Triaging the Week 137

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Theme 1: Trusted Tools, Malicious Intent

Stories

🗞️ Attackers Weaponize AI Builders & RMM Tools in Novel Campaign (Allure Security) – Attackers are offering fake “desktop apps” for cloud HR and payroll platforms. The download sites are built with AI app builders and hosted on Vercel and GitHub Releases, and the “app” silently installs a modified ConnectWise ScreenConnect. Every piece of infrastructure is legitimate, so signature-based detection has nothing malicious to catch. 🔎 Threat Hunting Package

🗞️ Phishing Attacks Stack Dual RMM Tools for Persistent Access (Microsoft Security) – Phishing emails deliver signed MSP360 installers disguised as meeting requests, tax documents, and job offers. MSP360 then stages ScreenConnect as a second foothold. The attacker ends up with redundant remote access that looks like routine IT administration. 🔎 Threat Hunting Package

🗞️ Threat Actors Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix Attacks (Huntress) – Fake Custom GPTs on chatgpt.com, such as “Plus 5.6”, send victims to CAPTCHA lures hosted on Google Sites. The lures trick users into pasting obfuscated PowerShell, which deploys a RAT by sideloading a DLL through a signed binary. 🔎 Threat Hunting Package

Recommendations

☑️ Tell employees that HR and payroll SaaS runs only in the browser or a mobile app. Any “desktop installer” for those services is phishing, and they should never paste PowerShell or Terminal commands from a website.

☑️ Audit endpoints for unauthorized RMM tools, especially ScreenConnect and MSP360. Look for unfamiliar background Windows services and remote sessions from non-corporate IP ranges.

☑️ Enforce application control (AppLocker or WDAC) and least privilege. This blocks unvetted RMM utilities, unsanctioned PowerShell, and unsigned DLL sideloading.

☑️ Hunt for these behaviors:

  • PowerShell spawning msiexec from %TEMP%
  • Signed binaries running from %LOCALAPPDATA%\Programs\
  • Run keys or scheduled tasks that recreate themselves after deletion

Also apply ASR rules that block process creation from PsExec and WMI.

Theme 2: Espionage, Theft and Influence

Stories

🗞️ Bitget Exchange Hacked by Suspected North Korean Threat Actors (BleepingComputer) – Suspected North Korean actors stole $351.6M from Bitget’s hot and warm wallets. They compromised a backend wallet-service system, forged transfer data, and triggered the signing process directly, bypassing standard controls. Bitget’s User Protection Fund will cover user balances.

🗞️ Microsoft Details NeedyMantis: Modular Post-Compromise Malware Used in Targeted Espionage (Microsoft Security) – NeedyMantis is a modular framework that China-aligned actors deploy after a breach. It hides payloads in custom encrypted archives and side-loads DLLs that spoof Office, Intel, NVIDIA, and ws2_32.dll to run covert WebSocket C2. Targets include telcos, universities, intergovernmental bodies, medical nonprofits, and government contractors. 🔎 Threat Hunting Package

🗞️ Star Blizzard APT Escalates Cyberespionage with Novel ‘RedFlick’ Malware Technique (Microsoft Security) – Russia’s Star Blizzard has moved from targeted spear-phishing to mass mailing from compromised WordPress and cPanel sites. Victims receive password-protected archives that trigger RedFlick, a single-click infection chain that uses scheduled tasks to install the CosmicPulse backdoor. Targets are Ukraine-supporting organizations, NGOs and think tanks. 🔎 Threat Hunting Package

🗞️ MI5 Issues Unprecedented Alert: Over 100 UK Academics Unknowingly Aided Chinese Intelligence Front (MI5) – In its first public Espionage Alert, MI5 warned that more than 100 UK academics contributed to research funded by CGTRI, a front for China’s Ministry of State Security. The research covered AI and sensitive technology. CGTRI hid its MSS ties, so the funding sidestepped export and security scrutiny.

Recommendations

☑️ Remove single points of trust in high-value transaction systems. Use MPC or hardware-backed multi-signature schemes, run anomaly detection on transaction requests, and halt suspicious bulk transfers automatically.

☑️ Hunt for:

  • Masquerading DLLs (e.g., dnsapi.dll, WinSparkle.dll) dropped in application directories
  • Unusual WebSocket traffic and user-agent strings
  • Scheduled tasks created from recently extracted archives

☑️ Brief high-risk staff in policy, NGO and research roles to scrutinize conference invites, roundtable lures and payment notices that carry password-protected attachments. Harden your own WordPress and cPanel so attackers can’t use your domains as a launch pad.

☑️ Before accepting foreign funding, verify who ultimately owns and funds the organization offering it. Review or suspend any collaboration linked to CGTRI, give research-security training to staff in dual-use fields, and enforce strict egress controls and microsegmentation.

Theme 3: Supply Chain, Cloud Identities and Edge Devices

Stories

🗞️ Re-Enabled GitHub Actions Expose Thousands of Repositories to Active Mini Shai-Hulud Malware (Socket) – Two previously compromised actions-cool GitHub Actions (issues-helper and maintain-one-comment) were re-enabled with their malicious release tags intact. The Mini Shai-Hulud payload then ran again across 15,000+ repositories and exposed CI/CD secrets. Any workflow referencing a mutable version tag was hit without the attackers doing anything new.

🗞️ ‘PhantomSub’ npm Campaign Abuses Baileys Library to Hijack WhatsApp Accounts for Spam (OX Security) – 101 malicious npm packages wrap the Baileys WhatsApp API and have been downloaded about 490,000 times. They hijack connected WhatsApp sessions to inflate follower counts on spam channels. The channel lists are hidden behind remote GitHub fetches, hardcoded IDs, or Base64 obfuscation.

🗞️ Storm-3168: Agentic-Driven Cloud Attacks Exploit Compromised Azure Service Principals (Microsoft Security) – Storm-3168 used Azure service principal secrets leaked in public repositories and issue histories. Within seven minutes, it wiped storage accounts, key vaults, and databases, then stole credentials to block recovery. Because the service principals were already over-privileged, the attacker never needed to escalate privileges. 🔎 Threat Hunting Package

🗞️ CISA Warns of Actively Exploited Zero-Day Vulnerabilities in Citrix NetScaler ADC and Gateway (CISA) – CISA added two actively exploited NetScaler zero-days to its KEV catalog, both rated CVSS 9.5. CVE-2026-88771 allows unauthenticated command execution in default configurations, and CVE-2026-88772 is a DTLS buffer overflow. Attackers are using them to plant persistent webshells before patches go out.

Recommendations

☑️ Pin all third-party GitHub Actions to full 40-character commit SHAs. Search your workflows for the two actions-cool actions, and rotate every secret exposed to tag-based runs between September 16 and 25, 2026.

☑️ Add software composition analysis and malicious-dependency vetting to CI/CD, and ingest the PhantomSub IOCs into your threat intel and URL-reputation pipelines.

☑️ Scan public repositories and issue histories for leaked service principal secrets. Then:

  • Move to Managed Identities
  • Enforce least-privilege RBAC
  • Put deletion locks on critical storage
  • Alert on machine-speed deletions in Azure Resource Manager and Entra ID logs

☑️ Patch NetScaler to 14.1-73.37, 13.1-64.23 or later, or restrict public access until you can. Run a compromise assessment first to preserve evidence. If the appliance is compromised, isolate it and rotate credentials, tokens, KEKs, and certificates.

Theme 4: AI Is the New Attack Surface

Stories

🗞️ 80,000+ Organizations Compromised in Massive AI Credential Theft (SOCRadar) – Infostealers have taken employee AI logins, mostly ChatGPT, from more than 80,000 corporate domains. Tech firms account for 40% of the exposed records. A stolen AI session bypasses MFA and gives the attacker two things: a searchable store of everything employees pasted in, and compute they can abuse for LLM-jacking or resell.

🗞️ High-Severity OAuth Flaw in Official MCP Python SDK Enables Account Takeovers (Cycode) – Weak issuer validation in the SDK’s OAuth discovery lets a malicious MCP server redirect token-exchange credentials to an attacker-controlled endpoint. That exposes client secrets, authorization codes, and PKCE keys, enabling account takeover without any phishing page.

🗞️ AI Coding Agents Accidentally Leak 13,000+ Sensitive Screenshots to Public GitHub Repositories (Glow) – AI coding agents needed to attach screenshots to pull requests but couldn’t upload images through the CLI. As a workaround, they pushed the screenshots to public repos on developers’ personal accounts, often using tools like gitshot. Customer records, credentials, and billing data from 300+ organizations were exposed, outside corporate monitoring.

🗞️ OpenAI Scraps GPT-6.1 Astra Release Over Agentic Deception and Safety Regressions (The Wall Street Journal) – OpenAI canceled the October release after safety testing found two problems. The model misreported actions it had taken, and it tried to use external tools without permission. That is a failure to respect scope and authorization, not ordinary hallucination.

🗞️ OpenAI Disrupts Coordinated Campaign Exploiting Model Interactions to Steal Protected Reasoning (OpenAI) – OpenAI shut down more than 15,000 accounts that were extracting its protected reasoning without breaching any database. They did it by manipulating sessions, for example, copying encrypted reasoning from one conversation and getting another session to decrypt it. A core cluster was linked to individuals associated with Moonshot AI.

Recommendations

☑️ Treat AI tools as identity infrastructure:

  • Enforce SSO
  • Use short-lived session cookies with refresh-token rotation
  • Scope, cap, and rotate API keys
  • Monitor stealer logs for your domains, and treat any exposed credential as a full endpoint compromise

☑️ Upgrade the MCP Python SDK to 1.30.0 (1.x branch) or 2.2.0 (2.x branch) and declare issuer= explicitly. Clear OAuth registrations created by older versions, and rotate tokens for any client that connected to an untrusted MCP server.

☑️ Put human-in-the-loop approval and granular permissions on autonomous agents. Log what agents do on the server side instead of trusting their self-reports.

☑️ Govern AI coding agents with DLP and shadow-AI controls so they can’t create public repos or run unvetted CLI tools. Search for repos named gitshot-images or releases tagged _gitshot, and audit shared prompt files and agent skills.

Theme 5: Workforce Strain, Skills Gaps and Cybercriminal Blunders

Stories

🗞️ Pentagon Escalates Direct Oversight of U.S. Cyber Command Following Operations Burnout Crisis (The Record) – After a cluster of suicide deaths among personnel supporting CYBERCOM and the NSA at Fort Meade, a Pentagon memo brings Cyber Command 2.0 reforms forward by years. The reforms include formal work-rest plans, educational sabbaticals, and reprioritized missions.

🗞️ 57% of UK Businesses Lack Confidence in Basic Cyber Skills as Skills Gap Widens (DSIT) – 57% of UK businesses, about 808,000 organizations, lack confidence in basic cyber tasks, up from 49% last year. Regulation alone won’t fix this without affordable tools and managed services for smaller organizations.

🗞️ Women in UK Cybersecurity Drops to 16% as Structural Barriers Persist (DSIT) – Women now make up 16% of the UK cyber workforce, the lowest share since 2021. In roles requiring six or more years of experience, it falls to 12%, pointing to a retention and advancement problem rather than only an entry-level one.

🗞️ England’s Schools Recover Faster from Cyber Attacks, but Governance Gaps Persist (Ofqual) – The share of schools hit by incidents fell to 27%, and 66% now recover immediately. However, only 9% of teachers see senior leadership as primarily responsible for cybersecurity, and 46% still treat it as an IT problem.

🗞️ Police Arrest 16-Year-Old Suspected Mastermind Behind KillSec Ransomware, Seize Leak Site and Servers (elperiodic.com) – Police in Germany, Spain, the UK and Romania arrested a 16-year-old Romanian suspected of running the KillSec RaaS operation. They seized more than 110 TB of stolen data, the leak site, and five servers. Most of the group’s 500+ victims were breached through cloud misconfigurations and unpatched edge applications.

🗞️ Dark Web Fails: When Cybercriminals Forget Operational Security (Trellix) – Trellix’s August roundup of criminal opsec blunders includes ten “independent” fake crypto exchanges running on one server with one shared Yandex.Metrica counter. It also covers “multi-gigabyte” data leaks that turned out to be megabytes.

Recommendations

☑️ Build sustainable operations: mandatory rest plans, rotation paths such as instructor or education roles, and support that staff can reach easily inside operational spaces. Match the operational tempo to the team’s actual capacity.

☑️ Close skills and governance gaps practically:

  • Use MSPs for baseline controls
  • Adopt Cyber Essentials and regular awareness training
  • Give board-level ownership of cyber risk
  • Support smaller suppliers with accessible guidance

☑️ Fix retention, not just recruitment. Audit hiring and promotion for bias, and fund sponsorship and mid-career programs that move women into senior technical and leadership roles.

☑️ Close the basics KillSec exploited: lock down cloud storage, patch public-facing apps quickly, keep immutable offline backups, and alert on unusual data transfer volumes. In CTI work, track shared infrastructure and analytics IDs to unmask actors operating under new aliases.


Feature Livestream

Here’s what no one tells you about running MISP:

👉 Your instance can be full of well-tagged events, and your stakeholders can still get nothing.

➡️ MISP is brilliant at collection and sharing. It has no idea what your CISO needs to decide this quarter.

➡️ It doesn’t hold your intelligence requirements.

➡️ It doesn’t know who your stakeholders are or what they’re cleared to see.

➡️ It doesn’t produce briefings, flash alerts, or advisories.

➡️ It doesn’t capture feedback, so you can’t show any of it mattered.

That’s where many MISP-based CTI teams stall. Plenty of data, no program.

💡 zsazsa is an open-source program layer that sits on top of MISP and stores everything back in MISP: requirements, stakeholders, products, and feedback.

Earlier this week I installed it and built a CTI program for Harbour & Finch. It’s a fictional UK retailer worried about help-desk social engineering leading to ransomware, the same pattern we’ve seen across UK retail.

By the end of the hour, we’ll have a PIR, stakeholders, three drafted products, one delivered alert, and a maturity baseline.

We’ve already covered sharing, workflows, the API, and SIEM integration in the MISP series. This episode adds the layer that turns all of that into a program.

Feature Course


Learning Resources

Triaging the Week News Stories

Cyber Training

Tools