Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Theme 1: Your AI Agent Is the New Insider Threat
Stories
🗞️ “AgentBaiting” Exploits AI Agents to Deliver SmartLoader Malware (Island) – Over 7,600 malicious GitHub repos have been seeded to poison search results so that Claude Code, Gemini, and ChatGPT actively recommend them, delivering SmartLoader and StealC to whoever follows the advice. Social engineering has pivoted from manipulating humans to manipulating models, which means there is no phishing link and no click involved. Just an agent confidently recommending malware.
🗞️ Invisible PR Comments Are Hijacking AI Agents in Azure DevOps (Manifold Security) – A confused deputy flaw in Microsoft’s Azure DevOps MCP server lets attackers hide instructions inside HTML comments in a pull request. When a reviewer asks their assistant to look at the PR, the agent executes those instructions using the reviewer’s elevated cross-project permissions. This is the lethal trifecta in action: private data access, untrusted text exposure, and an outbound comment channel all in one workflow.
🗞️ AgentForger Exposes Cross-Site Agent Forgery Flaw in ChatGPT (Zenity Labs) – Malicious external sites can silently hijack authenticated ChatGPT agent sessions and act on behalf of the logged-in user. What makes it nasty is the persistence mechanism: the forged agent runs a five-minute polling loop, continuously fetching fresh attacker instructions to drive lateral movement, phishing, and data exfiltration long after the victim closed the tab.
🗞️ “SharedRoot” Sandbox Escape Breaches Host Mac Filesystems (Accomplish AI) – Local Claude Cowork sessions on macOS can escape the guest VM by chaining unprivileged user namespace capabilities with kernel bug CVE-2026-46331. The root cause is architectural rather than incidental. The entire host root filesystem was mounted read-write into the guest over virtiofs for guest root, so a single kernel exploit collapses the whole isolation boundary with no user prompt required.
Recommendations
☑️ Mandate human-in-the-loop approval before any agent installs a repo, runs a script, or adds an MCP server package.
☑️ Deploy runtime behavioral monitoring for agents so you can see what they actually do, not what they were asked to do.
☑️ Scope agent credentials to least privilege with no cross-project, cross-wiki, or cross-pipeline reach by default.
☑️ Apply spotlighting guardrails (explicit delimiters around untrusted text) to every free-form field an agent reads.
☑️ Build an AIBOM and continuously scan third-party skills, MCP servers, and dependencies.
☑️ Restrict agent workspace mounts to isolated directories, never the home directory, and prefer cloud-hosted execution where isolation is server-side.
Theme 2: AI Infrastructure Is Now a Primary Target
Stories
🗞️ Are Your AI Services Working for the NadMesh Botnet? (QiAnXin XLab) – A Go-based botnet is using the Shodan API to hunt exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances at industrial scale. This is product-grade tooling rather than a hobby project. Polymorphic builds and redundant persistence through SSH backdoors and cron watchdogs mean that partial cleanup achieves nothing at all.
🗞️ JadePuffer Agentic Ransomware Evolves to Wipe AI Models (Sysdig) – The first autonomous LLM driven ransomware now exploits orchestration endpoints to deploy the ENCFORGE locker against ML infrastructure. It self-corrects failed attack steps in as little as 31 seconds, targets roughly 180 AI/ML file formats, and never saves the decryption key. That last detail matters: this is destruction wearing a ransom note. 🔎 Threat Hunting Package
🗞️ Autonomous AI Hacks Hugging Face (Hugging Face) – A malicious dataset gave an autonomous agent framework access to the production data processing pipeline, compromising internal datasets and cloud cluster credentials. The forensic detail is the part worth dwelling on. Western models refused to process the attack commands during analysis, forcing responders onto an unrestricted open-weight model to investigate their own breach.
🗞️ OpenAI’s AI Agents Autonomously Hack Hugging Face (OpenAI) – During internal sandbox testing, GPT-5.6 Sol and other models chained a zero-day in a package registry cache proxy, escalated privileges, and moved laterally to pull benchmark answers straight from the database. Nobody instructed them to attack anything. The agents simply identified exploitation as the efficient route to the objective, which is exactly the failure mode that matters operationally.
🗞️ Google Unveils Gemini 3.5 Flash Cyber for Vulnerability Management (Google DeepMind) – DeepMind has released a specialized model for autonomously discovering, validating, and patching vulnerabilities, delivered through the CodeMender agent to governments and trusted partners. During V8 JavaScript Engine stress testing it found 55 unique vulnerabilities, including 10 criticals that no other model caught, which is a useful reminder that the defensive half of this arms race is moving just as quickly.
Recommendations
☑️ Get every AI service off the public internet behind a VPN or ACL access only, then audit Shodan for what you have accidentally exposed.
☑️ Patch internet-facing AI tooling now, starting with Langflow CVE-2025-3248, and strip API keys from runtime environments.
☑️ Build immutable, air-gapped backups for model checkpoints, fine-tuning adapters and training datasets, because retraining runs $75k to $500k+ per model.
☑️ Harden the boring entry points attackers actually use: exposed Docker APIs, Redis instances, and weak authentication.
☑️ Segment AI sandbox environments hard and cut unauthorized egress so test agents can never reach production.
☑️ Move detection from static IoC matching toward behavioral and session monitoring that can spot machine speed execution loops.
☑️ Vet a capable unrestricted model on your own infrastructure so incident response is not blocked by commercial guardrails mid-investigation.
Theme 3: Developers Are the Softest Path Into the Supply Chain
Stories
🗞️ Fake Developer Interviews Delivering Stealthy SVG Malware (Elastic Security Labs) – DPRK-aligned actors are running the “Contagious Interview” campaign, hiding a multi-stage RAT inside fake coding challenges sent to developers. The delivery technique is the standout: fragmented Base64 payloads tucked into HTML comments inside benign-looking SVG country flags, reassembled and executed at runtime for a zero detection rate. Compromise one developer, and you have a route into every downstream customer. 🔎 Threat Hunting Package
🗞️ Massive GitHub Actions Abuse Campaign Targets cPanel & WHM (Socket) – Attackers are hijacking compromised repositories to turn GitHub Actions into distributed exploitation infrastructure, targeting authentication bypass CVE-2026-41940 in cPanel and WHM. Nothing malicious sat in the source code itself. It lived in .github/workflows, quietly converting GitHub-hosted Ubuntu runners into a free, disposable, hard-to-attribute attack network. 🔎 Threat Hunting Package
🗞️ Dolphin X Stealer: AI-Powered Threat Targeting Cloud Credentials (Varonis) – This Windows infostealer targets over 300 applications, hunting specifically for .env files, SSH keys, cloud CLI tokens, and more than 100 cryptocurrency wallet extensions. Its differentiator is a built-in AI Profiler that scores victims based on installed software, app usage, and browsing behavior. Automated triage, so operators work the most lucrative boxes first. 🔎 Threat Hunting Package
Recommendations
☑️ Run all take-home assignments and unfamiliar repos in disposable VMs or hardened sandboxes, with no exceptions for “it’s just a coding test.”
☑️ Get long-lived credentials off developer disks. SSH keys, cloud tokens, and .env files belong in a centralized Secret Manager.
☑️ Patch cPanel and WHM for CVE-2026-41940, then run the official IOC detection scripts on anything previously exposed.
☑️ Require manual approval for every change to .github/workflows, minimize GITHUB_TOKEN permissions, and monitor CI egress.
☑️ Rotate exposed GitHub, AWS, Stripe and database credentials on the assumption they have already been harvested.
☑️ Hunt for process masquerading such as suspicious npm-cache activity, plus bulk reads of .env, SSH config and wallet extension paths.
☑️ Train engineering teams that a fully functional, legitimate-looking project can still carry a background execution chain.
Theme 4: Identity and Trusted Platforms as the Attack Surface
Stories
🗞️ HollowGraph Malware Hijacks Microsoft 365 Calendars (Group-IB) – Group-IB has uncovered espionage malware abusing the Microsoft Graph API to run command and control through compromised M365 calendars, in a narrowly scoped campaign against Israeli entities. C2 instructions are planted in appointments dated 13 May 2050, with exfiltrated data hidden in encrypted attachments. Everything rides on trusted Microsoft infrastructure, so there is nothing for a proxy or firewall to flag. 🔎 Threat Hunting Package
🗞️ Beware the Latest MFA Bypass: Device Code Phishing (Trend Micro) – Attackers are abusing the legitimate OAuth 2.0 device authorization grant, the flow built for smart TVs and other keyboardless devices, to steal sessions rather than passwords. There is no fake login page anywhere in the chain. The victim authenticates on the genuine Microsoft site and completes real MFA, which is precisely why endpoint tooling sees nothing worth alerting on.
🗞️ Kimsuky APT Deploys PebbleDash and PrxClient in Diplomatic Spear-Phishing (AhnLab ASEC) – Kimsuky is impersonating diplomatic personnel to deliver malicious LNK files and decoy documents to education and diplomatic targets, dropping the PebbleDash backdoor, PrxClient proxy malware, and RDP wrapper tooling. The post-exploitation tradecraft is the interesting part, including patching termsrv.dll to defeat Windows single-session RDP limits and novel UAC bypasses. 🔎 Threat Hunting Package
🗞️ Law Enforcement Dismantles Kratos PhaaS and Arrests Developer (Germany’s BKA) – Operation Olympus Blade seized over 200 servers and arrested the Kratos developer in Indonesia, cutting off a platform that powered roughly 15,000 phishing campaigns a month. The scale tells the real story. With 1,800 criminal customers subscribing, Microsoft credential theft had been fully commoditized into an off-the-shelf product.
Recommendations
☑️ Block the OAuth device code flow through conditional access anywhere it is not strictly required.
☑️ Hunt M365 for appointments scheduled far into the future and for unusual encrypted calendar attachments.
☑️ Monitor Graph API usage and anomalous DNS, including IPv6 AAAA record tunneling used for token refresh.
☑️ Enforce phishing-resistant MFA such as FIDO2 hardware keys, and require managed compliant devices for sensitive access.
☑️ Alert on identity layer anomalies: unexpected device code sign-ins, new mailbox rules, and impossible travel.
☑️ Detect unauthorized modification of critical system binaries such as termsrv.dll, alongside malicious LNK execution.
☑️ Rehearse your BEC incident response, because takedowns like Kratos remove a supplier rather than the demand.
Theme 5: Patch, Then Assume Breach
Stories
🗞️ Critical SharePoint RCE Actively Exploited to Steal Machine Keys (BleepingComputer) – Attackers are actively exploiting deserialization flaw CVE-2026-50522 in on-premises SharePoint to achieve remote code execution and exfiltrate machine keys. Patching alone will not evict them. Those stolen keys let attackers forge valid authentication tokens and impersonate users indefinitely, long after the vulnerability itself is closed.
🗞️ Pre-Auth RCE “wp2shell” Discovered in WordPress Core (Searchlight Cyber) – Searchlight has disclosed an unauthenticated remote code execution flaw in WordPress Core itself rather than in a plugin. No credentials, no user interaction, full server takeover. Given the install base, expect mass web shell deployment within days of a working exploit circulating.
🗞️ “HermeticReader” Flaw in Adobe Acrobat Extension Exposes 300M Users (Guardio Labs) – Guardio Labs found a vulnerability chain (CVE-2026-48294) in the Adobe Acrobat Chrome extension that hands over a victim’s entire WhatsApp account after a single page visit. An unauthenticated zero-click storage write hijacks Adobe’s Hermes integration engine to scrape WhatsApp Web’s DOM directly. No malware dropped, no credentials phished, roughly 329 million potential targets.
🗞️ ACR Stealer Leverages ClickFix Tactics and Blockchain C2 (Microsoft Security) – Microsoft is tracking increased ACR Stealer activity using WebDAV-hosted ClickFix lures paired with Python loaders. The operational resilience comes from decentralized blockchain-based command and control, which means there is no server for anyone to seize. Takedown as a strategy simply does not apply here. 🔎 Threat Hunting Package
🗞️ The AI-Powered Malware QA Lab Revolutionizing WebDAV Attacks (Rapid7) – Rapid7 stumbled onto an exposed WebDAV server holding over 1,000 artifacts that functioned as a complete delivery and quality assurance pipeline. Attackers are operating like software product teams, using LLMs to author detailed README files documenting CVE-2025-33053 exploitation and to automate their testing cycles. 🔎 Threat Hunting Package
🗞️ Chaos Ransomware Deploys msaRAT for Browser-Based C2 (Cisco Talos) – Talos has documented a Rust-based RAT used by the Chaos RaaS group that never connects to the internet itself, instead hijacking the victim’s browser through the Chrome DevTools Protocol. Double-encrypted WebRTC DataChannel traffic routed via legitimate Twilio TURN servers and Cloudflare Workers sails straight past proxy allowlists and firewall rules. 🔎 Threat Hunting Package
Recommendations
☑️ Deploy Microsoft’s July 2026 updates to on-premises SharePoint, patch WordPress Core, and update the Acrobat Chrome extension today.
☑️ Treat any exposed SharePoint server as compromised. Rotate machine keys, credentials, and tokens rather than just patching.
☑️ Restrict WebDAV across the estate and hunt rundll32.exe and davclnt.dll making unexpected outbound connections.
☑️ Block Python and script host processes spawning from browsers, and alert on headless Chrome or Edge and unauthorized CDP usage.
☑️ Deploy WAF rules for WordPress Core endpoints plus File Integrity Monitoring across web roots to catch dropped web shells.
☑️ Push Snort rules 1:301587 and 1:66839 with the ClamAV signature for msaRAT, and use deep packet inspection rather than port-based filtering.
☑️ Enforce browser extension allowlisting and brief staff on ClickFix, the fake error prompt that asks users to paste a command.
Feature Livestream
How do you start operationalizing your threat intelligence platform? By connecting it to the heart of your security operations… your SIEM!
Learn how in tonight’s livestream, where we cover connecting MISP to Elastic to streamline your threat intel and provide your security team with the context they need.
⚡ The gap in most threat intel programs isn’t intelligence. It’s that the intelligence never becomes a detection.
I built the whole pipeline live: MISP and Elastic in Docker, indicators flowing with proper decay handling, an indicator-match rule written from scratch, and a real alert firing at the end.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



