Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top 10 News Stories

Supply Chain Attack: Malware Injected Into Popular NPM Packages
A sophisticated phishing campaign has compromised several popular npm packages, injecting malicious code that could lead to remote code execution on developer machines. This highlights the ongoing threat of supply chain attacks targeting the open-source ecosystem.
Key takeaways:
🚨 Phishing Campaign: Attackers impersonated npm to steal developer credentials through a typosquatted domain, gaining access to publish malicious package versions.
🔒 Affected Packages: eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, and napi-postinstall were all compromised. Developers should immediately verify the versions they are using.
🛡️ Enable 2FA: This incident underscores the critical importance of enabling two-factor authentication on all developer accounts to prevent unauthorized access.
💡 Scoped Tokens: Project maintainers should use scoped tokens for publishing packages. This limits the potential damage if a token is compromised.
🌐 Vigilance is Key: This attack, along with other recent incidents involving protestware and RATs in package repositories, demonstrates the need for constant vigilance and security best practices within the development lifecycle.
CrushFTP Zero-Day: Unpatched Vulnerability Actively Exploited to Hijack Servers
Zero-day vulnerability in the CrushFTP managed file transfer solution is being actively exploited by attackers to escape the user’s virtual file system and download system files, including those containing plaintext passwords and credentials. This flaw enables complete server takeover, posing a significant threat to organizations that use this software.
Key takeaways:
🚨 Active Exploitation: This is not a theoretical vulnerability. Attackers are actively using it in the wild to compromise servers and steal sensitive data.
🔒 Total Server Compromise: The vulnerability allows attackers to bypass security restrictions and gain full control over the underlying server, enabling them to read and write files anywhere on the system.
🛡️ No Patch Available: As a zero-day, there is currently no official patch from the vendor. This makes mitigation and detection efforts even more critical.
💡 Mitigation Steps: The article highlights temporary mitigation measures provided by the security researchers who discovered the flaw, which can help protect systems until a patch is released.
🌐 Immediate Action Required: Administrators of CrushFTP servers must take immediate action to apply the suggested mitigations and monitor their systems for any signs of compromise.
New SharePoint Zero-Day “ToolShell” Exploited in the Wild
A critical zero-day vulnerability, dubbed “ToolShell” (CVE-2025-53770), is being actively exploited in on-premise Microsoft SharePoint servers. This flaw allows unauthenticated attackers to achieve remote code execution (RCE), giving them full control over vulnerable systems.
Key takeaways:
🔒 Critical Vulnerability: The “ToolShell” vulnerability (CVE-2025-53770) has a CVSS score of 9.8, making it a critical threat to unpatched on-premise SharePoint servers.
🚨 Active Exploitation: Threat actors are already using this zero-day to target organizations, with evidence of widespread exploitation attempts. High-value targets in technology, manufacturing, and critical infrastructure have been identified.
💡 Bypassing Previous Patches: This vulnerability is a bypass of a previously patched issue (CVE-2025-49704), highlighting the attackers’ ability to adapt and find new ways to exploit systems.
🛡️ Immediate Action Required: Organizations using on-premise SharePoint servers are urged to apply the latest security updates from Microsoft immediately. If patching isn’t possible, consider disconnecting affected servers from the internet.
🌐 Not an Online Threat: Fortunately, SharePoint Online (Microsoft 365) is not affected by this specific vulnerability.
ExpressVPN Bug Leaks User IPs in Remote Desktop Session
A significant flaw has been discovered in the ExpressVPN Windows client, allowing Remote Desktop Protocol (RDP) traffic to bypass the VPN tunnel and expose users’ actual IP addresses. This bug undermines the core privacy promise of a VPN service.
Key takeaways:
🔒 IP Leak: The vulnerability allowed TCP traffic on port 3389, used by RDP, to bypass the VPN, revealing users’ true IP addresses to ISPs or anyone on the same network.
🚨 Production Code Flaw: The issue stemmed from debug code that was mistakenly included in production builds of the ExpressVPN Windows client, specifically versions 12.97 to 12.101.0.2-beta.
💡 Patch Available: ExpressVPN has released a patch in version 12.101.0.45. All Windows users are strongly advised to update their clients to the latest version to ensure their privacy is protected.
🛡️ Encryption Unaffected: While the IP leak is a serious issue, ExpressVPN has stated that the encryption of the VPN tunnel itself was not compromised.
🌐 Limited User Base Impacted: The company believes the number of affected users is likely small, as RDP is more commonly used in enterprise environments than by typical consumers.
“PoisonSeed” Hackers Devise New Method to Bypass FIDO Keys
A new threat actor group, dubbed “PoisonSeed,” has developed a sophisticated technique to bypass FIDO security keys by exploiting the cross-device sign-in feature through QR code phishing. This attack highlights a critical vulnerability in how some systems implement FIDO, putting user accounts at risk.
Key takeaways:
🔒 QR Code Phishing: The attack tricks users into scanning a malicious QR code on a fake login page, which then authorizes the attacker’s login session on a separate device.
🚨 Exploiting a Feature: “PoisonSeed” doesn’t break the FIDO protocol itself but abuses the “hybrid transport” method for cross-device logins, especially when proximity checks like Bluetooth are not enforced.
💡 Persistence is Key: Once initial access is gained, the attackers have been observed enrolling their own FIDO keys to maintain persistent and authorized access to the compromised accounts.
🛡️ Defense in Depth: To mitigate this threat, organizations should enforce proximity checks for FIDO authentication, encourage same-device logins, and monitor for suspicious QR code-based sign-ins and new passkey enrollments.
🌐 Context is Crucial: Login screens for cross-device sign-ins should provide more contextual information, such as the location and device type of the login attempt, to help users spot malicious activity.
Lumma Infostealer Disrupted, But The Fight Isn’t Over
A major law enforcement operation has taken down the infrastructure of the prolific Lumma infostealer malware. While this is a significant victory, the threat of data-stealing malware remains high as cybercriminals look to rebuild and adapt.
Key takeaways:
🚨 Lumma’s reach: This malware-as-a-service (MaaS) was a go-to tool for cybercriminals, enabling widespread theft of sensitive data.
🌐 Global takedown: A coordinated effort by international law enforcement and tech giants like Microsoft successfully dismantled Lumma’s core infrastructure.
🛡️ Resilience of threats: The cybercrime ecosystem is adaptable. The takedown of one threat often leads to the rise of another. Stolen data may still be in circulation.
💡 Stay vigilant: Infostealers like Lumma spread through phishing, malvertising, and social engineering. Constant awareness is your best defense.
🔒 Protect yourself: Use unique, strong passwords, enable MFA, and be cautious of unsolicited links and downloads to protect your digital identity.
New ‘Coyote’ Malware Exploits Windows Accessibility for Stealthy Data Theft
A new banking trojan, dubbed ‘Coyote’, is leveraging a novel technique to steal financial credentials by abusing the Windows UI Automation (UIA) framework. This allows the malware to monitor user activity and identify when to strike without being detected by traditional security tools.
Key takeaways:
🌐 New Threat Vector: Coyote is the first observed malware to abuse the Windows UIA accessibility feature for malicious reconnaissance, a previously theoretical attack method.
🎯 Targeted Attack: The malware is currently focused on stealing credentials from 75 specific banking and cryptocurrency applications, primarily targeting users in Brazil.
🛡️ Evasion Tactics: By using a legitimate Windows framework, Coyote can inspect browser tabs and address bars to identify targets while evading detection from endpoint security solutions.
💡 Future Implications: While now used for spying, this technique could evolve to directly steal credentials as they are typed, representing a significant future threat.
🔒 Stay Alert: This evolving threat highlights the importance of multi-layered security and staying vigilant against unexpected application behavior, even from trusted system features.
UK Government to Outlaw Ransomware Payments for Public Sector
The UK is taking a hard stance against cybercrime, announcing a ban on ransomware payments for all public sector and critical national infrastructure organizations. This move aims to disrupt the business model of ransomware gangs by making essential services less attractive targets.
Key takeaways:
🚫 No More Payouts: Public bodies like the NHS, schools, and local councils will be legally prohibited from paying ransoms to cybercriminals.
📝 Mandatory Reporting: Businesses not covered by the ban will now be required to notify the government of any intent to pay a ransom, promoting greater transparency and enabling support.
💥 Disrupting the Model: The core goal is to slash the profitability of ransomware attacks on UK essential services, thereby reducing the incentive for criminals to target them.
🤔 A Contentious Move: While a decisive step, security experts are divided. Some fear this could lead to under-reporting of attacks or simply shift the burden to organizations that are unprepared for lengthy recovery processes without the option to pay.
🛡️ Focus on Resilience: This policy underscores the critical need for robust cybersecurity defenses, offline backups, and well-rehearsed incident response plans for all organizations.
Suspected Admin of Major Russian Hacking Forum Arrested in Ukraine
In a significant blow to the cybercrime underworld, Ukrainian authorities, in collaboration with French law enforcement and Europol, have arrested the suspected administrator of the notorious Russian-language hacking forum, XSS.is. The forum’s domains have also been seized, disrupting a major hub for illicit cyber activities.
Key takeaways:
🚨 Major Takedown: The arrest and seizure of XSS.is, a forum with over 50,000 users, represents a major victory for international law enforcement against organized cybercrime.
🌐 International Cooperation: This successful operation underscores the crucial importance of cross-border collaboration among law enforcement agencies in combating global cyber threats.
🔒 End of an Era?: XSS.is, formerly known as DaMaGeLab, has been a long-standing fixture in the cybercrime ecosystem. Its takedown will have a significant and lasting impact on the Russian-speaking hacker community.
🛡️ No Safe Haven: This action sends a clear message to cybercriminals that there are no safe havens, and international law enforcement will continue to pursue and dismantle their operations.
💡 Shifting Landscape: The removal of a major player like XSS.is will likely lead to a shift in the cybercrime landscape as threat actors seek alternative platforms. We must remain vigilant in monitoring for new and emerging threats.
Threat Actor “Mimo” Evolves, Now Targeting Magento and Docker
The threat actor known as Mimo (or Mimo’lette), previously observed targeting Craft CMS, has significantly evolved its tactics to include Magento ecommerce platforms and misconfigured Docker instances. This actor utilizes sophisticated techniques to remain undetected while monetizing compromised systems through cryptojacking and proxyjacking.
Key takeaways:
♻️ Evolving Threats: Mimo has expanded its target scope from Craft CMS to now include Magento and Docker, demonstrating a significant evolution in its capabilities and a broader threat to the e-commerce and web hosting sectors.
💻 In-Memory Evasion: The actor employs advanced evasion techniques, executing malware directly in memory to bypass traditional file-based security tools, making detection significantly more challenging.
💰 Dual Monetization: Mimo maximizes its illicit profits by simultaneously using victims’ CPU resources for cryptocurrency mining (cryptojacking) and selling their bandwidth on residential proxy networks (proxyjacking).
🛡️ Vulnerability Exploitation: The initial access is gained by exploiting known vulnerabilities in PHP-FPM and various Magento plugins, reinforcing the critical need for timely patching and security updates.
🌐 Diversified Attacks: The addition of Docker environments to their target list shows Mimo’s willingness to compromise a wide range of services, increasing the potential attack surface for many organizations.
Top Tips of the Week

Threat Intelligence
- Incorporate geopolitical intelligence. Understand global events that may impact cyber threats to enhance strategic decision-making.
- Monitor supply chain risks with threat intelligence. Assess and address vulnerabilities to mitigate potential threats.
- Consider geopolitical factors in CTI analysis. Understand global events’ impact on cyber threats for more informed decision-making.
Threat Hunting
- Conduct threat intelligence awareness sessions in cyber threat hunting. Ensure that all team members understand the value and application of threat intel.
- Validate threat intelligence. Ensure the accuracy and relevance of information for informed cyber security decisions.
- Diversify your threat intelligence sources. A variety ensures a comprehensive understanding of potential threats.
- Validate threat intelligence. Ensure accuracy and relevance for informed cybersecurity decisions.
Feature Article

Defenders are often stuck in a reactive loop. We’re chasing alerts, patching vulnerabilities, and trying to keep up with adversaries who are constantly changing their attacks. The sheer volume of noise from traditional security tools can be overwhelming, leading to alert fatigue and letting real threats slip through the cracks. What if you could change the game entirely?
Instead of building taller walls, turn your network into a minefield for hackers with cyber detection!
This guide will explore how deception technology works and why it’s essential for modern defense. We’ll take a deep dive into the Acalvio ShadowPlex platform, an industry-leading solution that uses AI to create a dynamic and intelligent active defense, turning the hunter into the hunted.
Let’s jump in!
Feature Course
Learning Resources

Tailscale 101
Ever wondered if your VPN could do more than just connect devices? 🤔 Tailscale isn’t just a VPN; it’s a cyber security game-changer!
I use it to secure access to my homelab, transfer files between, and connect to clients worldwide to securely conduct cyber operations. This excellent video breaks down five exciting use cases for Tailscale you can start today.
Key Takeaways:
🌍 Broad Compatibility: Install Tailscale on almost any OS – from your phone to your cloud VPS!
🤖 Programmatic Management: Automate your network with Model Context Protocol (MCP) for seamless control.
🚀 CI/CD Integration: Simplify deployments and manage SSH keys effortlessly within your pipelines.
🔒 Simplified SSH: Ditch the key rotations! SSH into any node with ease using Tailscale’s built-in solution.
🌐 Expose Local Services: Securely share local web servers with automatic HTTPS, even across different networks.
I highly recommend watching it and getting started with Tailscale today to start securing your tools, automations, and access requirements.
Mastering Google Dorking and OSINT
🕵️♀️ Are you truly leveraging the internet’s power for cyber security reconnaissance? This week’s Just Hacking Training with The Security Rex revealed some mind-blowing techniques!
The episode covers:
🔍 Google Dorking: Uncover hidden gems like exposed admin portals, confidential PDFs, and even live webcams with advanced search queries.
🌐 Shodan Mastery: Explore internet-connected devices, from creepy open webcams to industrial control systems and vulnerable RDP logins.
💡 Actionable Insights: Learn how these recon methods directly enhance your penetration tests, red team engagements, and bug bounty hunts.
⚠️ Golden Rule: Always remember to “just look, not touch” when exploring publicly available information.
An excellent breakdown of key OSINT techniques that delivers insights even an expert investigator will find enlightening. Shout out to John Hammon and Bailey Marshall for the live stream!



