Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

New “Cophish” Attack Weaponizes Microsoft Copilot Studio to Steal M365 Access
A sophisticated “Cophish” attack is weaponizing Microsoft Copilot Studio by leveraging the trusted microsoft.com domain to host malicious agents. These agents redirect users to fraudulent OAuth consent prompts designed to steal access tokens and bypass multi-factor authentication.
Key takeaways:
🚨 Trusted Domain Abuse: The attack is hosted on the legitimate copilotstudio.microsoft.com domain. This makes it highly convincing and allows it to bypass standard phishing filters and user suspicion.
🤖 Malicious AI Agent: Attackers create a custom Copilot agent and configure its standard “Login” button to redirect users to a malicious OAuth application instead of a legitimate sign-in page.
🛡️ Token Theft vs. Password Theft: The goal isn’t to steal your password. It’s to trick you into granting consent to a malicious app. This provides the attacker with an OAuth token, effectively bypassing MFA and granting persistent access to your M365 data (email, files, chats, etc.).
🔒 Defense: Always scrutinize OAuth consent screens, even if they originate from a trusted domain. Check exactly what permissions an application is requesting and who the publisher is. Admins must enforce strict application consent policies in Entra ID to block unverified publishers.
Mass Exploit Campaign Targeting Outdated WordPress Plugins
Threat actors are actively conducting a widespread campaign, exploiting known vulnerabilities in several popular but outdated WordPress plugins. The primary objective is to inject malicious scripts, create rogue administrator accounts, and take full control of vulnerable websites.
Key takeaways:
🚨 Active Mass Scanning: This is not a targeted attack. Hackers are automatically scanning millions of websites for any site running unpatched, vulnerable versions of popular plugins.
🌐 Multiple Plugins at Risk: Active exploits are targeting high-severity vulnerabilities in plugins like WP Meta SEO, LiteSpeed Cache, and WP Statistics, among others. If it’s outdated, it’s a target.
🔒 Rogue Admin Creation: The main attack vector (often Unauthenticated Stored XSS) allows attackers to create new, hidden administrator accounts, effectively handing them the keys to your site.
🛡️ Persistent Backdoors: Once admin access is gained, attackers install persistent backdoors and malware. This ensures they maintain access even if you later update the vulnerable plugin.
💡 Immediate Action Required: UPDATE ALL PLUGINS NOW. After updating, manually audit all user accounts on your WordPress dashboard. Delete any admin accounts you do not recognize immediately.
Critical RCE Flaw in Windows Server (WSUS) Under Active Attack
Microsoft has issued an emergency out-of-band (OOB) patch for a critical (9.8 CVSS) remote code execution vulnerability, CVE-2025-59287, in Windows Server Update Services. This flaw is being actively exploited in the wild by unauthenticated attackers to gain full SYSTEM-level control of servers.
Key takeaways:
🚨 Immediate Threat: CVE-2025-59287 is a 9.8 CVSS RCE flaw with public proof-of-concept (PoC) code. Active “in-the-wild” exploitation has been observed.
🛡️ Attack Vector: An unauthenticated attacker can remotely send a crafted request to the WSUS service, triggering an unsafe deserialization of data and resulting in arbitrary code execution with the highest privileges.
🌐 Affected Systems: This vulnerability impacts all supported versions of Windows Server (2012-2025) only if the WSUS server role is enabled.
🔒 Action: Patch Immediately: Apply the new emergency OOB updates to all vulnerable WSUS servers. A system reboot is required after installation.
💡 Mitigation: If you cannot patch immediately, block all inbound traffic to ports 8530 and 8531 on the host firewall, or disable the WSUS Server Role entirely.
Major Shift in Ransomware: Profits Plummet as Victims Refuse to Pay
This is a significant win for defenders: Ransomware profits are dropping as organizations increasingly refuse to pay, with payment rates hitting a record low of just 23%. This success is attributed to better backups and stronger defenses, but it’s forcing attackers to change their entire playbook.
Key takeaways:
🚨 Payment Rates Collapse: The number of victims paying ransoms has hit an all-time low. This collective refusal is effectively “constricting the oxygen” from threat actors’ primary revenue stream.
🛡️ Defenses Are Working: The trend is driven by organizations investing in robust backup and recovery strategies, making it possible to restore operations without giving in to demands.
🌐 Shift to “Double Extortion”: Attackers are adapting. Over 76% of attacks now focus on data exfiltration (data theft) before encryption, as threatening to leak stolen data is their new main leverage.
💡 New Target Focus: With large enterprises hardening their defenses, ransomware groups (like Akira and Qilin) are now shifting their focus to medium-sized firms, which they perceive as easier targets and more likely to pay.
🔒 The Next Vector: As technical defenses improve, analysts predict attackers will increasingly rely on social engineering and recruiting malicious insiders to gain initial access.
New “Tainted Memory” Exploit Hijacks ChatGPT Atlas Browser via CSRF
A critical “Tainted Memory” vulnerability is being exploited in the new ChatGPT Atlas browser. Attackers are using a Cross-Site Request Forgery (CSRF) flaw to inject persistent, malicious instructions into the AI’s memory, which can execute later to steal data or take over your accounts.
Key takeaways:
🚨 Persistent Threat: The exploit uses a CSRF attack to permanently inject malicious commands into the AI’s “memory” feature. These “tainted memories” survive reboots and new sessions.
💡 Latent Execution: The attack is stealthy. The malicious instructions lie dormant until the user makes a legitimate prompt, which then triggers the hidden malicious code.
🛡️ Full-Scale Hijack: Because the AI agent operates with your full privileges across all logged-in services (email, cloud storage, etc.), this exploit can be used to run arbitrary code and exfiltrate private data.
🌐 Omnibox Jailbreak: A separate, related flaw shows the browser’s address bar (omnibox) can be “jailbroken” by disguising malicious prompt injections as harmless-looking URLs.
🔒 Blurred Boundaries: The root cause is the AI’s inability to distinguish between untrusted content from the web and trusted commands from the user, turning a helpful feature into a weapon.
‘RedTiger’ Malware Campaign Targeting Gamers and Discord
A new, modular infostealer named RedTiger is actively targeting the gaming community to steal Discord tokens, browser data, and crypto wallets. This open-source Python tool, originally for red teaming, uses a two-stage process to exfiltrate data via cloud storage and Discord webhooks.
Key takeaways:
🚨 What is RedTiger? It’s an open-source, Python-based red-teaming tool now being used maliciously as an infostealer.
🎯 Primary Targets: The malware is aimed at gamers, with a strong focus on compromising Discord accounts by injecting malicious JavaScript.
💰 Data at Risk: RedTiger exfiltrates a wide range of data, including browser credentials, payment information, cryptocurrency wallets, and game files (like Roblox).
📤 Stealthy Exfiltration: It uses a two-stage method: stolen data is first uploaded to ‘GoFile’ (cloud storage), and then the download link is sent to the attacker using a Discord webhook.
🛡️ Anti-Forensics: The malware can also create mass “spam” files and processes to overload the victim’s system and make forensic analysis more difficult.
Qilin Ransomware Abuses WSL for Cross-Platform Attacks
The Qilin ransomware group is now abusing the Windows Subsystem for Linux (WSL) to execute its Linux-based encryptor directly on Windows systems. This hybrid technique allows them to bypass standard EDR and antivirus tools focused on Windows threats.
Key takeaways:
🐧 Hybrid Attack Vector: Attackers are running their Linux ransomware variant directly on Windows machines by leveraging WSL, demonstrating a sophisticated cross-platform strategy.
🛡️ Evasion Tactic: This method is designed to bypass security tools that are primarily focused on monitoring native Windows executables, allowing the malware to operate undetected.
📦 Payload Delivery: The attack chain often involves transferring the Linux binary to the Windows host using legitimate tools like WinSCP after gaining initial access.
💥 Combined TTPs: This technique is often used alongside other advanced methods, like Bring Your Own Vulnerable Driver (BYOVD), to disable endpoint security before encryption.
🌐 Growing Threat: Qilin (aka Agenda) remains one of the most active RaaS operations, using its Rust-based, cross-platform malware to target critical sectors globally.
GhostCall Campaign Targets macOS Execs with Fake Zoom Meetings
The BlueNoroff hacking group (part of Lazarus) is targeting tech and VC executives on macOS with a sophisticated new campaign. Attackers use social engineering on platforms like Telegram to lure victims to malicious, “Zoom-like” phishing sites that mimic investment meetings.
Key takeaways:
👻 Advanced Social Engineering: Targets are invited to a fake Zoom call that appears legitimate, even playing recordings of other victims to build trust before claiming there’s an audio issue.
🚨 Fake Update Trojan: The site prompts the victim to download a “Zoom client update” to fix the “problem.” This file is a malicious script that downloads and installs a backdoor.
🔒 Info-Stealing Payload: The malware, including a backdoor dubbed ‘CosmicDoor,’ is designed to harvest sensitive files from the compromised Mac, specifically targeting password managers (like 1Password, LastPass), note-taking apps, and Telegram data.
🛡️ High-Value Targets: This campaign is not random; it is a highly-targeted operation focused on C-suite executives and venture capitalists, demonstrating a clear financial motive.
Malicious NPM Packages Deploy Cross-Platform Infostealer
A sophisticated campaign has been identified using 10 malicious, typosquatted NPM packages to deliver a potent information stealer. This malware is designed to harvest sensitive credentials from developers across Windows, macOS, and Linux systems.
Key takeaways:
🚨 Typosquatting Threat: The packages impersonate popular libraries like discord.js, ethers.js, nodemon, and typescriptjs to trick developers. Always double-check package names before installation.
🛡️ Multi-Stage Attack: The malware uses a post-install script to launch in a new terminal, displays a fake CAPTCHA to appear legitimate, and uses four layers of obfuscation to evade detection.
💻 Cross-Platform Payload: A large 24MB PyInstaller-packaged binary (data_extracter) is downloaded, enabling it to attack Windows, macOS, and Linux environments.
🔒 Credential Theft: The stealer’s primary goal is to harvest credentials from system keyrings (e.g., macOS Keychain, Windows Credential Manager), browser data, SSH keys, and application config files.
💡 Immediate Action: Audit your dependencies for the malicious packages (e.g., deezcord.js, nodemonjs, react-router-dom.js). Any system with these installed should be considered fully compromised.
Canada Warns: Hacktivists Breached Critical Water & Energy Systems
The Canadian Centre for Cyber Security (CCCS) has confirmed that hacktivists successfully breached multiple municipal water and energy facilities. These “unsophisticated” but effective attacks targeted internet-exposed Industrial Control Systems (ICS), highlighting significant vulnerabilities in critical infrastructure.
Key takeaways:
🚨 Target: Exposed ICS: The attackers were opportunistic, compromising internet-facing Industrial Control Systems (ICS), PLCs, and HMIs that were poorly secured.
🛡️ “Unsophisticated” is Still Dangerous: The breaches didn’t require advanced techniques, just basic security lapses. They tampered with water pressure, triggered false alarms at an O&G firm, and manipulated grain silo temperatures.
💡 Remove Direct Exposure: The CCCS urges all operators to inventory internet-accessible devices and immediately remove direct internet exposure where possible.
🔒 Layer Your Defenses: Implement VPNs with 2FA, use an Intrusion Prevention System (IPS), manage vulnerabilities, and keep all ICS firmware updated to block these low-effort attacks.
Canadian Centre for Cyber Security (CCCS)
New “AI-Targeted Cloaking” Attack Poisons AI Models with Fake Info
Researchers have uncovered a sophisticated new attack where malicious sites trick “agentic” AI web crawlers (like those from ChatGPT & Perplexity) into reading fake information. This “context poisoning” causes AI models to present misinformation as fact, undermining user trust.
Key takeaways:
🚨 Deceptive Content: The attack serves a benign webpage to humans but a different, malicious page to AI crawlers, all based on a simple “user agent” check.
💡 Context Poisoning: The goal is to poison the AI’s “ground truth.” The model then cites the fake information as authoritative, effectively manipulating its reality.
🌐 Misinformation Weapon: This technique can be used to undermine trust in AI tools, spread propaganda, or launch smear campaigns that are invisible to human users.
🛡️ Trust but Verify: This attack highlights a critical vulnerability. What may appear as an AI “hallucination” could, in fact, be purposefully injected misinformation.
New NFC Relay Malware Stealing Credit Cards in Europe
A sophisticated Malware-as-a-Service (MaaS) platform named ‘SuperCard X’ is enabling a massive surge in credit card fraud. Hackers are using this Android malware to conduct NFC relay attacks, capturing card data in real-time from victims and using it at contactless payment terminals.
Key takeaways:
📱 Social Engineering: The attack begins with a fake SMS or WhatsApp message, supposedly from a bank, which uses social engineering to trick victims into installing a malicious “security” app from outside the Google Play Store.
💳 NFC Data Theft: Scammers instruct the victim to “verify” their card by tapping it against their own phone. The malicious app then reads the card’s chip data via NFC and relays it to the attacker.
🔒 Real-Time Fraud: The attacker instantly uses the stolen data on their own device (running a ‘Tapper’ app) to emulate the victim’s card and make fraudulent contactless payments at POS terminals or ATMs.
🛡️ Stealthy Malware: The malware avoids detection by requesting minimal permissions (only NFC access) and is not found on the official Google Play Store. It uses secure communication channels to hide its activity from researchers.
🌍 Primary Target: This campaign is actively targeting users and financial institutions in Europe, with initial attacks spotted in Italy.
State-Sponsored Hackers Breach Major Telecom Provider
Telecom giant Ribbon Communications, a key provider for the U.S. government and global telecoms, has confirmed a network breach by nation-state actors. The attackers may have had persistent access to its IT network since as early as December 2024, posing a significant supply chain risk.
Key takeaways:
🌐 Major Supply Chain Target: Ribbon provides services to critical infrastructure and government bodies, including the U.S. Department of Defense and major carriers like Verizon and Deutsche Telekom.
🚨 Long-Term Intrusion: The threat actor, suspected to be a nation-state, may have had undetected access for over nine months before being discovered in September 2025.
🔒 Data Access Confirmed: While the full investigation is ongoing, the attackers successfully accessed files belonging to several customers that were stored on laptops outside the main network.
🛡️ Pattern of Attack: This breach resembles previous widespread campaigns by groups like China’s “Salt Typhoon,” which has a history of targeting U.S. telecom and critical infrastructure.
Russian Ransomware Gangs Weaponize Open-Source C2 Framework
Russian-linked ransomware groups, including the notorious Fog and Akira operators, are now actively using a powerful open-source C2 framework called AdaptixC2. This tool, marketed for ‘red teaming,’ is being leveraged to conduct advanced attacks and gain comprehensive control over victim systems.
Key takeaways:
🚨 Emerging Threat: The open-source AdaptixC2 framework is being adopted by high-profile ransomware gangs for post-exploitation.
🔧 Dual-Use Danger: Originally released as a “penetration testing” tool, its powerful features (like encrypted comms and command execution) are now actively weaponized by criminals.
💡 Varied Attack Vectors: This C2 has already been spotted in attacks ranging from AI-generated PowerShell scripts to fake help desk support scams conducted over Microsoft Teams.
🌐 Blurred Lines: The tool’s creator, a self-described “MalDev” (malware developer), highlights the dangerous trend of open-source projects directly fueling cybercrime.
🛡️ Defense Insight: Security teams must expand detection capabilities beyond known malware to include signatures and behaviors of emerging, “legitimate” open-source C2 frameworks.
New Phishing Scam Targets Finance Leaders on LinkedIn
A highly targeted phishing campaign is using fake “executive board” invitations in LinkedIn direct messages to steal Microsoft 365 credentials from finance executives. The attack uses sophisticated techniques, including bot evasion, to lure victims to an advanced credential-harvesting page.
Key takeaways:
🔒 Highly Targeted: The attackers are specifically sending direct messages to high-level finance professionals, such as CFOs and VPs, with personalized lures.
💡 Deceptive Lure: The scam uses the prestige of an “exclusive invitation” to join an executive board, creating a sense of urgency and legitimacy to trick victims into clicking.
🌐 Advanced Credential Theft: The malicious link redirects to an Adversary-in-the-Middle (AITM) phishing page, disguised as a Microsoft login, designed to steal both passwords and session cookies.
🛡️ Evades Security: The attack path uses redirects and Cloudflare Turnstile (a CAPTCHA) to prevent automated security tools and bots from scanning and flagging the malicious site.
🚨 Verify All DMs: Treat unsolicited messages on any platform, even trusted ones like LinkedIn, with extreme caution. Always verify the sender and the opportunity through a separate, known communication channel before clicking.
Top Tips of the Week

Threat Hunting
- Foster a proactive mindset in threat hunting. Be the hunter, not the hunted. Anticipate and neutralize potential threats.
- Embrace a proactive mindset in cyber threat hunting. Anticipate and neutralize potential threats before they escalate.
- Utilize threat intelligence for risk assessment in cyber threat hunting. Identify and prioritize potential risks to allocate resources effectively.
- Conduct threat intelligence awareness sessions. Ensure that all team members understand the value and application of threat intel.
Custom Tooling
- Collaborate with threat modeling teams during custom tool development. Identify potential risks and vulnerabilities to strengthen security measures.
- Implement secure coding practices in custom tool development. Address vulnerabilities at the code level to enhance overall security.
- Regularly communicate updates about custom tools to your team. Keep stakeholders informed about enhancements and changes.
Feature Article
Stop hoarding your threat intel!
That “clever” phishing attack you blocked at 9 AM? By lunchtime, it’s hammering your peers across the industry because your detailed report is just sitting on an internal server. In cyber security, sharing isn’t just caring—it’s a critical force multiplier.
This video breaks down the four CTI communities you need to know:
🌍 OSINT (Open Source): The public square. Think blogs, social media, and platforms like AlienVault OTX. It’s where everyone starts, but it can be noisy!
🤝 ISACs (Info Sharing & Analysis Centers): The private, industry-specific club (e.g., FS-ISAC, H-ISAC). This is where you get high-trust, highly relevant intel from your direct peers.
🤖 Vendor Platforms: The “pay-to-play” ecosystem. These communities (from vendors like CrowdStrike, Mandiant, etc.) are powered by massive global telemetry from products you already use.
🤫 Trusted Groups: The invite-only “inner circle”. Built entirely on reputation and personal trust, this is where the most timely, “bleeding edge” intelligence is shared.
Watch now to learn what these groups are and how you can join them!
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defense strategies.
- TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



