Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top 10 News Stories

Linux-Based Lenovo Webcams Vulnerable to Remote BadUSB Attacks
A critical flaw in Lenovo’s Linux-based webcams allows attackers to remotely reflash the device’s firmware, turning it into a malicious BadUSB device. This vulnerability, codenamed BadCam, enables keystroke injection and malware delivery without physical access.
Key takeaways:
🚨 Remote Exploitation: Attackers with initial access to a system can remotely hijack Lenovo 510 FHD and Performance FHD webcams by exploiting a lack of firmware validation.
⌨️ BadUSB Attacks: The compromised webcam can act as a malicious USB device, injecting keystrokes, delivering malware, and creating persistent access to the host system.
🔒 Firmware Updates Crucial: Lenovo has released firmware version 4.8.0 to patch the vulnerability. Users are urged to update their devices immediately to prevent exploitation.
🛡️ Peripheral Security Risk: This incident highlights the security risks posed by peripherals with their own operating systems, emphasizing the need for robust firmware security and regular updates.
Researchers Uncover GPT-5 Jailbreak and Data Exfiltration Vulnerability
A new “jailbreak” technique bypasses GPT-5’s ethical safeguards by combining the “Echo Chamber” method with narrative-driven steering, enabling it to generate illicit instructions. This vulnerability also creates a risk of zero-click attacks that can exfiltrate data from connected cloud services.
Key takeaways:
🚨 Advanced Jailbreak: Attackers can manipulate AI models by creating a biased conversational context (“Echo Chamber”) and using storytelling to steer the AI toward generating harmful or forbidden content without explicit prompts.
🌐 Wider AI Threat: This vulnerability is not exclusive to GPT-5. The technique highlights a significant challenge for the entire AI industry, as similar methods can be used to compromise other large language models.
🔓 Zero-Click Data Theft: A new attack vector, dubbed “AgentFlayer,” can exploit AI agents connected to cloud services. Through “indirect prompt injection,” attackers can potentially steal sensitive data, like API keys from a Google Drive, without any user interaction.
🛡️ Evolving Defenses Needed: Traditional security measures, such as simple keyword filtering, are proving insufficient against these sophisticated, context-aware attacks that unfold over multi-turn conversations.
💡 Proactive Security is Crucial: The findings emphasize the urgent need for developers to implement stronger, built-in security measures, including strict output filtering and continuous “red teaming,” to protect AI systems from manipulation.
Critical WinRAR Zero-Day Under Active Exploitation
A critical zero-day vulnerability in WinRAR is being actively exploited by hacking groups to install malware on target PCs. The flaw allows attackers to gain remote code execution by tricking users into opening a specially crafted RAR archive.
Key takeaways:
🚨 Path Traversal Flaw: The vulnerability is a path traversal issue that enables attackers to drop malicious files into sensitive locations, like the Windows Startup folder, ensuring the malware runs automatically.
🔒 Stealthy Infection: Attackers are using clever techniques, like hiding payloads in Alternate Data Streams (ADS), to evade detection when the malicious archive is opened.
💡 Manual Update Required: WinRAR does not have an automatic update function. This means users are not protected unless they manually download and install the latest patched version.
🛡️ Immediate Action Needed: All users should immediately update to WinRAR version 7.13 or newer to patch this vulnerability and prevent potential system compromise.
🌐 Popular Target: The widespread use of WinRAR makes it a high-value target for threat actors seeking to distribute malware broadly.
Phishing Attacks Evolve, Abusing Microsoft 365 Apps
Attackers are now using trusted Microsoft 365 applications like OneNote and OneDrive to launch “native phishing” campaigns. These attacks bypass traditional email security by sharing malicious files directly from compromised internal accounts, making them appear dangerously legitimate.
Key takeaways:
🚨 Trusted Apps as Weapons: Hackers are exploiting the inherent trust users have in Microsoft 365 apps like OneNote and OneDrive to launch attacks from within an organization.
🔒 Internal Account Takeover: The attack often begins with a single compromised account, which is then used as a launchpad to spread malicious files internally, making them appear to come from a trusted colleague.
💡 Bypassing Security: This “native phishing” technique is highly effective at bypassing standard email gateways and security filters because the malicious links are shared from a legitimate, internal source.
🛡️ Defense in Depth: To combat this threat, you must go beyond email security. Enforce multi-factor authentication (MFA), tighten file-sharing permissions, and train users to scrutinize even internal sharing requests.
🌐 AI-Powered Phishing Pages: Threat actors are leveraging AI-powered website builders to rapidly create convincing phishing pages that perfectly mimic legitimate company login portals.
Allianz Life Data Leaked by Hackers After Salesforce Breach
Hackers have leaked 2.8 million records belonging to customers and business partners of Allianz Life. The data was stolen from the company’s Salesforce cloud environment as part of a wider campaign by the ShinyHunters extortion group.
Key takeaways:
🔑 Social Engineering for Access: Attackers used social engineering to trick an employee into granting a malicious OAuth application access to the company’s Salesforce instance, leading to the data theft.
👥 Cybercrime Collaboration: The attack is attributed to a collaboration between the notorious ShinyHunters, Scattered Spider, and Lapsus$ hacking groups.
📄 Sensitive Data Exposed: The leaked data includes a vast amount of sensitive information, including names, addresses, phone numbers, dates of birth, and Tax Identification Numbers.
☁️ Cloud Platform Targeted: This incident is part of a larger, ongoing campaign specifically targeting companies that use Salesforce for their customer relationship management.
🛡️ Third-Party App Risk: The attack highlights the critical need for organizations to scrutinize and control third-party applications and their access to sensitive corporate data in cloud environments.
XZ Backdoor Still Lurking in Docker Hub Images
Over a year after its initial discovery, the highly sophisticated XZ Utils backdoor is still present in numerous Docker Hub images, posing a continued supply chain risk. Researchers have found that the vulnerability is propagating as developers unknowingly use these infected base images to build new applications.
Key takeaways:
🌐 Persistent Threat: The XZ Utils backdoor (CVE-2024-3094) has been discovered in at least 35 different Docker Hub images, highlighting the lingering danger of this critical supply chain attack.
🔄 Silent Propagation: The vulnerability spreads transitively through the software supply chain as new Docker images are built upon compromised base images, creating a cascading security risk.
🚨 Sophisticated Origins: This was a state-sponsored attack where the threat actor, “Jia Tan,” infiltrated the open-source project over two years to plant the backdoor, which allows for remote code execution via SSH.
🛡️ Container Risk: Despite some maintainers considering the risk low in containerized environments, the presence of a network-reachable backdoor represents a significant threat that cannot be ignored.
🔍 Action Required: This discovery emphasizes the urgent need for continuous, binary-level monitoring of software artifacts to detect and mitigate such threats, as simple version checks are not enough.
New Downgrade Attack Bypasses FIDO Authentication in Microsoft Entra ID
A recently discovered vulnerability allows attackers to bypass FIDO-based multi-factor authentication in Microsoft Entra ID using a sophisticated downgrade attack. This method could expose organizations to adversary-in-the-middle (AiTM) attacks, undermining the security of what is considered a highly secure authentication standard.
Key takeaways:
🔒 A novel “downgrade attack” can circumvent FIDO-based authentication, one of the most secure forms of MFA.
🚨 The attack utilizes a custom “phishlet” to trick the system into using a less secure authentication method, opening the door for AiTM attacks and session hijacking.
💡 While this vulnerability is a significant concern, researchers have not yet observed it being exploited in the wild.
🛡️ Despite this new threat, FIDO-based authentication remains a highly recommended and effective method for protecting against most credential phishing and account takeover attempts.
🌐 It is crucial for organizations to stay informed about evolving threats and ensure their security protocols are up-to-date to defend against such sophisticated attacks.
Spike in Fortinet VPN Brute-Force Attacks Raises Zero-Day Concerns
Cyber security researchers are warning of a significant increase in brute-force attacks targeting Fortinet VPNs, sparking fears of a potential new zero-day vulnerability. The attacks are widespread and indiscriminate, targeting a variety of industries with generic usernames.
Key takeaways:
🔒 Massive Attack Volume: A distributed botnet is behind a high volume of brute-force attempts against Fortinet SSL-VPN services.
🚨 Zero-Day Speculation: The sudden and widespread nature of the attacks suggests that threat actors might actively exploit a previously unknown vulnerability.
💡 Generic Usernames Targeted: The attacks are using common usernames like “admin,” “administrator,” and “root,” indicating a broad, non-targeted approach.
🛡️ Immediate Action Required: Fortinet administrators are strongly advised to investigate their logs for compromise indicators, disable inactive user accounts, and enforce multi-factor authentication (MFA).
🌐 Stay Vigilant: Security teams must monitor for any unusual login activity and apply all available security patches to mitigate potential risks.
Critical Infrastructure Under Siege: Pro-Russian Hackers Target Norwegian Dam
Pro-Russian hacking groups are now being implicated in the sabotage of a water dam in Norway, demonstrating a significant and concerning escalation in cyber warfare tactics. This incident highlights the increasing willingness of state-affiliated actors to target critical infrastructure to sow fear and disrupt essential services.
Key takeaways:
🌊 Vulnerable Infrastructure: The attack, which involved remotely opening a dam’s control valves, proves that even physical infrastructure is highly vulnerable to cyber-attacks.
💻 State-Sponsored Threats: Norwegian authorities have pointed to pro-Russian hackers, indicating a potential hybrid warfare strategy aimed at destabilizing Western nations.
💡 Beyond Data Theft: The objective appears to be shifting from data exfiltration to causing real-world disruption and psychological impact, aiming to create chaos and fear.
🛡️ Urgent Need for Resilience: This event is a stark reminder for all critical sectors to reassess and bolster their operational technology (OT) and industrial control system (ICS) security.
🌐 Global Implications: The incident in Norway is part of a broader pattern of escalating cyber-attacks against critical infrastructure across Europe and North America.
New Phishing Scam Targets Booking.com Users With Sneaky Characters
A sophisticated phishing campaign is targeting Booking.com customers with deceptive emails that lead to malware infection. Attackers are using a clever trick involving a special character in URLs to make malicious links look like legitimate ones from Booking.com, redirecting users to fake sites that install infostealing malware.
Key takeaways:
💡 Deceptive URLs: The scam uses the Japanese hiragana character ‘ん’, which visually resembles ‘/n’, to create convincing but fake URLs that trick the eye.
🚨 Malware Delivery: Clicking on these deceptive links redirects victims to a lookalike domain that automatically downloads a malicious installer, leading to malware and credential theft.
🔒 Verify Before You Click: Always hover your cursor over links in emails, regardless of how legitimate they appear, to preview the actual destination URL before clicking.
🛡️ Stay Vigilant: Phishing attacks are becoming increasingly sophisticated. Be wary of unsolicited emails requesting you to log in or verify account details.
🌐 Direct Navigation is Safest: When in doubt, avoid clicking links in emails altogether. Manually type the website address (e.g., booking.com) directly into your browser to access your account securely.
Top Tips of the Week

Threat Intelligence
- Implement threat intelligence metrics. Track the effectiveness of your intelligence efforts and adjust strategies accordingly.
- Test threat intelligence in tabletop exercises. Simulate scenarios to enhance readiness and identify areas for improvement.
- Foster a threat intelligence sharing culture. Encourage information exchange within your organization and with external partners.
- Incorporate CTI into risk management strategies. Identify and prioritize potential risks based on real-time threat intelligence.
Threat Hunting
- Create a cyber threat hunting roadmap. Define strategies for integrating and optimizing cyber threat hunting processes.
Custom Tooling
- Use modular design principles in custom tool development. Modular components enhance maintainability and scalability.
- Create custom tools with extensibility in mind. Design solutions that can easily adapt to future changes and evolving requirements.
Feature Article

As a cyber threat intelligence (CTI) analyst, there is immense pressure to make fast, accurate judgments. In this high-stakes environment, it’s tempting to rely on gut feelings and past experiences to cut through the noise. But intuition is not enough. It is plagued with cognitive biases that lead to critical intelligence failures. You need a structured analytic technique!
Structured analytic techniques (SATs) provide the scaffolding for your expertise, ensuring your judgments are as rigorous as they are insightful. This guide will demystify the world of SATs, showing you how these simple, methodical processes can sharpen your analysis.
We’ll explore the core categories of techniques and explain how to choose the right one for your intelligence needs. Let’s get started!
Feature Course
Learning Resources

Investigating Insider Threats With Digital Forensics
Is your team equipped to handle an insider threat?
It’s not just about monitoring logs; it’s about conducting in-depth analysis of digital forensics to uncover malicious behavior.
🕵️♂️ Forensic Process is Key: The investigation starts with solid evidence collection. Following the order of volatility and maintaining the chain of custody is crucial to building a strong case.
💻 Know Your Artifacts: The real story is hidden in Windows artifacts. Memory images, the NTFS file system, the Windows Registry, and event logs are your primary sources of truth.
🔧 Tools of the Trade: A skilled investigator is only as good as their tools. The video highlights essentials like Arsenal Image Mounter, KAPE Parser, and Eric Zimmerman’s tools for effective analysis.
📈 Real-World Case Study: Watch a live investigation of a COO suspected of data exfiltration, uncovering evidence through ShellBags, ActivitiesCache.db, and Google Drive forensics.
This video breaks down how to apply Windows forensics to investigate and uncover insider threats.
AI Agent-Driven Detection
Is your security team drowning in a sea of alerts from detection rules you can’t even decipher?
It’s time to trade in the frustration for a smarter, AI-powered approach to detection engineering. This excellent video from AttackIQ breaks down this new agent-driven methodology:
🕵️ Interpret: Get plain English explanations of cryptic detection rules, their context, and MITRE ATT&CK techniques.
✅ Validate: Confirm your rules work against real-world attacker behaviors by finding or crafting the right test content and scenarios.
📏 Measure: Assess rule performance over time to manage “detection debt” and shrink attacker dwell time.
✍️ Generate: Create better detection rules faster by extracting insights from threat intelligence and using AI to build new rules.
Watch now to see how an agent-driven approach can help you interpret, validate, measure, and generate better detections faster.



