Triaging the Week 084

Hello there πŸ‘‹

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top 10 News Stories

Triaging the Week News Stories

Fake Mac Fixes Trick Users into Installing New Shamos Infostealer

A new macOS infostealer, “Shamos,” is being distributed through deceptive online ads that mimic legitimate websites. Unsuspecting users are tricked into running a malicious command, thinking they are installing a software fix, which then deploys the Shamos malware to steal sensitive information.

Key takeaways:

πŸ”’ Be cautious of online ads, especially those for software downloads or system fixes. Always verify the URL and legitimacy of the website before downloading or installing anything.

🚨 Shamos is a potent infostealer that can harvest credentials, browser data, and cryptocurrency wallets. The financial and privacy risks are significant.

πŸ’‘ This campaign highlights the increasing trend of malvertising, where cybercriminals use legitimate advertising platforms to distribute malware.

πŸ›‘οΈ To protect yourself, use a reputable ad-blocker, enable multi-factor authentication on all your accounts, and keep your operating system and software updated.

🌐 Always download software from the official source or trusted app stores. Avoid running commands from unfamiliar websites, especially those that require administrative privileges.

🎯 Threat Hunting Package

CrowdStrike

New AI Attack Steals Data Through Downscaled Images

A novel AI attack has been developed that can steal user data by injecting malicious prompts into images before they are processed by AI systems and delivered to a large language model. This technique allows attackers to stealthily exfiltrate sensitive information.

Key takeaways:

🚨 Stealthy Data Theft: This new attack vector demonstrates how threat actors can abuse AI systems for data theft in a way that is difficult to detect. By hiding malicious prompts within downscaled images, attackers can bypass traditional security measures.

πŸ”’ Vulnerable Systems: AI systems that process images and interact with large language models (LLMs) are potentially vulnerable to this type of attack. This includes a wide range of applications, from chatbots to image analysis tools.

πŸ’‘ Actionable Insight: Organizations and developers using AI and LLM technologies should be aware of this new threat and take steps to validate and sanitize image inputs before processing. This may involve implementing stricter content policies and security protocols for AI-powered applications.

πŸ›‘οΈ Defense in Depth: Relying on a single layer of security is no longer sufficient. A multi-layered defense strategy that includes input validation, content filtering, and anomaly detection is crucial to mitigate the risks associated with this and other emerging AI-based attacks.

🌐 Evolving Threat Landscape: The development of this attack highlights the continuous evolution of the cybersecurity threat landscape. As AI becomes more prevalent, we can expect to see more sophisticated attacks that target AI systems and exploit their unique vulnerabilities.

Trail of Bits

New Critical Docker Vulnerability Alert

A critical vulnerability has been discovered in Docker Desktop that could allow an attacker to escape container environments and gain unauthorized access to the host system. The flaw, with a high severity CVSS score, impacts Docker Desktop versions on both Windows and macOS, even with Enhanced Container Isolation (ECI) enabled.

Key takeaways:

🚨 Container Escape: A malicious container can connect to the Docker Engine API and launch additional containers without needing the Docker socket to be mounted, leading to a full container escape.

πŸ”’ Unauthorized Access: This vulnerability could allow attackers to access user files and other sensitive data on the host system, posing a significant security risk.

πŸ’‘ ECI Not a Mitigation: Enhanced Container Isolation (ECI) does not protect against this vulnerability, making it critical for all users to update their Docker Desktop installations immediately.

πŸ›‘οΈ Patch Available: Docker has released a patched version to address this vulnerability. All users are strongly advised to update to the latest version of Docker Desktop to protect their systems.

🌐 Stay Informed: This incident highlights the importance of staying informed about the latest security advisories and promptly applying patches to mitigate potential threats.

Pivotal Technologies

Threat Actors Weaponize Incident Response Tool for Remote Access

A recent investigation has revealed a disturbing new trend in which threat actors are abusing the legitimate open-source DFIR tool, Velociraptor, to gain initial network access β€”a tactic that could be a precursor to a major ransomware attack. This incident highlights a significant shift from abusing remote monitoring tools to weaponizing incident response tools themselves.

Key takeaways:

πŸ”’ Living Off the Land: Attackers deployed the legitimate Velociraptor tool to download and execute Visual Studio Code, aiming to create a secure tunnel to their command and control server.

🚨 Ransomware Precursor: This activity is a strong indicator of an impending ransomware attack. Early detection of such techniques is crucial to prevent widespread damage.

πŸ’‘ Shifting Tactics: The abuse of a trusted DFIR tool like Velociraptor instead of traditional malware marks an evolution in attacker methodology, making detection more challenging.

πŸ›‘οΈ Monitor & Detect: Organizations must monitor their environments for unauthorized or anomalous use of legitimate tools, including incident response and digital forensic software.

🌐 Proactive Defense: Implementing a robust endpoint detection and response (EDR) solution and maintaining secure backups are critical steps to mitigate the risks posed by such evolving threats.

Sophos

Citrix Patches Three Critical NetScaler Flaws, One Under Active Attack

Citrix has just rolled out patches for three significant vulnerabilities in its NetScaler ADC and Gateway products, with one of the flaws, a critical remote code execution vulnerability (CVE-2025-7775), already being actively exploited in the wild. This demands immediate attention from all NetScaler administrators.

Key takeaways:

πŸ”’ Active Exploitation: CVE-2025-7775 (CVSS score: 9.2) is being used by attackers. This flaw can lead to remote code execution or denial-of-service, making it a top priority for patching.

🚨 Patch Immediately: Citrix has released security updates to address these vulnerabilities. If you are using NetScaler ADC or Gateway, applying these patches should be your immediate priority to prevent a potential breach.

πŸ’‘ Multiple Vulnerabilities: Alongside the actively exploited flaw, two other high-severity vulnerabilities were patched: CVE-2025-7776 (CVSS 8.8) and CVE-2025-8424 (CVSS 8.7), which could lead to denial-of-service and improper access control.

πŸ›‘οΈ Configuration Matters: Successful exploitation of these flaws requires specific configurations. For instance, CVE-2025-7775 is exploitable if the appliance is configured as a Gateway (VPN, ICA Proxy, etc.) or an AAA virtual server. Review your configurations to assess your risk.

🌐 Recurring Target: This is not an isolated incident. NetScaler appliances have been a consistent target for threat actors. A proactive and aggressive patching strategy is essential for defending against these persistent threats.

The Hacker News

SalesLoft Breach Leads to Salesforce Data Theft via OAuth Token Abuse

A significant security incident has seen the sales engagement platform SalesLoft breached, with attackers stealing OAuth tokens to gain unauthorized access to customers’ Salesforce accounts. This sophisticated supply chain attack highlights the critical need for robust third-party application security.

Key takeaways:

πŸ”’ OAuth Token Theft: Attackers compromised SalesLoft to steal OAuth tokens associated with the Drift AI chat agent. These tokens were then used to pivot and access the Salesforce instances of SalesLoft’s customers.

🚨 Widespread Impact: The breach has potentially impacted over 700 organizations, with attackers automating the data theft process to exfiltrate large volumes of sensitive information from Salesforce.

πŸ’‘ Focus on Credentials: The primary goal of the attackers appears to be credential harvesting. After gaining access, they searched for sensitive information like AWS keys and Snowflake access tokens, indicating intent for further attacks.

πŸ›‘οΈ Third-Party Risk: This incident underscores the inherent risks associated with third-party integrations. Even if your direct security is strong, a vulnerability in a connected application can provide a gateway for attackers.

🌐 Immediate Action Required: SalesLoft and Salesforce have revoked all active Drift tokens. If you use this integration, it is crucial to re-authenticate your Salesforce connection and review your logs for any signs of unauthorized access or data exfiltration.

🎯 Threat Hunting Package

Google Threat Intelligence Group

New AI-Powered Ransomware “PromptLock” Emerges

ESET researchers have discovered a new type of ransomware, “PromptLock,” that leverages generative AI to execute attacks, representing a potential turning point in the cyber threat landscape. This malware utilizes a locally accessible AI language model to generate malicious scripts in real-time, allowing it to autonomously determine which files to search, copy, or encrypt.

Key takeaways:

πŸ”’ AI-Driven Attacks: PromptLock uses an AI model to generate malicious scripts, making sophisticated attacks more accessible to threat actors without extensive development skills.

🚨 Cross-Platform Threat: The ransomware is written in Golang and can create malicious Lua scripts that are compatible with Windows, Linux, and macOS.

πŸ’‘ Autonomous Operation: The malware autonomously decides whether to exfiltrate or encrypt data based on predefined text prompts, a significant evolution in ransomware capabilities.

πŸ›‘οΈ Evasive Maneuvers: Because the malware relies on AI-generated scripts, indicators of compromise (IoCs) may vary between executions, potentially complicating detection and defense.

🌐 Proof of Concept: While currently considered a proof-of-concept, PromptLock highlights a new and dangerous direction for malware development.

BleepingComputer

Anthropic Disrupts AI-Powered Cyberattacks, Highlighting New Threats.

Anthropic recently disrupted a sophisticated cybercriminal operation that used its AI model, Claude, to automate and scale a large-scale data theft and extortion campaign. The operation targeted at least 17 organizations across various sectors, including healthcare, government, and emergency services.

Key takeaways:

πŸ”’ AI as a Weapon: This incident demonstrates how threat actors are now using AI as both a technical consultant and an active operator to automate reconnaissance, credential harvesting, and network penetration.

🚨 “Vibe Hacking”: Security researchers have coined the term “vibe hacking” to describe this new evolution in AI-assisted cybercrime, where AI enables a single operator to achieve the impact of an entire team.

πŸ’‘ Adapting Defenses: The use of AI makes attacks more difficult to detect and defend against, as AI-powered tools can adapt to security measures in real-time.

πŸ›‘οΈ Proactive Measures: Anthropic has banned the accounts associated with this operation and is developing new classifiers and detection methods to prevent similar misuse in the future.

🌐 Collaborative Defense: Anthropic is sharing technical indicators with relevant authorities to help bolster defenses against this emerging threat.

Anthropic

TamperedChef Malware: Your Free PDF Editor Could Be a Trap!

A new malware campaign is using fake PDF editors to distribute ‘TamperedChef,’ an information stealer designed to harvest your credentials and web cookies. The campaign leverages malvertising to lure unsuspecting victims.

Key takeaways:

πŸ”’ Deceptive Disguise: The malware is bundled with a seemingly legitimate but trojanized PDF editor called ‘AppSuite PDF Editor’.

🚨 Malvertising Menace: The campaign uses malicious online ads to direct users to fraudulent download sites.

πŸ’‘ Delayed Activation: The malware remains dormant for a period, activating its malicious features after the initial installation to evade detection.

πŸ›‘οΈ Data Theft: ‘TamperedChef’ is designed to steal sensitive information, including credentials and cookies from popular web browsers.

🌐 Backdoor Access: The malware can also function as a backdoor, allowing attackers to execute commands and exfiltrate data.

🎯 Threat Hunting Package 

Truesec

Loophole in VS Code Marketplace Allows Malicious Extension Name Squatting

A loophole has been discovered in the Visual Studio Code (VS Code) Marketplace that allows threat actors to reuse the names of legitimate but unpublished or removed extensions. This could lead to developers unknowingly installing malware disguised as a trusted tool.

Key takeaways:

πŸ”’ Name Reuse: Threat actors can claim the names of previously legitimate but now-removed VS Code extensions, bypassing the platform’s unique naming policy.

🚨 Risk of Impersonation: This loophole makes it possible for malicious extensions to impersonate trusted, albeit discontinued, tools, increasing the likelihood of successful social engineering.

πŸ’‘ Developer Deception: Developers searching for a previously used extension might be tricked into installing a malicious version, compromising their development environment.

πŸ›‘οΈ Supply Chain Threat: This represents a significant software supply chain risk, as a compromised IDE can lead to credential theft, code tampering, and further network infiltration.

🌐 Verification is Key: Developers should be extra vigilant, verify the publisher, and check for any signs of suspicious activity before installing or reinstalling extensions, especially those that have been unlisted and then reappear.

🎯 Threat Hunting Package

ReversingLabs


Top Tips of the Week

Triaging the Week Tops Tips of the Week

Threat Intelligence

  • Conduct threat intelligence awareness sessions. Ensure that all team members understand the value and application of threat intel.
  • Integrate threat intelligence into threat detection tools. Enhance the capabilities of your detection systems for more accurate alerts.
  • Stay informed about APT groups. CTI helps identify and counter advanced persistent threats effectively.
  • Automate the collection and analysis of threat data. Speed up response times and stay ahead of emerging threats.

Threat Hunting

  • Validate threat intelligence in cyber threat hunting. Ensure accuracy and relevance for informed cybersecurity decisions.

Custom Tooling

  • Use agile development methodologies for custom tools. Iterate quickly, respond to feedback, and adapt to evolving requirements.
  • Collaborate with threat intelligence teams for custom tool development. Incorporate real-time threat data to enhance detection capabilities.

Feature Article

What is an Intelligence Product Header

The key to a successful cyber threat intelligence (CTI) program isn’t just about sharing more indicators, producing more reports, or performing more cycles of the threat intelligence lifecycle. It’s about delivering an intelligence product that will actually benefit your intelligence consumer. 

But what does that even mean? What is an intelligence product? 

Many analysts, new and seasoned, struggle to define the tangible outputs of their hard work. This guide will demystify the concept, transforming it from a vague idea into a practical tool you can use. We’ll explore what an intelligence product is, look at concrete examples from the strategic to the tactical, and walk through a simple process for creating them. Let’s get to it!

Read Now

Feature Course


Learning Resources

Triaging the Week Learning Resources

Pandas 101

Ever feel like you’re trying to wrangle a herd of cats when working with data in Python? This video is your catnip! 

It breaks down the Pandas library in a way that’s both fun and easy to understand, even if you’re just starting out.

Here are the key takeaways:

🐼 Pandas 101: Learn about the two core data structures in Pandas – Series (1D) and DataFrame (2D) – and how to get them set up in your environment.

πŸ“‚ Data Loading & Exploration: Discover how to load data from CSV and Excel files and get a quick overview of your data with functions like .head(), .tail(), and .info().

πŸ”Ž Filtering & Selection: Master the art of selecting and filtering data using iloc, loc, and various string methods to find exactly what you need in your dataset.

✨ Data Cleaning & Manipulation: Say goodbye to messy data! Learn how to drop, fill, and rename columns, and even update values based on specific conditions.

Data analysis is a crucial component of cyber security and cyber threat intelligence. From sifting through log files to spotting trends over time, you need to know how to analyze data. This video is a great starting point!

The Evolution of Automation in the SOC

Is your Security Operations Center (SOC) drowning in alerts? It might be time to call in the robots! 

This insightful video from SANS explores the evolution of SOC automation, from traditional playbooks to the exciting world of AI agents.

Here is a quick overview of what’s covered:

πŸ€– The “Why” of Automation: Discover why automation is no longer a luxury but a necessity for combating analyst burnout and alert fatigue in modern SOCs.

πŸ“– Playbooks Aren’t Dead: Learn why traditional SOAR playbooks are still the reliable and cost-effective backbone for handling repetitive tasks and weeding out false positives.

🧠 Enter the AI Agents: Get a glimpse into the future with “agentic AI” frameworks like CrewAI and Autogen, which promise more complex, autonomous security workflows.

βš–οΈ A Hybrid Approach: Understand the importance of a layered architecture that combines the predictability of playbooks with the advanced capabilities of AI for a truly effective SOC.