Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Critical Flaw in Microsoft Entra ID Exposed All Tenants
A critical vulnerability in Microsoft’s Entra ID could have allowed an attacker to take complete control of any company’s tenant, granting them Global Admin privileges. The flaw, which has since been patched, highlights the significant risks associated with legacy components in modern cloud services.
Key takeaways:
🔒 Total Takeover: The vulnerability could have allowed an attacker to manage users, reset passwords, and access all services authenticated through Entra ID.
🛡️ Stealthy Attack: The initial stages of the attack would not have generated any logs in the victim’s tenant, making detection extremely difficult.
💡 Legacy Systems Risk: The exploit relied on a combination of a legacy authentication service and a deprecated API, underscoring the dangers of outdated components.
🌐 Prompt Patching: Fortunately, the vulnerability was responsibly disclosed and promptly patched by Microsoft, preventing widespread exploitation.
Dirk-jan Mollema (Outsider Security)
North Korean Hackers Evolve “ClickFix” Tactic to Deliver Malware
North Korean-backed hacking groups are expanding their targets and refining their techniques, using an evolved social engineering tactic dubbed “ClickFix” to deliver a range of malware. These campaigns, no longer limited to software developers, are now targeting cryptocurrency and retail sectors.
Key takeaways:
🔒 Expanded Targeting: The threat has moved beyond developers to include marketing and trading roles, indicating a broader and more financially motivated strategy.
🛡️ Sophisticated Social Engineering: The “ClickFix” tactic tricks users into running malicious code through seemingly legitimate troubleshooting steps, often disguised as job assessments.
💡 New Malware Strains: The attackers are deploying new and updated malware, including BeaverTail, GolangGhost, and FlexibleFerret, across Windows, macOS, and Linux systems.
🌐 Abuse of Trusted Platforms: The Kimsuky group is leveraging GitHub for malware delivery and data exfiltration, and even using OpenAI’s ChatGPT to create deepfake IDs for phishing campaigns.
LastPass Warns of Fake GitHub Repositories Distributing Malware
A widespread campaign is targeting macOS users with fake GitHub repositories that impersonate popular applications like LastPass, 1Password, and Dropbox. The goal is to trick users into downloading and installing the Atomic Stealer malware, which is designed to steal sensitive information.
Key takeaways:
🔒 SEO Poisoning: The attackers are using SEO poisoning to make their malicious GitHub pages appear high in search results, tricking users into thinking they are legitimate.
🛡️ Terminal Execution: The attack relies on social engineering, convincing users to execute a malicious command in their Terminal application to install the malware.
💡 Broad Impersonation: The campaign is impersonating a wide range of popular and trusted software, increasing the chances of tricking unsuspecting users.
🌐 Ongoing Threat: The use of public code repositories like GitHub for malware distribution is a persistent and evolving threat that requires constant vigilance.
Verified Steam Game “BlockBlasters” Steals Crypto, Including Cancer Donations
A verified game on Steam, “BlockBlasters,” was used in a malicious campaign to steal cryptocurrency, including donations meant for a streamer’s cancer treatment. The game, initially safe, was later updated with a cryptodrainer, highlighting the potential for even verified applications to be compromised.
Key takeaways:
🔒 Trust is Not a Guarantee: Even games that have been verified by platforms like Steam can be updated with malicious code after the fact.
🛡️ Significant Financial Loss: The attack resulted in the theft of approximately $150,000 from over 250 Steam accounts.
💡 Social Engineering: The attackers specifically targeted individuals known to manage significant amounts of cryptocurrency, demonstrating a targeted social engineering approach.
🌐 Immediate Action Required: If you have installed “BlockBlasters,” it is crucial to reset your Steam password and move any digital assets to new wallets immediately.
Ransomware Attack Disrupts Major European Airports
A ransomware attack on third-party provider Collins Aerospace has caused significant flight disruptions at several major European airports, including London’s Heathrow. The attack on the company’s check-in and boarding systems forced manual processing for thousands of passengers, leading to delays and cancellations.
Key takeaways:
🔒 Third-Party Vulnerability: The incident highlights the significant risks posed by third-party vendors and the need for robust supply chain security.
✈️ Critical Infrastructure at Risk: The attack on a key aviation system demonstrates the vulnerability of critical infrastructure to cyberattacks.
💡 Widespread Impact: The disruption affected multiple major airports and airlines, showcasing the interconnectedness of the aviation industry and the cascading effects of a single cyberattack.
🛡️ Proactive Defense is Key: The NCSC is urging organizations to strengthen their cybersecurity posture to mitigate the risk of similar attacks.
New “EDR-Freeze” Tool Suspends Security Software Using Windows Components
A novel technique dubbed “EDR-Freeze” has been discovered, which leverages legitimate Windows Error Reporting (WER) components to suspend Endpoint Detection and Response (EDR) and antivirus software. This method, which effectively puts security tools into a “coma,” poses a significant threat as it operates from the user mode, making it stealthier than traditional kernel-based attacks.
Key takeaways:
🔒 Stealthy Evasion: EDR-Freeze uses the intended behavior of Windows components to disable security software without requiring a kernel driver, making it harder to detect.
🛡️ Design Weakness: This is not a traditional vulnerability but a design flaw that exploits the WerFaultSecure process to freeze security tools.
💡 Monitoring is Key: Defenders should monitor for unusual WER activity, especially when it points to sensitive processes like LSASS or security software.
🌐 Potential for Hardening: Microsoft could potentially harden the abused Windows components to prevent this type of attack.
U.S. Secret Service Seizes Over 300 SIM Servers in National Security Threat
The U.S. Secret Service has dismantled a significant threat to national security, seizing over 300 SIM box servers and 100,000 SIM cards in the New York tri-state area. The network, which was used to send assassination threats against senior U.S. officials, was also capable of disabling cell towers and facilitating encrypted communication for criminals and nation-state actors.
Key takeaways:
🔒 Sophisticated Threat: The network used a complex infrastructure of “electronic safehouses” to conceal its activities and posed a significant threat to national security.
🛡️ Proactive Intelligence: The Secret Service’s proactive protective intelligence investigation was crucial in identifying and neutralizing this threat before it could cause further harm.
💡 Anonymous Communication: The seized equipment was capable of generating anonymous, untraceable calls and messages, making it a valuable tool for criminals and nation-state actors.
🌐 Disruption of Malicious Infrastructure: The operation sends a clear message that law enforcement is actively working to dismantle the infrastructure used by malicious actors.
GitHub Cracks Down on npm Security with Mandatory 2FA and Granular Tokens
In response to a recent surge in supply-chain attacks, GitHub is significantly enhancing the security of its npm package registry. The platform is introducing mandatory two-factor authentication (2FA) for local publishing and enforcing the use of granular, short-lived access tokens.
Key takeaways:
🔒 Mandatory 2FA: Developers will now be required to use two-factor authentication when publishing packages from their local machines, adding a critical layer of security.
🛡️ Granular, Short-Lived Tokens: GitHub is moving away from classic, overly permissive tokens in favor of granular tokens with a 7-day lifespan, limiting the potential damage of a compromise.
💡 Proactive Defense: These measures are a direct response to recent attacks like “s1ngularity” and “GhostAction,” which have compromised thousands of accounts.
🌐 Ecosystem-Wide Effort: These changes are part of a broader effort to secure the open-source ecosystem, with other platforms like RubyGems also tightening their security.
“ShadowV2” Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire
A new and sophisticated “DDoS-for-Hire” botnet, named ShadowV2, is actively exploiting misconfigured Docker containers on Amazon Web Services (AWS) to launch powerful DDoS attacks. The botnet uses advanced techniques to bypass security measures and offers a user-friendly interface for launching attacks.
Key takeaways:
🔒 Misconfiguration is the Entry Point: The primary attack vector is misconfigured Docker containers, highlighting the critical importance of secure cloud configurations.
🛡️ Sophisticated Attack Methods: ShadowV2 utilizes advanced techniques like HTTP/2 Rapid Reset and methods to bypass Cloudflare’s “Under Attack” mode, making it a formidable threat.
💡 Cybercrime-as-a-Service: The botnet is being offered as a “DDoS-for-Hire” service, complete with a command-and-control framework and a user-friendly interface.
🌐 Stealthy Deployment: The attackers use a multi-stage deployment process to install their malware within a generic Ubuntu container, making detection more difficult.
Hackers Exploit Pandoc Flaw to Steal AWS Credentials
A critical Server-Side Request Forgery (SSRF) vulnerability in the popular Pandoc utility is being actively exploited to steal IAM credentials from Amazon Web Services (AWS) EC2 instances. The flaw (CVE-2025-51591) allows attackers to trick the application into making unauthorized requests to the AWS Instance Metadata Service (IMDS).
Key takeaways:
🔒 SSRF Vulnerability: The attack leverages a flaw in how Pandoc handles HTML iframes, allowing attackers to make requests to internal services.
🛡️ Targeting Cloud Credentials: The primary goal is to steal temporary IAM credentials from the AWS IMDS, which can then be used to access other AWS services.
💡 IMDSv2 is Key: The observed attack was unsuccessful because the targeted instance had IMDSv2 enabled, which mitigates SSRF attacks.
🌐 Shared Responsibility: Pandoc’s maintainers consider this intended behavior, placing the onus on users to sanitize input and use secure configurations.
PyPI Urges Credential Reset Amidst New Phishing Attacks
The Python Package Index (PyPI) is urging all users to reset their credentials following the discovery of a new phishing campaign. The attack uses a convincing fake PyPI website to steal login information, posing a significant threat to the Python ecosystem.
Key takeaways:
🔒 Credential Harvesting: The attack uses a malicious website that perfectly mimics the legitimate PyPI login page to trick users into entering their username and password.
🛡️ Supply Chain at Risk: Stolen credentials could be used to compromise popular Python packages, injecting malware that would then be distributed to countless downstream users.
💡 Phishing-Resistant 2FA: PyPI strongly recommends the use of phishing-resistant two-factor authentication methods, such as hardware security keys, to mitigate this threat.
🌐 Ongoing Threat: This is not an isolated incident. Sophisticated phishing and supply chain attacks are increasingly targeting the open-source community.
Python Package Index (PyPI)
“Brickstorm” Malware Steals Data from US Orgs for Over a Year
Suspected Chinese state-sponsored hackers have been using a sophisticated Go-based backdoor, dubbed “Brickstorm,” in a long-running espionage campaign targeting U.S. organizations. The malware, which has been active for over a year, has been used to steal sensitive data from companies in the tech, legal, and SaaS sectors.
Key takeaways:
🔒 Long Dwell Time: The attackers remained undetected in victim networks for an average of 393 days, allowing for extensive data exfiltration.
🛡️ Stealthy Operations: The threat actors used advanced techniques to evade detection, including masquerading their command-and-control traffic as legitimate services like Cloudflare and Heroku.
💡 Focus on High-Value Targets: The campaign specifically targeted developers, administrators, and individuals with access to sensitive information.
🌐 Evolving Threat Landscape: The use of custom malware, zero-day exploits, and sophisticated evasion techniques highlights the ever-evolving nature of cyber threats.
Google Threat Intelligence Group
Salesforce Patches Critical “ForcedLeak” Vulnerability
A critical vulnerability, dubbed “ForcedLeak,” has been discovered and patched in Salesforce’s Agentforce platform. The flaw could have allowed attackers to exfiltrate sensitive CRM data through a sophisticated AI prompt injection attack.
Key takeaways:
🔒 AI-Powered Data Theft: The attack leveraged a weakness in how the platform’s AI agent handled user-submitted data, allowing for the execution of hidden, malicious commands.
🛡️ Web-to-Lead Vector: The vulnerability was exploitable through the “Web-to-Lead” functionality, a common feature used to capture sales leads from websites.
💡 Exfiltration via Expired Domain: The attackers cleverly exfiltrated the stolen data to a previously allowlisted domain that had expired and was subsequently purchased by the security researchers.
🌐 Proactive Patching: Salesforce has addressed the issue by re-securing the expired domain and implementing patches to prevent AI agents from sending data to untrusted URLs.
New XCSSET Malware Variant Targets macOS Developers
A new and more potent variant of the XCSSET macOS malware is actively targeting Xcode developers. The malware, which spreads through infected Xcode projects, has been updated to steal data from the Firefox browser and hijack cryptocurrency transactions.
Key takeaways:
🔒 Supply Chain Attack: The malware infects Xcode projects, turning developers into unwitting distributors of the malicious code.
🛡️ Enhanced Data Theft: The new variant is capable of stealing sensitive information from the Firefox browser, expanding its data theft capabilities.
💡 Cryptocurrency Hijacking: The malware includes a feature to monitor the clipboard for cryptocurrency addresses and replace them with an attacker’s address.
🌐 Improved Persistence: The malware uses new techniques to ensure it remains on an infected system, making it more difficult to remove.
Unofficial “postmark-mcp” NPM Package Steals User Emails
A malicious npm package impersonating the official ‘postmark-mcp’ project has been discovered, designed to secretly steal users’ email communications. The package, which was available for a week and downloaded around 1,500 times, forwarded all emails to an external address controlled by the attacker.
Key takeaways:
🔒 Impersonation and Deception: The malicious package perfectly replicated the legitimate project, lulling users into a false sense of security.
🛡️ Data Exfiltration: A single line of code was added to silently BCC all sent emails, potentially exposing sensitive information like password resets, 2FA codes, and financial details.
💡 Limited but Significant Impact: While the number of downloads was relatively small, the potential for data theft from those affected is significant.
🌐 Verify Your Sources: This incident underscores the importance of verifying the source of all open-source packages and carefully reviewing code before implementation.
Top Tips of the Week

Threat Intelligence
- Regularly communicate CTI insights to stakeholders. Keep decision-makers informed to guide strategic security decisions.
- Use CTI to enhance threat intelligence platforms (TIPs). Leverage insights for continuous improvement and optimization of TIP capabilities.
Threat Hunting
- Understand the value of threat intelligence in penetration testing. Use insights to enhance real-world attack simulations.
Custom Tooling
- Implement continuous monitoring for custom tools. Proactively identify issues, assess performance, and ensure ongoing reliability.
- Regularly review custom tool access controls. Ensure that permissions align with organizational roles and responsibilities.
- Consider the accessibility of custom tools. Design interfaces and functionalities that cater to users with diverse needs and requirements.
- Understand your specific needs before creating custom tools. Tailor solutions to your unique challenges for optimal effectiveness.
Feature Video
Defenders are often stuck in a reactive loop. We’re chasing alerts, patching vulnerabilities, and trying to keep up with adversaries who are constantly changing their attacks. The sheer volume of noise from traditional security tools can be overwhelming, leading to alert fatigue and letting real threats slip through the cracks. What if you could change the game entirely?
Instead of building taller walls, turn your network into a minefield for hackers with cyber detection!
This guide will explore how deception technology works and why it’s essential for modern defense. We’ll take a deep dive into the Acalvio ShadowPlex platform, an industry-leading solution that uses AI to create a dynamic and intelligent active defense, turning the hunter into the hunted.
Let’s jump in!



