Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Dutch Teens Arrested for Allegedly Spying on Europol for Russia
Two 17-year-old boys have been arrested in the Netherlands on suspicion of attempting to spy on Europol and other international organizations for Russia. The pair were allegedly recruited via Telegram and used a Wi-Fi sniffer to gather intelligence.
Key takeaways:
🔒 Youth Recruitment: This incident highlights a disturbing trend of foreign intelligence agencies targeting and recruiting young, tech-savvy individuals for espionage.
🛡️ Insider Threat from the Outside: While not traditional insiders, the recruitment of individuals to physically plant snooping devices demonstrates a creative approach to bypassing perimeter security.
💡 Wireless Insecurity: The use of a Wi-Fi sniffer underscores the importance of robust wireless security measures, especially for high-value targets.
🌐 Escalating Tactics: The alleged espionage attempt represents a significant escalation from previous cases where minors were recruited for less sophisticated activities.
Akira Ransomware Bypassing MFA on SonicWall VPNs
The Akira ransomware group is actively exploiting a vulnerability in SonicWall SSL VPNs, and they’re now able to bypass multi-factor authentication. This campaign poses a significant threat, as it allows attackers to gain access to networks even when MFA is enabled.
Key takeaways:
🔒 MFA Bypass: The attackers have found a way to circumvent MFA, likely by using previously stolen OTP seeds, although the exact method is still under investigation.
🛡️ Ongoing Attacks: Even after patching, attackers are still successfully compromising networks using stolen credentials, highlighting the need for a multi-layered defense.
💡 Rapid Infiltration: Once inside a network, the Akira group moves extremely quickly, often beginning their internal reconnaissance within five minutes.
🌐 Credential Reset is Crucial: All VPN credentials on any SonicWall device that has used vulnerable firmware in the past must be reset immediately.
Microsoft Warns of AI-Driven Phishing Attacks
Microsoft has identified a new wave of sophisticated phishing attacks that leverage Large Language Models (LLMs) to create convincing and evasive malicious files. These AI-crafted attacks are designed to bypass traditional email security measures and trick users into compromising their credentials.
Key takeaways:
🔒 AI-Generated Lures: Attackers are using LLMs to create malicious SVG files that are obfuscated with business-related jargon, making them appear legitimate to both users and security tools.
🛡️ Evasive Tactics: The campaign employs clever tactics, such as self-addressed emails and multi-stage redirections, to bypass standard security filters.
💡 Hidden in Plain Sight: Malicious code is embedded within the SVG files in a way that mimics legitimate code, making it difficult for automated systems to detect.
🌐 Evolving Threat Landscape: This campaign highlights the continued evolution of phishing attacks and the need for advanced, AI-powered security solutions to combat them.
“EvilAI” Malware Masquerades as Benign AI Tools to Infiltrate Networks
A widespread malware campaign, dubbed “EvilAI,” is using trojanized AI-powered applications to infiltrate organizations globally. The malware, disguised as legitimate productivity tools, has been used to target a wide range of sectors, including manufacturing, government, healthcare, and technology.
Key takeaways:
🔒 Deceptive Appearance: The malware is packaged in professional-looking installers with valid digital signatures, making it difficult to distinguish from legitimate software.
🛡️ Global Reach: The campaign has a global footprint, with victims in Europe, the Americas, Asia, the Middle East, and the African (AMEA) region.
💡 Stealthy Operation: The trojans mimic the functionality of real software, allowing them to gain persistent access to networks without raising suspicion.
🌐 Multiple Distribution Channels: The malware is being spread through malicious ads, SEO poisoning, and promoted download links on forums and social media.
Bitcoin Queen” Convicted in World’s Largest Crypto Seizure
Zhimin Qian, the so-called “Bitcoin Queen,” has been convicted in a landmark case involving the seizure of over £5.5 billion ($7.3 billion) in cryptocurrency. Qian was the mastermind behind a massive fraudulent scheme that defrauded over 128,000 victims in China.
Key takeaways:
🔒 Massive Scale: The fraudulent investment scheme raised 40 billion yuan by promising returns of up to 300%.
🛡️ Record-Breaking Seizure: The 61,000 Bitcoin seized by the Metropolitan Police is the largest single crypto seizure in history.
💡 International Cooperation: The successful investigation was a result of close collaboration between UK and Chinese law enforcement.
🌐 Investor Warning: This case serves as a stark reminder of the risks associated with “get-rich-quick” investment schemes, especially in the volatile cryptocurrency market.
Cyberattack Halts Operations at Asahi, Japan’s Largest Brewer
Japan’s largest brewer, Asahi Group Holdings, has been forced to suspend its ordering and shipping operations following a significant cyberattack. The attack has disrupted the company’s Japan-based systems, leading to a complete shutdown of key business functions.
Key takeaways:
🔒 Operational Standstill: The attack has brought Asahi’s core logistics to a halt, demonstrating the crippling effect a cyber incident can have on a major corporation.
🛡️ Investigation Underway: The source of the attack and the initial access vector are still under investigation, and no group has yet claimed responsibility.
💡 Business Continuity is Crucial: This incident serves as a stark reminder of the importance of robust business continuity and disaster recovery plans.
🌐 No Data Breach Confirmed (Yet): While the company has not yet confirmed any data leakage, the investigation is ongoing.
Imgur Blocks UK Users Over Data Privacy Concerns
Imgur has blocked all access for users in the United Kingdom following a potential fine from the UK’s data watchdog, the Information Commissioner’s Office (ICO). The move comes amid an investigation into how the platform handles children’s data and verifies user ages.
Key takeaways:
🔒 Regulatory Pressure: The threat of a significant fine from the ICO prompted Imgur to withdraw its service from the UK entirely.
🌐 Widespread Impact: The block has broken embedded images on countless websites, including Steam and various forums, for all UK users.
🛡️ Compliance Challenges: This incident highlights the growing challenges for online platforms in navigating complex and evolving data privacy regulations like the UK’s Online Safety Act.
💡 The Future of the UK Internet?: The strict enforcement of these new laws could lead to more services choosing to geoblock UK users rather than risk non-compliance.
CISA Warns of Critical Sudo Flaw Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Sudo utility to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. The flaw (CVE-2025-32463) could allow a local attacker to gain root privileges on Linux and Unix-like systems.
Key takeaways:
🔒 Privilege Escalation: The vulnerability allows a local attacker to run arbitrary commands as root, even if they are not authorized in the sudoers file.
🛡️ Active Exploitation: CISA has confirmed that this vulnerability is being actively exploited, making it a high-priority threat.
💡 Chroot Abuse: The flaw is tied to the abuse of Sudo’s –chroot option, which can be manipulated to load arbitrary shared libraries.
🌐 Patch Immediately: All organizations using Sudo are urged to update to version 1.9.17p1 or later to mitigate this critical risk.
“Gemini Trifecta” Flaws Exposed User Data
Three critical vulnerabilities, collectively dubbed the “Gemini Trifecta,” have been discovered and patched in Google’s Gemini AI assistant. The flaws, all forms of prompt injection, could have allowed attackers to steal sensitive user data, including search history and location information.
Key takeaways:
🔒 Prompt Injection: The vulnerabilities allowed attackers to insert malicious instructions into various parts of the Gemini suite to manipulate its behavior.
🛡️ Multiple Attack Vectors: The flaws affected Gemini Cloud Assist, the Search Personalization model, and the Browsing Tool, creating multiple avenues for data exfiltration.
💡 AI as an Attack Surface: This incident highlights the growing trend of AI agents becoming a primary target for attackers.
🌐 Proactive Patching: Google has addressed these issues, but it serves as a reminder for organizations to maintain visibility and control over their AI tools.
New “MatrixPDF” Toolkit Turns PDFs into Phishing Weapons
A new toolkit called MatrixPDF is being sold on the dark web, allowing cybercriminals to easily convert standard PDF files into sophisticated phishing and malware lures. This tool makes it simple to embed malicious links and fake prompts into seemingly harmless documents, bypassing traditional email security filters.
Key takeaways:
🔒 Weaponized PDFs: MatrixPDF allows attackers to add blurred overlays and fake “Secure Document” buttons to PDFs, tricking users into clicking malicious links.
🛡️ Bypassing Security: Because the malicious content is not in the file itself but is fetched from an external link after a user clicks, these PDFs can easily bypass many email security solutions.
💡 User Awareness is Crucial: Be wary of any PDF that requires you to click a button or link to view its content, especially if the document appears blurred or locked.
🌐 AI-Powered Defense: AI-driven email security tools can help detect these threats by analyzing PDF structures and sandboxing embedded links to identify malicious behavior.
Critical Flaw in WD My Cloud Devices Allows Remote Command Injection
A critical vulnerability (CVE-2025-30247) in several Western Digital (WD) My Cloud NAS models could allow an unauthenticated attacker to execute arbitrary commands remotely. The flaw, which affects a wide range of popular devices, could lead to a full system compromise.
Key takeaways:
🔒 Remote Code Execution: The vulnerability allows for unauthenticated remote command injection, giving attackers a high level of control over the affected devices.
🛡️ End-of-Life Devices at Risk: Several of the affected models are no longer supported by WD, meaning they may not receive security updates, leaving users permanently vulnerable.
💡 Data at Risk: A successful exploit could lead to the theft, modification, or deletion of data stored on the NAS, and could even be used to deploy ransomware.
🌐 Patch Immediately: All users of affected My Cloud devices are urged to update to the latest firmware (5.31.108) immediately. If you cannot update, take the device offline.
Google Drive Gets AI-Powered Ransomware Shield
Google is rolling out a new AI-powered ransomware detection and recovery feature for Google Drive on desktop. The system is designed to automatically detect and thwart ransomware attacks, protecting your valuable files from being encrypted and held hostage.
Key takeaways:
🔒 AI-Powered Detection: A specialized AI model, trained on millions of ransomware samples, identifies suspicious file activity.
🛡️ Automatic Sync Pause: If an attack is detected, Google Drive automatically pauses file syncing to prevent the infection from spreading.
💡 Easy Restoration: Users are alerted to the potential attack and can easily restore their files to a pre-attack state with just a few clicks.
🌐 Proactive Defense: This new feature adds a crucial layer of proactive defense against one of the most significant and costly cyber threats.
WestJet Data Breach Exposes 1.2 Million Customers’ Personal Information
Canadian airline WestJet has confirmed a data breach that exposed the personal and travel information of 1.2 million customers. The breach is believed to be the work of the “Scattered Spider” hacking group, which has been targeting the aviation industry.
Key takeaways:
🔒 Sensitive Data Exposed: The stolen data includes full names, dates of birth, addresses, and travel document information, including passports and government IDs.
🛡️ Social Engineering Attack: The attackers reportedly gained access to WestJet’s network through a social engineering attack that targeted a single employee.
💡 Free Identity Theft Protection: WestJet is offering two years of free identity theft protection and monitoring to all affected customers.
🌐 Vigilance is Key: All WestJet customers, even those not directly notified, should be vigilant for phishing attempts and monitor their accounts for suspicious activity.
Red Hat Confirms Security Breach of GitLab Instance
Red Hat has confirmed a security incident involving a breach of one of its GitLab instances by a group calling itself the Crimson Collective. The hackers claim to have stolen nearly 570GB of data, including sensitive customer engagement reports.
Key takeaways:
🔒 Third-Party Risk: The attackers claim to have used authentication tokens found in Red Hat’s code to access their customers’ infrastructure, highlighting the significant risks of third-party integrations.
🛡️ Extortion Attempt: The hacking group attempted to extort Red Hat, but their demands were not met.
💡 Limited Impact (Officially): Red Hat states the breach is contained to its consulting division and does not affect other products or services.
🌐 Customer Notification: Red Hat is in the process of notifying all impacted customers and has implemented additional security measures.
Microsoft Outlook Blocks Inline SVG Images to Combat Phishing
In a significant move to enhance security, Microsoft has disabled the rendering of inline SVG images in both Outlook for the Web and the new Outlook for Windows. This change is a direct response to the massive 1,800% increase in SVG-based phishing attacks observed since early 2025.
Key takeaways:
🔒 Phishing Threat Neutralized: By blocking inline SVGs, Microsoft is cutting off a popular and effective vector for phishing and malware distribution.
🛡️ Minimal User Impact: The change is expected to affect less than 0.1% of all images sent via Outlook, so most users will not notice a difference.
💡 Proactive Security: This is part of a broader trend by Microsoft to disable features that are frequently abused by threat actors proactively.
🌐 Vigilance Still Required: While this is a positive step, users should remain cautious of all email attachments, including SVG files, from unknown senders.
Top Tips of the Week

Threat Intelligence
- Use CTI to inform threat modeling efforts. Identify potential threats and vulnerabilities during the development phase for proactive security measures.
- Use CTI in security architecture design. Develop robust architectures that align with threat intelligence for effective defenses.
- Engage in threat intelligence forums. Participate in discussions to share insights and learn from others in the field.
- Create a threat intelligence roadmap. Define objectives, processes, and milestones for a strategic and effective intelligence program.
Threat Hunting
- Implement threat intelligence in your cyber threat hunting workflow. Enhance detection capabilities with real-time threat data.
- Leverage threat intelligence in cloud security in cyber threat hunting. Adapt your strategies for the unique challenges of cloud environments.
Custom Tooling
- Implement secure update mechanisms for custom tools. Ensure a secure and seamless process for deploying updates and patches.
Feature Video
Tired of drowning in endless threat intel tabs? Drowning in endless threat intel tabs? What if you could build a powerful Cyber Threat Intelligence (CTI) aggregator for free and streamline your workflow?
This video provides a step-by-step guide on how to do it. Here are the key takeaways:
🧠 Single Pane of Glass: Discover the cognitive benefits of consolidating all your threat data into one central platform. Less stress, more focus!
🛠️ Build it for FREE: Learn how to use free tools like Inoreader to create your own CTI aggregator, no expensive platforms needed.
📊 Actionable Intel: Understand the difference between tactical, operational, and strategic intelligence to move from a data collector to a data analyst.
📚 Top-Tier Sources: Get a curated list of essential sources, including CTI blogs, CERT alerts, and researcher insights to kickstart your feed.



