Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Massive Surge in Scans Targeting Palo Alto Networks & Grafana
Cybersecurity researchers have observed a massive 500% spike in scanning activity targeting Palo Alto Networks’ login portals. While there’s no evidence of a breach, the increased activity is a clear indicator of malicious intent. Separately, there has been a significant rise in attacks targeting a known vulnerability in Grafana.
Key takeaways:
🔒 Heightened Alert: The dramatic increase in scanning suggests that threat actors are actively probing for weaknesses in Palo Alto Networks’ infrastructure.
🛡️ No Breach (Yet): Palo Alto Networks has confirmed they have not been compromised, but the situation is being closely monitored.
💡 Grafana Under Fire: An old but effective path traversal vulnerability in Grafana is being actively exploited, with a significant number of malicious IPs identified.
🌐 Patch and Protect: All Grafana users should ensure their systems are patched against CVE-2021-43798 and review their logs for any signs of compromise.
“CometJacking” Flaw Turns AI Browser into a Data Thief
A newly discovered vulnerability, dubbed “CometJacking,” can turn Perplexity’s Comet AI browser into a powerful data-stealing tool with just a single click. The attack uses a sophisticated prompt injection technique to bypass security measures and exfiltrate sensitive data from connected services.
Key takeaways:
🔒 One-Click Exploit: A single click on a malicious link is all it takes to trigger the attack.
🛡️ Bypasses Security: The attack uses simple encoding to bypass Perplexity’s data protection mechanisms.
💡 No Credentials Needed: The attack doesn’t require stealing passwords because the browser is already authorized to access your connected accounts.
🌐 New AI-Powered Threats: This incident highlights the emerging security risks associated with AI-native browsers and the need for new, agent-focused security measures.
Rhadamanthys Stealer Gets a Sinister Upgrade
The Rhadamanthys Stealer malware, a potent information-stealing tool, has received a significant update, making it even more dangerous and evasive. The new version incorporates advanced features like steganography and device fingerprinting to bypass security measures and steal sensitive data.
Key takeaways:
🔒 Stealthy Payload Delivery: The malware now uses steganography to hide its malicious payloads within seemingly harmless image and audio files.
🛡️ Advanced Evasion: Rhadamanthys employs sophisticated techniques to detect and evade analysis in sandboxed environments.
💡 Professional Operation: The threat actors behind this malware are operating a professional Malware-as-a-Service (MaaS) business, complete with tiered pricing and branding.
🌐 Continuous Evolution: The malware is under constant development, with its creators continuously adding new features and improving its evasion capabilities.
“RediShell” Flaw Puts Thousands of Redis Instances at Risk
A 13-year-old, maximum-severity vulnerability (CVSS 10.0) dubbed “RediShell” has been discovered in all versions of Redis, a popular open-source data store. The flaw could allow attackers to gain remote code execution on the hundreds of thousands of Redis instances currently exposed online.
Key takeaways:
🔒 Critical “Use-After-Free” Flaw: The vulnerability (CVE-2025-49844) resides in the Lua interpreter and can be exploited by an authenticated attacker to escape the sandbox and take control of the server.
🛡️ Widespread Exposure: Researchers have identified over 330,000 Redis instances exposed to the internet, with a shocking 60,000 requiring no authentication.
💡 Active Targeting: Redis servers are a popular target for botnets and cryptomining campaigns, making this vulnerability a particularly attractive target for attackers.
🌐 Immediate Action Required: Administrators are urged to patch their systems immediately, enable authentication, and limit access to trusted networks.
GoAnywhere MFT Flaw Exploited in Medusa Ransomware Attacks
Affiliates of the Medusa ransomware gang are actively exploiting a critical vulnerability in Fortra’s GoAnywhere MFT. The flaw (CVE-2025-10035) allows for remote code execution and is being used to gain initial access to networks, leading to data theft and ransomware deployment.
Key takeaways:
🔒 Active Exploitation: The vulnerability was exploited as a zero-day, with attacks beginning at least a week before a patch was available.
🛡️ Multi-Stage Attack: The attackers use a sophisticated chain of tools for persistence, reconnaissance, and lateral movement.
💡 Data Exfiltration: Stolen data is exfiltrated using Rclone before the Medusa ransomware is deployed.
🌐 Patch and Investigate: All GoAnywhere MFT users should upgrade immediately and inspect logs for signs of compromise.
AI is Now the #1 Channel for Data Exfiltration
New research reveals that the widespread, unmanaged use of generative AI tools by employees has made AI the leading channel for corporate data exfiltration, surpassing even shadow IT and unmanaged file sharing.
Key takeaways:
🔒 Unmanaged Usage is Rampant: A staggering 67% of employee AI usage is through unmanaged personal accounts, leaving security teams completely in the dark.
🛡️ Sensitive Data at Risk: An alarming 40% of files uploaded to GenAI tools contain sensitive information, including PII and PCI data.
💡 Copy/Paste is the New Leaky Faucet: The primary method of data leakage isn’t file uploads, but the simple act of copy/pasting data into AI prompts, with 77% of employees admitting to this practice.
🌐 “Corporate” Doesn’t Mean Secure: A high percentage of logins to critical platforms like CRMs and ERPs are non-federated, making corporate accounts as vulnerable as personal ones.
North Korean Hackers Steal Record $2 Billion in Crypto This Year
North Korean state-sponsored hackers have shattered all previous records, stealing an estimated $2 billion in cryptocurrency in 2025 alone. The funds are believed to be financing the country’s nuclear weapons program.
Key takeaways:
🔒 Record-Breaking Heists: The staggering $2 billion figure is nearly triple the amount stolen in 2024 and includes the single largest crypto heist on record.
🛡️ Shifting Tactics: Attackers are increasingly targeting individuals and employees of crypto exchanges with sophisticated social engineering attacks.
💡 Complex Laundering: The hackers are using advanced techniques, including multiple mixing services and cross-chain transfers, to obscure the trail of stolen funds.
🌐 Constant Vigilance Required: The cryptocurrency community must remain on high alert and implement robust security measures to combat this ever-evolving threat.
Docker Makes Hardened Images More Accessible for All
Docker is democratizing security by offering its catalog of “Hardened Images” at a more affordable price, making near-zero CVEs a reality for startups and SMBs. This move aims to elevate the security of the entire container ecosystem by providing a secure-by-default starting point for all developers.
Key takeaways:
🔒 Near-Zero Vulnerabilities: Docker’s Hardened Images are built from source and stripped of non-essential components, reducing the attack surface by up to 95%.
🛡️ Enterprise-Grade Security for All: Previously a premium offering, these highly secure images are now accessible to everyone through an affordable subscription.
💡 Faster Patching: Docker is backing its Hardened Images with a seven-day SLA for patching critical and high-severity vulnerabilities.
🌐 Seamless Integration: Migrating to a hardened image is as simple as changing a single line in a Dockerfile, making it easy for developers to adopt.
UK Teens Arrested in Nursery Ransomware Attack & Child Doxing Case
Two 17-year-olds have been arrested in the UK in connection with a ransomware attack on the Kido nursery chain that led to the doxing of children. The cybercrime gang, known as Radiant Group, leaked sensitive data, including photos and addresses of children, on the dark web and attempted to extort the nursery and parents.
Key takeaways:
🔒 Third-Party Risk: The breach occurred via a third-party software service, highlighting the critical importance of vetting vendors who handle sensitive data.
끔 Horrific Tactics: The attackers stooped to doxing children and making threatening calls to parents, a deeply concerning escalation.
💡 Youth in Cybercrime: The arrests underscore a disturbing and growing trend of teenagers participating in high-profile cyberattacks.
🛡️ Constant Vigilance: This incident is a stark reminder for all organizations, especially those protecting children’s data, to maintain the highest levels of security and incident response planning.
Discord Breach Exposes User Data After Third-Party Hack
Discord has confirmed a data breach stemming from a compromise at a third-party customer service provider. The breach exposed the personal information of users who had contacted Discord’s support teams, including some government-issued IDs.
Key takeaways:
🔒 Third-Party Vulnerability: The attack targeted an external vendor, highlighting the significant risks posed by supply chain partners.
🛡️ Sensitive Data Exposed: The breach included names, email addresses, partial payment information, and, in some cases, scanned government-issued photo IDs.
💡 Extortion Attempt: The hacking group, believed to be “Scattered Lapsus$ Hunters,” attempted to extort a ransom from Discord.
🌐 No Direct System Compromise: Discord’s own systems were not breached. The company has revoked the third party’s access and is working with law enforcement.
New “FileFix” Attack Uses Cache Smuggling to Evade Security
A new and stealthy variant of the “FileFix” social engineering attack is using a technique called cache smuggling to bypass security software and deliver malware. The attack, which impersonates a “Fortinet VPN Compliance Checker,” tricks users into executing malicious code without raising any red flags.
Key takeaways:
🔒 Cache Smuggling: The attack disguises a malicious ZIP archive as an image file, which is then cached by the browser. A subsequent PowerShell script can then extract the malware without making any suspicious web requests.
🛡️ Stealthy Execution: Users are tricked into pasting a seemingly harmless network path into their File Explorer, which contains a hidden PowerShell command that executes invisibly.
💡 Automated Lures: A new toolkit called the “IUAM ClickFix Generator” is being used to automate the creation of these phishing lures, making it easier for attackers to launch campaigns.
🌐 Infostealer Payloads: These attacks are being used to distribute various infostealer malware, including DeerStealer for Windows and Odyssey for Mac.
“Crimson Collective” Targets AWS Cloud Instances for Data Theft
The hacking group “Crimson Collective” is actively targeting Amazon Web Services (AWS) cloud environments to steal data and extort companies. The group, which recently claimed responsibility for the Red Hat breach, uses open-source tools to find exposed credentials and then escalates privileges to gain full control of the targeted AWS environment.
Key takeaways:
🔒 Exposed Credentials are the Entry Point: The attackers’ primary method is finding exposed long-term AWS access keys.
🛡️ Privilege Escalation: Once inside, they create new admin accounts to gain complete control over the victim’s cloud infrastructure.
💡 Data Exfiltration: The group systematically identifies and exfiltrates valuable data from various AWS services, such as RDS and EBS.
🌐 Extortion and Collaboration: After stealing the data, the group uses the compromised AWS email service to send extortion demands and has even partnered with other hacking groups to increase pressure.
New “ClayRAT” Android Spyware Spreads Like Wildfire
A sophisticated and rapidly evolving Android spyware campaign, “ClayRAT,” is targeting users in Russia through fake lookalike versions of popular apps. The malware, which is designed to steal sensitive data and self-propagate, poses a significant threat to user privacy and security.
Key takeaways:
🔒 Deceptive Distribution: ClayRAT is being spread through fake websites and Telegram channels impersonating popular apps like WhatsApp, TikTok, and YouTube.
🛡️ Total Data Theft: The spyware can steal SMS messages, call logs, notifications, and device details. It can also take pictures, place calls, and send texts without the user’s knowledge.
💡 Self-Propagating Worm: ClayRAT is designed to spread by sending malicious links to all contacts on an infected device.
🌐 Evasive Maneuvers: The malware uses advanced obfuscation and fake Play Store update screens to bypass Android’s security protections and remain undetected.
AI-Powered Attacks on the Rise in Ukraine
Russian hackers are increasingly using artificial intelligence to generate sophisticated phishing messages and even create malware, according to a new report from Ukraine’s SSSCIP. This marks a significant evolution in the tactics used in the ongoing cyber warfare.
Key takeaways:
🔒 AI as a Weapon: Threat actors are leveraging AI to create more convincing and effective cyberattacks.
🛡️ Synchronized Attacks: Russia is coordinating its cyber operations with kinetic attacks on the battlefield, creating a hybrid warfare environment.
💡 Abuse of Legitimate Services: Attackers are using trusted platforms like Dropbox, Google Drive, and Telegram to host malware and phishing pages.
🌐 Zero-Click Exploits: The APT28 group has been using zero-click exploits to steal credentials and monitor email communications.
“Payroll Pirate” Attacks Target University HR Employees
A new wave of “payroll pirate” attacks is targeting university employees, using sophisticated phishing tactics to compromise HR accounts and divert salary payments. The attackers are bypassing MFA and using clever social engineering to gain access to sensitive systems.
Key takeaways:
🔒 MFA is Not a Silver Bullet: The attackers are using adversary-in-the-middle (AITM) techniques to steal MFA codes, highlighting the need for phishing-resistant MFA.
🛡️ Social Engineering at its Finest: The phishing emails are highly targeted and use relevant themes like campus illness outbreaks to trick victims into clicking.
💡 Silent Takeover: Once inside an account, the attackers create inbox rules to hide their activity and then pivot to the HR platform via single sign-on.
🌐 Widespread Threat: While this campaign is currently focused on universities, the tactics could easily be adapted to target any organization.
Top Tips of the Week

Threat Intelligence
- Integrate CTI into threat intelligence sharing platforms. Facilitate seamless sharing and dissemination of threat intelligence within and beyond the organization.
- Consider the dark web in CTI research. Monitor underground forums for insights into potential threats.
- Conduct cyber threat intelligence exercises. Simulate scenarios to test readiness and identify areas for improvement.
Threat Hunting
- Foster threat hunting skills in-house. Develop a culture of continuous learning to adapt to the evolving threat landscape.
- Develop hypotheses for threat hunting. Form educated guesses about potential threats and use them as guides.
- Educate your team on cyber threat hunting techniques. A knowledgeable team is your first line of defense. Train regularly for threat awareness.
Custom Tooling
- Optimize custom tools for performance across different devices. Ensure compatibility and optimal user experience on various platforms.
Feature Video
Tired of sifting through endless raw logs and unstructured data? 😫 What if your command line could understand JSON, CSV, and even Windows Event Logs natively?
Nushell is here to revolutionize your cyber security analysis! Here’s why you need to check it out:
✨ Structured Data Power: Move beyond plain text. Nushell treats everything as structured data, making complex parsing obsolete.
⚡️ Faster Investigations: Reduce cognitive load with clear, tabular outputs, helping you spot anomalies in Apache or Windows Event logs in a flash.
💻 Cross-Platform Consistency: Whether you’re on Windows, Mac, or Linux, Nushell provides a unified, powerful analysis environment.
🔍 Interactive Exploration: Use the explore command to visually and interactively pivot, filter, and reshape data on the fly – perfect for dynamic threat hunting!
Ready to upgrade your terminal and supercharge your data forensics? Watch the full video to see Nushell in action!
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



