successful SMS phishing (smishing) campaign targeting Mixpanel employees, highlighting the supply chain risk.
⚠️ Immediate Risk: With accurate metadata (OS, browser, Org IDs) now in the wild, users should expect highly realistic, targeted phishing emails.
🛡️ Actionable Advice: Verify all communications claiming to be from OpenAI, enable 2FA on all accounts, and never share verification codes via chat or email.
Microsoft Hardens Entra ID Against Script Injection Attacks
Microsoft is rolling out a major security update to Entra ID (formerly Azure AD) that will block unauthorized scripts during login to prevent XSS attacks. Starting late 2026, a strict Content Security Policy (CSP) will enforce that only trusted Microsoft domains can execute scripts on sign-in pages.
Key takeaways:
📅 Timeline: The new policy kicks in globally from mid-to-late October 2026, giving admins a year to prepare.
🚫 The Change: A stricter Content Security Policy (CSP) will block all non-Microsoft scripts on login.microsoftonline.com.
🧩 Impact: Browser extensions or custom tools that inject code into the sign-in flow will break.
✅ Action Item: Admins must test sign-in flows now using browser developer tools to spot “Refused to load the script” errors.
🌐 Security Goal: This move significantly reduces the attack surface for Cross-Site Scripting (XSS) and credential theft during authentication.
Top Tips of the Week

Threat Intelligence
- Regularly update CTI analysts’ skills. Continuous learning ensures expertise aligns with evolving threat landscapes.
- Conduct regular threat intelligence exercises. Simulate scenarios to test CTI readiness and identify areas for improvement.
Threat Hunting
- Understand the tactics, techniques, and procedures (TTPs) of cyber threat actors. Identify and respond effectively to their methods. Develop hypotheses for cyber threat hunting. Form educated guesses about potential threats and use them as guides in your investigations.
- Develop hypotheses for cyber threat hunting. Form educated guesses about potential threats and use them as guides in your investigations.
- Implement a response plan. Be prepared to act swiftly when a threat is detected. A well-defined plan is crucial.
- Monitor supply chain risks in cyber threat hunting. Assess and address vulnerabilities to mitigate potential threats.
Custom Tooling
- Implement error reporting and analysis in custom tools. Quickly identify and address issues to maintain tool reliability.
Feature Video
Feel like a line cook just following recipes in the SOC? 👨🍳 It might be time to become the chef and write your own cookbook.
Learn what detection engineering is and how to become one in this video!
🔄 Flip the Script: Stop waiting for a vendor’s “black box” to tell you something is wrong. Detection Engineering moves you from a reactive posture to a proactive defense architect.
💻 Detection as Code: It’s not just writing queries; it’s engineering. Treat your detections like software with version control, automated testing, and CI/CD pipelines to reduce false positives.
🔺 Climb the Pyramid of Pain: Move beyond easy-to-change indicators like IPs and hashes. Focus on TTPs (behaviors) to make attacks fundamentally expensive and painful for the adversary.
🧠 The Hybrid Skill Set: This role combines the best of three worlds: the coding chops of a developer, the query mastery of a senior analyst, and the deep OS knowledge of a researcher.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



