Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top 10 News Stories

Amazon Disrupts APT29 Watering Hole Attack
Amazon has successfully disrupted a watering hole campaign orchestrated by the Russian-linked threat actor APT29, also known as Cozy Bear. The attackers used compromised websites to redirect victims to malicious infrastructure, tricking them into authorizing attacker-controlled devices through Microsoft’s device code authentication flow.
Key takeaways:
😈 The Russian-linked APT29 group was behind a sophisticated watering hole attack.
💧 The campaign used compromised websites to redirect users to malicious infrastructure.
💻 The ultimate goal was to trick users into authorizing attacker-controlled devices via Microsoft’s device code authentication.
🛡️ Amazon’s security team detected and disrupted the campaign, highlighting the importance of proactive threat intelligence.
🔒 This incident underscores the continued threat posed by state-sponsored actors and the need for robust security measures to protect against such attacks.
Zscaler Data Breach Exposes Critical Customer Information via Third-Party Compromise
A recent supply-chain attack has led to a significant data breach at Zscaler, a prominent cloud security company. Threat actors compromised a third-party application, Salesloft Drift, to gain unauthorized access to Zscaler’s Salesforce environment, exposing sensitive customer data.
Key takeaways:
🔒 Supply-Chain Vulnerability: The breach originated from a compromised AI-powered chat application, Salesloft Drift, highlighting the critical risks associated with third-party integrations and the need for rigorous vendor security assessments.
🚨 OAuth Token Theft: Attackers exploited stolen OAuth tokens to bypass traditional authentication and gain persistent access to Zscaler’s Salesforce data, underscoring the importance of monitoring and controlling application permissions.
💡 Exposed Data: The compromised information includes customer names, email addresses, phone numbers, job titles, and commercial details, creating a high risk of targeted phishing and social engineering campaigns.
🛡️ Immediate Action Required: Organizations using Salesloft Drift are advised to immediately review and revoke unnecessary application permissions, rotate credentials, and audit all third-party integrations connected to their critical systems.
🌐 Broader Impact: The incident is part of a wider campaign targeting Salesforce customers, emphasizing the need for a holistic security approach that scrutinizes all connected applications and services.
Scammers Target UK-Bound Travelers with Fake ETA Websites
Cybercriminals are capitalizing on the UK’s new Electronic Travel Authorisation (ETA) system by creating fraudulent websites to deceive travelers. These scams range from charging excessive fees for legitimate ETAs to outright theft of personal and financial information.
Key takeaways:
🔒 Official Channels are Key: To avoid scams, only use the official UK government website (gov.uk) or the official UK ETA app to apply for your Electronic Travel Authorisation.
💸 Beware of Inflated Fees: The official cost for a UK ETA is a modest £10. Be immediately suspicious of any third-party site charging significantly more than this amount.
🎣 Phishing for Your Data: Many of these scam sites are designed to harvest your sensitive personal and payment information without ever providing the actual travel authorization.
🛡️ Verify Before You Click: Be cautious of sponsored links and top search engine results. Always double-check that you are on the official government website before entering any information.
🌐 No Official Expedited Service: Scammers may offer a faster, “expedited” service for an additional fee. The official process is typically very quick, so these offers are unnecessary and fraudulent.
Cloudflare Breached in Sophisticated Supply-Chain Attack
Cloudflare has been hit by a data breach stemming from a supply-chain attack targeting third-party vendors Salesloft and Drift. This incident allowed attackers to access Cloudflare’s Salesforce instance, exposing sensitive customer support data and API tokens.
Key takeaways:
🔒 Third-Party Risk is Real: The breach originated from compromised third-party applications, highlighting the critical need to vet and continuously monitor the security of all integrated services.
🚨 Rotate Your Secrets: Cloudflare has rotated the compromised API tokens, but they are urging customers to immediately rotate any credentials, passwords, or keys shared with their support team.
💡 Phishing is Evolving: The broader attack campaign utilized voice phishing and malicious OAuth applications, reminding us that threat actors are constantly refining their social engineering tactics.
🛡️ Proactive Defense is Key: Organizations must review and secure third-party integrations, especially those connected to sensitive systems, and educate employees on emerging threat vectors.
🌐 Widespread Campaign: This incident is part of a larger series of attacks targeting Salesforce customers, affecting other major tech companies and signaling a significant, ongoing threat.
Silver Fox Threat Actor Exploits Microsoft-Signed Driver
A new campaign by the threat actor dubbed “Silver Fox” has been identified, showcasing the abuse of a legitimate Microsoft-signed WatchDog driver to deploy the ValleyRAT malware. This technique allows the malware to bypass security measures by piggybacking on a trusted and verified component.
Key takeaways:
🔒 Abuse of Trust: Attackers are exploiting the trust placed in signed drivers, turning a security feature into a vector for compromise.
🚨 New RAT Variant: The campaign delivers ValleyRAT, a remote access trojan, giving attackers control over the infected systems.
💡 Defense Evasion: Using signed drivers is a sophisticated method to evade detection by endpoint security solutions that may trust any process initiated by a signed binary.
🛡️ Driver Monitoring is Crucial: Security teams must monitor for unusual driver installation and activity, even from trusted vendors, to detect this kind of abuse.
🌐 Constant Vigilance: This incident is a stark reminder that threat actors are continuously evolving their tactics to exploit even the most secure environments.
Palo Alto Networks Hit by Supply-Chain Attack, Customer Data Exposed
Cybersecurity giant Palo Alto Networks has disclosed a data breach resulting from a sophisticated supply-chain attack that compromised the Salesloft Drift application. The incident allowed threat actors to access the company’s Salesforce instance, leading to the exposure of customer business contact information and details from support cases.
Key takeaways:
🔒 Third-Party Integrations as a Weak Point: The breach originated from a compromised OAuth token in a third-party marketing and sales platform, underscoring the significant risks associated with interconnected SaaS applications.
🚨 Customer Data Exposed: Attackers accessed and exfiltrated business contact information, internal sales records, and the text comments within customer support cases.
💡 Attackers Were Hunting for Secrets: The primary objective of the threat actor was to comb through the stolen data searching for keywords like “password,” “secret,” and “key” to find credentials for further attacks.
🛡️ Urgent Action Required: Companies using the affected platforms are advised to immediately investigate their logs, revoke and rotate any potentially exposed credentials, and thoroughly review all third-party application integrations.
🌐 Wider Campaign Impact: This is not an isolated incident; it’s part of a broader attack campaign that has impacted hundreds of organizations, highlighting a systemic vulnerability in the SaaS ecosystem.
Threat Actors Weaponize X’s Grok AI to Spread Malicious Links
A novel attack vector has emerged on X (formerly Twitter), where threat actors are abusing the platform’s Grok AI to bypass security measures and amplify malicious links. This technique, dubbed “Grokking,” cleverly uses the AI’s functionality to lend credibility to scams and malware distribution campaigns.
Key takeaways:
🔒 Bypassing Security: Attackers are hiding malicious links in the metadata of video ads, a field that currently seems to evade X’s security scans.
🚨 AI as an Accomplice: They then prompt Grok with simple questions about the ad’s source. The AI dutifully extracts and posts the hidden malicious link in its reply.
💡 Abusing Trust: Because the link is shared by Grok, a trusted, official system account, users are more likely to click on it, significantly increasing the scam’s reach and effectiveness.
🛡️ User Vigilance is Crucial: Be extremely cautious with links in replies, even if they come from a verified or system account. Always scrutinize the context, especially if it relates to a suspicious-looking ad.
🌐 Platform Responsibility: This highlights a critical need for social media platforms to sanitize AI outputs and ensure all metadata fields are scanned for malicious content to prevent AI systems from being manipulated.
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws
A new AI-driven offensive security tool, HexStrike AI, has been rapidly weaponized by threat actors to exploit recently disclosed vulnerabilities in Citrix systems, in some cases within a week of public disclosure. This marks a significant acceleration in the threat landscape, as tools designed for legitimate security testing are immediately repurposed for malicious attacks.
Key takeaways:
🤖 AI as a Weapon: Offensive AI tools like HexStrike AI are being rapidly adopted by threat actors, significantly reducing the time from vulnerability disclosure to active exploitation.
⚡ Accelerated Attacks: The report from Check Point highlights that attackers are leveraging this tool to exploit Citrix flaws almost immediately after they are made public.
🛡️ Defense in the AI Era: This represents a new paradigm in cyberattacks. Defensive strategies must evolve to counter AI-driven reconnaissance and exploit development.
💡 Patching is Critical: The window for patching critical vulnerabilities is shrinking. Organizations must prioritize and accelerate their patch management processes to stay ahead of these AI-powered threats.
🌐 Open-Source Risks: While created for legitimate security testing, open-source offensive tools can be easily repurposed by malicious actors, demonstrating a significant dual-use risk.
Russian APT28 Hackers Deploy New “NotDoor” Outlook Backdoor
The notorious Russian state-sponsored group APT28 has unleashed a new stealthy backdoor called “NotDoor,” specifically targeting Microsoft Outlook in NATO countries. This sophisticated malware allows attackers to exfiltrate data, upload files, and execute commands by monitoring incoming emails for a specific trigger word.
Key takeaways:
🔒 Stealthy Outlook Integration: NotDoor operates as an obfuscated VBA macro within Outlook, enabling it to monitor emails and await commands from the attackers, all while disabling macro security warnings to remain undetected.
🚨 DLL Side-Loading: The malware is deployed using a DLL side-loading technique via Microsoft’s OneDrive executable, a method that helps it evade traditional security measures.
🛡️ Persistence is Key: NotDoor establishes persistence through Registry modifications and disables Outlook-related dialogue messages, ensuring it remains active and hidden on the compromised system.
🌐 Data Exfiltration: The backdoor supports commands to execute commands, exfiltrate files, and drop new files onto the victim’s machine, with stolen data being sent to a Proton Mail address.
Popular Android VPNs Unmasked: Security Flaws and Secret China Links Exposed
A new report reveals that many popular Android VPN apps on the Google Play Store have critical security flaws and are secretly operated by a Chinese company, putting millions of users’ data at risk. These apps were found to use hard-coded keys, allowing for user traffic to be intercepted and decrypted.
Key takeaways:
🚨 Critical Security Flaws: Many top Android VPNs use hard-coded passwords, making it possible for attackers to intercept and decrypt your private data, completely defeating the purpose of a VPN.
🇨🇳 Deceptive Ownership: Several of these VPN services are secretly owned by a single Chinese company, with some providers having links to a cybersecurity firm connected to the Chinese military.
🔒 False Privacy Promises: Despite privacy policies claiming otherwise, some of the investigated VPN apps were caught collecting and storing user location data.
💡 Research is Crucial: This investigation highlights the vast difference in quality and security among VPN providers. Always research a VPN’s reputation and ownership before trusting it with your data.
Top Tips of the Week

Threat Intelligence
- Regularly communicate CTI insights to stakeholders. Keep decision-makers informed to guide strategic security decisions.
- Use CTI to enhance threat intelligence platforms (TIPs). Leverage insights for continuous improvement and optimization of TIP capabilities.
Threat Hunting
- Understand the value of threat intelligence in penetration testing. Use insights to enhance real-world attack simulations.
Custom Tooling
- Implement continuous monitoring for custom tools. Proactively identify issues, assess performance, and ensure ongoing reliability.
- Consider the accessibility of custom tools. Design interfaces and functionalities that cater to users with diverse needs and requirements.
- Regularly review custom tool access controls. Ensure that permissions align with organizational roles and responsibilities.
- Understand your specific needs before creating custom tools. Tailor solutions to your unique challenges for optimal effectiveness.
Feature Article

So, you’ve built a Cyber Threat Intelligence (CTI) program. You’re neck-deep in indicators, you’re tracking threat actors, and you’re churning out reports. But when your CISO walks over and asks, “So… is it working? Are we more secure? Are we getting a return on this investment?”—Do you have CTI metrics to give a good answer and demonstrate success?
Too often, CTI teams become bogged down in the details, focusing on the volume of reports produced or indicators collected, rather than on the overall effectiveness of their work. While those numbers are part of the story, they don’t capture the most important things that business values: return on investment (ROI).
Proving your program’s worth can feel like trying to catch smoke.
This guide will help you cut through the noise. We’ll explore why measuring your program is critical, define what success actually looks like for your program, and break down the key CTI metrics you can use to prove your impact to everyone from the SOC analyst to the CEO. Let’s dive in!
Feature Course
Learning Resources

AI in the Terminal
Ready to ditch the manual grind and let AI supercharge your command line?
This video showcases Warp, an AI-powered terminal that revolutionizes the way developers, engineers, and cyber security professionals work.
Here’s a sneak peek at what you’re missing out on:
🤖 Autonomous Workflows: Imagine deploying applications, troubleshooting servers, and even writing new code without lifting a finger. Warp’s AI agent can handle it all.
🔒 Secure & Controlled: You set the rules. With customizable permissions, you have complete control over what the AI can and cannot do on your system.
🧠 Context is King: Warp’s AI understands the context of your project, making it a powerful pair programmer and an even better troubleshooter.
🖥️ SSH Savvy: All of Warp’s AI magic is available over SSH so that you can bring the power of AI to your remote servers.
AI in the terminal is a game-changer for cyber security professionals who need to sift through log files, analyze data, and access remote machines. No more trying to remember arcane CLI options!
Why is MFA Still Getting Defeated?
Is your MFA really as secure as you think?
This video from SANS Offensive Operations delves into the clever ways adversaries can bypass multi-factor authentication and offers some eye-opening takeaways.
In short:
📧 Phishing is still king: The human element remains the weakest link, with email being the preferred attack vector for social engineering.
🔍️ Tracking pixels are scarily effective: These tiny images can reveal a wealth of information about you, including your location, device, and even if you’re using an ad blocker.
🔑 Credential harvesting is becoming increasingly sophisticated: Attackers are utilizing frameworks like GoPhish to clone login portals and steal credentials, even when MFA is in place.
📱 MFA bypass techniques are evolving: From AI voice scams to SIM swapping and session hijacking, adversaries have a growing arsenal of tools to defeat MFA.
You need to understand how MFA is being bypassed to defend your organization better. Don’t miss this excellent deep dive!



