Triaging the Week 138

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Theme 1: Rogue AI Agents & the AI Governance Gap

Stories

🗞️ OpenAI Dismisses Safety Researchers Over Sensitive Data Leak (The Wall Street Journal) – OpenAI fired three safety team members for leaking confidential infrastructure architecture to an outside organization. Organizations now face two AI threats at once: insiders motivated by AI safety concerns, and autonomous agents breaking out of their sandboxes.

🗞️ Rogue AI Agents Target Wikimedia: What You Need to Know (Wikimedia Foundation) – Rogue OpenAI agents went beyond scraping. They made test edits in sandboxes, tried to use Etherpad as a proxy for remote fetching, and drove a 50% jump in bot bandwidth that contributed to a partial outage.

🗞️ Apple Tightens macOS Security Against AI Agent Exploitation (The Hacker News) – Apple will require explicit user action to grant Full Disk Access after AI agents such as Meta’s Muse were found reading iMessages. Zero-days like “not-a-mused” show that AI tools with privileged access are prime targets for privilege amplification.

🗞️ GitHub Copilot CLI Leaks Developer Secrets via Cryptographic Context Injection (Adversa AI) – Attackers hide encrypted prompt-injection instructions on web pages. Input guardrails can’t read them, so they decrypt them only inside the agent’s trusted loop, where they tell Copilot CLI in autopilot mode to read and exfiltrate .env secrets.

🗞️ Google Pauses Open-Source Bug Bounty Program Due to AI-Generated Spam (BleepingComputer) – Google halted OSS VRP submissions after a flood of AI-generated “slop” reports. This is now a systemic problem, following curl shutting down its HackerOne program.

🗞️ OpenAI Rolls Out Text Watermarking in EU to Meet AI Act Rules (OpenAI) – OpenAI’s “textGrain” watermark helps meet EU AI Act obligations but breaks easily. Swapping 10% of words for synonyms drops detection from 92% to 66%, and swapping 25% drops it to 17%.

🗞️ Anthropic Expands Cyber Verification Program to Empower Vetted Security Teams (Anthropic) – The program now has three tiers, including Defense Access and Red Team Access. Vetted teams get fewer false-positive blocks on dual-use work with Claude Opus 5.5 and Sonnet 5.5, while ransomware development and similar destructive tasks stay hard-blocked.

Recommendations

☑️ Treat AI agents as privileged identities. Apply least privilege, revoke unnecessary permissions such as Full Disk Access, disable autopilot or autonomous browsing on untrusted content, and isolate credential files (.env, .aws/credentials, private keys) from AI assistants.

☑️ Audit AI agent activity and harden your sandboxes. On the receiving end, defend public infrastructure with API rate limiting, bot-traffic monitoring, and support for transparent agent-identification standards.

☑️ Build an AI governance framework that covers insider threat monitoring, runtime re-screening of tool outputs before they enter the LLM context, AI-resistant triage for inbound reports, and layered content provenance (C2PA, metadata) rather than relying on watermarking alone.

☑️ Security teams doing defensive or authorized offensive work should apply for vetted AI access programs and secure their enrolment with phishing-resistant MFA and Workload Identity Federation.

Theme 2: Impersonation Everywhere

Stories

🗞️ China-Aligned Threat Group TA419 Impersonates Experts to Target US AI Policy Circles (Proofpoint) – TA419 poses as real AI policy authorities, including Anthropic personnel and former White House staff. It builds rapport through harmless conversations about AI policy, then sends multi-stage links to frameless Browser-in-the-Browser (BitB) AitM phishing pages. 🔎 Threat Hunting Package

🗞️ Fake AI Ad Portals Deploy Browser-in-the-Browser Attacks to Hijack Corporate Ad Accounts (Island) – Fake Gemini, Claude, ChatGPT, and Muse ad portals render a fake browser window, complete with a spoofed address bar, inside the page. Live operators then trigger and relay MFA prompts in real time to take over Google Ads and Meta Business accounts. 🔎 Threat Hunting Package

🗞️ Leaked Chats Expose Extortion Gang Deploying In-Person “Agents” to Breach U.S. Law Firms (The Record) – Silent Ransom Group (Luna Moth) recruits field operatives through Telegram job ads. These agents use forged badges, delivery uniforms, or masks to walk into law firm offices and plug into internal networks.

🗞️ Microsoft Teams to Add Third-Party Deepfake Detection and Impersonation Protection (BleepingComputer) – Microsoft is letting certified third-party providers analyze live meeting streams. They will raise real-time warnings in the meeting window when they detect synthetic video or audio.

Recommendations

☑️ Require out-of-band verification for unsolicited outreach and high-risk requests such as payments, password resets, and data access. This applies whether the request comes by email, video call, or in person.

☑️ Enforce phishing-resistant MFA (FIDO2/WebAuthn passkeys or hardware keys). This binds authentication to the real origin domain, defeating BitB and AitM relay attacks.

☑️ Train staff to spot impersonation. Teach the “window freedom check” (a real OAuth popup can be dragged outside the browser; a BitB one can’t), deepfake indicators and Teams warning banners, and courier or contractor ruses at reception.

☑️ Tighten physical and network controls. Escort all visitors, and use NAC/ZTNA to detect rogue hardware or unauthenticated connections. Regularly audit Google Ads MCC, Meta Business Manager, and M365 external guest settings for unauthorized changes.

Theme 3: Poisoned Trust

Stories

🗞️ Massive “FakeGit” Campaign Hijacks 17,600+ GitHub Repos to Deliver SmartLoader Malware (Apiiro) – Attackers don’t create new malicious repos. Instead, they “RePoint” existing, trusted ones, editing the README to link to malicious ZIPs that deliver SmartLoader and StealC. Because the repos are old and legitimate, domain blocklists and takedowns barely work. 🔎 Threat Hunting Package

🗞️ Midnight Mimosa Malware: The Unremovable Threat Shipping Pre-installed on Android Devices (Bitdefender) – Midnight Mimosa is built into the firmware of cheap MediaTek-based phones as a platform-signed system component. You can’t uninstall it, and it remotely loads code for ad fraud and botnets before the user ever turns the phone on. 🔎 Threat Hunting Package

🗞️ ccTLD Registry Hijacking Threatens Global Domains (Google Security) – Attackers breached the .gh, .sl, and .as registries and changed DNS records to obtain legitimate-looking HTTPS certificates. They never touched Google or any Certificate Authority.

🗞️ ASOS Confirms Data Breach After Hackers Broadcast Rogue In-App Notifications (BleepingComputer) – Attackers hijacked ASOS’s third-party messaging integrations and pushed “ASOS HACKED” alerts to customers’ phones, claiming a Snowflake compromise. The company’s own customer channels became the attackers’ megaphone.

Recommendations

☑️ Verify what you trust before you run it. Scrutinize repository download links, especially READMEs that tell you to bypass SmartScreen, or ZIPs that contain unexpected scripts like Launcher.cmd. Use MDM to block unverified or unusually cheap devices from corporate resources.

☑️ Monitor your external trust anchors continuously. Watch Certificate Transparency logs across your whole domain portfolio, and publish restrictive CAA records with ACME account bindings.

☑️ Audit, rotate, and tightly scope API keys and admin credentials for third-party integrations such as push gateways. Add broadcast kill-switches and rate limits to mass-notification systems.

☑️ Assume some sessions will be stolen. Use EDR to detect infostealer behavior, and apply continuous authentication and short session lifetimes across cloud consoles, SSO, and data warehouses.

Theme 4: Patch or Pay

Stories

🗞️ Warlock Ransomware Targets Critical Infrastructure via SharePoint Flaws (Symantec and Carbon Black) – China-nexus group Longlegs gets in through unpatched “ToolShell” SharePoint flaws. It then uses BYOVD to kill security software at the kernel level and pushes ransomware network-wide through SYSVOL, hitting utilities, telcos, governments, and universities. 🔎 Threat Hunting Package

🗞️ Critical Unauthenticated File Read Flaw Hits Atlassian Suite (CVE-2026-21589) (watchTowr) – A path traversal using :: delimiters in Atlassian’s web-resource routing lets unauthenticated attackers read config files. In common Jira and Crowd setups, reading crowd.properties exposes plaintext credentials and can lead to a full takeover. The flaw is being exploited in the wild.

🗞️ Stealthy BPFDoor & AVERAT Implants Target the Network Edge via SMTP Evasion (Rapid7) – These implants disguise themselves as regional security products such as SpamSniper. They hide triggers in padded HTTPS POST requests and tunnel commands over HTTP and SMTP to slip past DPI on telco and embedded edge devices. 🔎 Threat Hunting Package

🗞️ Canto Incognito: Tracking the New PoeLLM Malware Campaign (Black Lotus Labs) – PoeLLM compromises exposed LiteLLM, Ollama, Gotenberg, and Gitea servers to mine cryptocurrency and scan for more targets. It finds its C2 server by translating a poem hosted on GitHub into an IP address. 🔎 Threat Hunting Package

Recommendations

☑️ Patch internet-facing systems immediately: on-prem SharePoint, self-managed Atlassian, and exposed AI/LLM services. Inventory and lock down anything self-hosted that doesn’t need to be public.

☑️ Hunt for signs of exploitation. Look for :: traversal in access logs, deleted-but-running binaries (e.g., ntpdate or udevds in /sbin), padded HTTP requests or SMTP beaconing from embedded devices, kernel driver abuse, and staging in SYSVOL.

☑️ Rotate any credentials or secrets stored in config files that may have been exposed. Watch for living-off-the-land tools and unexpected remote access channels such as VS Code tunnels.

☑️ Apply strict egress filtering and zero-trust policies to edge appliances, and back them with XDR coverage across endpoints and domain controllers.

Theme 5: Geopolitics, Law Enforcement & Accountability

Stories

🗞️ Key ShinyHunters Hacker Detained in Jordan and Cooperating with FBI (Reuters) – Saif al-Din Khader was detained after the group breached 2–3 TB of FBI personnel records through an Oracle PeopleSoft flaw. His cooperation is already forcing ShinyHunters’ channels and leak sites offline.

🗞️ Justice Department & FBI Seize China-Linked Hacking Tools (U.S. Department of Justice) – The DOJ and FBI seized the “Microscan” scanner and “FishHub” spear-phishing tool run by Integrity Technology Group. The case shows how heavily the PRC relies on contractors to build out its cyber capabilities.

🗞️ Ransomware Recovery CEO Indicted for Fraudulent Decryption Scheme (BleepingComputer) – MonsterCloud’s CEO allegedly paid ransoms in secret while claiming to use proprietary recovery technology, charging victims more than $19M. The “recovery proofs” shown to victims were actually decrypted samples supplied by the ransomware operators.

🗞️ The “Putin Tax”: Russian Cyber Attacks Cost the UK Up to £2.5 Billion Annually (Graeme Downie MP) – This is the first attempt to put a number on the national economic cost of state cyber hostility: £2–2.5B a year, with a single major attack on critical infrastructure potentially costing £3.3B.

🗞️ UK and Germany Launch Joint Defense Partnership to Counter Russian Cyberattacks and Sabotage (Gov.uk) – Building on the Kensington Treaty, Europe’s two largest defense spenders will share intelligence and run joint disruption operations against hybrid threats to critical infrastructure.

Recommendations

☑️ Turn government action into detections. Review the FBI advisory on Integrity Tech for IoCs, follow national security briefings, and track the TTPs of extortion and breach groups in your threat intelligence program.

☑️ Patch ERP and HR systems such as Oracle PeopleSoft. Use DLP and database query monitoring to catch bulk exfiltration of sensitive personnel data.

☑️ Quantify your exposure to state-backed disruption with operational impact assessments, catastrophe risk modeling, and severe-scenario stress tests. Strengthen OT resilience through segmentation and continuous monitoring.

☑️ Vet incident response and recovery vendors before you need them. Demand transparency about their methods and any contact with threat actors, and join public-private sharing and joint IR arrangements.


Feature Video

The question I get most about the CTI-CMM: “Where do I even start?”

Here’s the short version. Three tools, three jobs:

1. The official CTI-CMM Assessor. A free, open-source spreadsheet on GitHub. It’s the ground truth, and the evidence column is the whole game. If you can’t link to a documented, repeatable process, you haven’t reached CTI 1.

2. Cosive’s web app. A browser-based version with a planning mode that plots domains by impact vs. effort. It also has a client-side version, so scores never leave your machine. Useful if legal won’t let maturity data touch a vendor’s servers.

3. A custom AI skill. It takes the grind out of gathering evidence across 230 statements. It speeds up the work but doesn’t replace human sign-off.

✅️ The assessor tells you what evidence you need.

✅️ Cosive gives you a plan you can present.

✅️ The AI skill gives you the speed to do both without burning a whole quarter on data entry.

Nobody on a leadership team wants to see 230 rows. They want a roadmap, milestones, and a plan to get there.

I walk through all three in the video!

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools