Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Glassworm Malware Returns: 3 Malicious VSCode Extensions Found on OpenVSX
The Glassworm malware campaign is back, targeting developers with three new malicious VSCode extensions on the OpenVSX marketplace, which have already amassed over 10,000 downloads.
Key takeaways:
🚨 Threat Identified: The “GlassWorm” malware is embedded in 3 new VSCode extensions: ai-driven-dev.ai-driven-dev, adhamu.history-in-sublime-merge, and yasuyuky.transient-emacs.
🔒 Data at Risk: The malware is designed to steal credentials for GitHub, NPM, and OpenVSX, as well as sensitive data from 49 different cryptocurrency wallet extensions.
💡 Deceptive Tactic: The malware uses invisible Unicode characters to hide its malicious payload, bypassing security checks.
🛡️ Immediate Action: Developers using OpenVSX should immediately check if they have installed these extensions. Always vet extension publishers and be cautious when downloading new tools.
🌐 Global Impact: The campaign has a global reach, with victims identified in the US, Europe, Asia, and a government entity in the Middle East.
Critical Flaws in runC: Container Escape Risk for Docker & Kubernetes
Three high-severity vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) have been found in runC, the core container runtime used by Docker and Kubernetes. These flaws could allow an attacker to bypass container isolation and gain root access to the host system.
Key takeaways:
🔒 Container Escape: The flaws allow an attacker to trick runC into mounting sensitive host file systems (like /proc) as read-write during container startup, leading to a full container escape.
🛡️ Root Access: Successful exploitation grants the attacker root privileges on the underlying host machine, compromising the entire system.
🌐 Wide Impact: These vulnerabilities affect all versions of runC (with one affecting 1.0.0-rc3 and later), impacting the entire ecosystem that relies on it, including Docker and Kubernetes.
💡 Attack Vector: Exploitation requires the ability to start containers with custom mount configurations, often achieved through malicious container images or Dockerfiles.
🛠️ Mitigation: Patches are available in runC versions 1.2.8, 1.3.3, and 1.4.0-rc.3. Admins should also use rootless containers or user namespaces as a strong preventative measure.
Microsoft Uncovers ‘WhisperLeak’ Side-Channel Attack on Encrypted AI Chats
Microsoft has disclosed a new side-channel attack, “WhisperLeak,” that allows adversaries to infer the topic of conversations with Large Language Models (LLMs) even when the traffic is fully encrypted. The attack bypasses TLS encryption by analyzing metadata patterns, posing a significant privacy risk to users discussing sensitive subjects.
Key takeaways:
🌐 How it Works: A passive network attacker (like an ISP or on a public Wi-Fi) analyzes the size and timing of encrypted data packets from a streaming LLM response. These patterns create a unique “fingerprint” for different topics.
🔒 Privacy Breach: The attack doesn’t break encryption but makes it possible to classify what a user is asking about. In tests, it identified sensitive topics like “money laundering” with near-perfect accuracy.
🛡️ Industry-Wide Impact: The vulnerability was found to affect 28 popular LLMs from major providers, highlighting a systemic risk in streaming AI services.
💡 Mitigation Deployed: Major providers, including OpenAI, Microsoft, Mistral, and xAI, have already implemented countermeasures like random padding and token batching to obfuscate these traffic patterns after responsible disclosure from Microsoft.
Malicious NuGet Packages with “Time Bombs” Target Industrial Controls
Nine malicious packages on the NuGet repository have been found to contain delayed-action “time bomb” payloads. These packages, downloaded nearly 9,500 times, are set to activate in 2027 and 2028, with the specific goal of sabotaging databases and Siemens S7 industrial control systems (PLCs).
Key takeaways:
💣 Delayed Payload: The malware is a “time bomb,” designed to lie dormant until specific dates in 2027 and 2028, when its disruptive code is set to activate.
🎯 Critical Targets: The attack targets .NET applications using SQL Server, PostgreSQL, and SQLite, as well as Siemens S7 industrial control systems (PLCs) via the Sharp7Extend package.
🔍 Stealthy Code: The malicious logic is small and hidden within 99% legitimate code, using C# extension methods to inject itself into normal database and PLC operations.
🛡️ Industrial Sabotage: The Sharp7Extend package is built to corrupt PLC write operations after a delay, potentially disabling safety systems and disrupting physical production processes.
🚨 Immediate Audit: All nine packages were published by the user “shanhai666.” Developers must audit their codebases for these packages and assume compromise if any are found.
Phishing Campaign Targets Booking.com Hotels & Customers
A sophisticated phishing campaign is compromising hotel Booking.com accounts, using their official messaging systems to send fake payment demands to customers. This highly convincing scam leverages stolen reservation data to steal guest credit card details.
Key takeaways:
🏨 The attack starts by targeting hotels with phishing emails using a “ClickFix” social engineering tactic, which ultimately installs the PureRAT malware to steal credentials.
✉️ Attackers then pivot, using the compromised hotel’s legitimate Booking.com portal to send fraudulent messages to guests with upcoming reservations.
💳 The scam (dubbed “I Paid Twice”) falsely claims a payment issue exists and directs the guest to a fake payment page to “re-verify” their card, harvesting their financial data.
🛡️ Hotels must train staff to spot advanced phishing and secure portals with 2FA. The initial compromise is often an infostealer or RAT from a malicious email.
🔍 Always be suspicious of payment requests, even if they come through an official app. Never enter payment details from a link in a message; log in to the main website directly to verify your reservation status.
New Report: Your Browser is the New #1 Enterprise Threat Surface
A 2025 security report reveals that identity, SaaS, and AI-related risks are converging on the user’s browser, bypassing traditional EDR, DLP, and SSE controls. This creates a parallel threat surface where unmanaged extensions, personal GenAI accounts, and session token theft dominate.
Key takeaways:
🧠 GenAI is now the top data exfiltration channel, with 77% of employees pasting sensitive data into prompts, often via personal accounts.
🔌 Browser extensions pose a significant, unregulated supply chain risk. 99% of users have one installed, with over half granting high-risk permissions and 26% being sideloaded.
🆔 Identity governance is failing, as 68% of corporate logins happen without SSO. Attackers are targeting browser session tokens and cookies, not just passwords.
💬 SaaS and messaging apps are exfiltrating data via simple copy-paste, with 62% of pastes into chat apps containing sensitive PII/PCI data, mostly via non-corporate accounts.
🛡️ Traditional tools are blind to this “session-native” activity. Security must shift to a new approach that monitors in-browser actions like copy-paste, prompt inputs, and extension activity.
APT37 Hackers Weaponize Google’s ‘Find Hub’ to Wipe Android Devices
North Korean hackers are compromising PCs to steal Google credentials, then using the legitimate ‘Find Hub’ (Find My Device) service to track victims’ GPS locations and remotely factory reset their Android phones.
Key takeaways:
💻 Attack Chain: The attack starts with spear-phishing on a PC, leading to credential theft that gives hackers access to the victim’s Google account.
🔒 Weaponized Feature: Attackers access the legitimate Google ‘Find Hub’ service to remotely locate, lock, and wipe all connected Android devices.
🎯 Tactics: Hackers track the victim’s GPS via ‘Find Hub’ and initiate the device wipe when the victim is away from their computer, maximizing disruption.
🤫 Motive: The goal is to silence mobile security alerts, delete attack traces, and hijack the victim’s PC-based messenger sessions to spread malware to contacts.
🛡️ Mitigation: Enable Multi-Factor Authentication (MFA) on your Google account immediately. Always verify the sender before opening attachments, even on messenger apps.
Rhadamanthys Infostealer Operation Disrupted
The Rhadamanthys malware-as-a-service (MaaS) operation has been significantly disrupted, with its cybercriminal “customers” reporting a widespread loss of access to their web panels and servers used to collect stolen data.
Key takeaways:
🚨 Operations Halted: Multiple threat actors using the Rhadamanthys infostealer have lost SSH access to their servers, which now unexpectedly require certificate-based logins instead of passwords.
🔒 Law Enforcement Action: The malware’s developer suspects German law enforcement is behind the disruption, citing German IP addresses logging into EU-hosted panels just before access was lost.
🛡️ Operation Endgame: This action is believed to be part of the ongoing “Operation Endgame,” a major international law enforcement effort targeting malware-as-a-service infrastructures.
🌐 Significant Blow: While the operation’s Tor sites are also offline, it’s unclear if this is a full takedown. However, the loss of server control deals a major blow to the infostealer’s operations.
💡 What is Rhadamanthys?: A potent infostealer that steals credentials and authentication cookies from browsers, email clients, and other apps, often spread via malicious ads and software cracks.
Hackers Abuse Triofox AV Feature for RCE Attacks
Threat actors exploited a critical auth bypass flaw (CVE-2025-12480) in Gladinet’s Triofox platform to abuse its built-in antivirus feature, allowing them to achieve remote code execution with SYSTEM-level privileges.
Key takeaways:
🚨 Critical Flaw: The vulnerability stemmed from an access control gap where admin access was granted if the request URL host was spoofed to ‘localhost’ via the HTTP Host header.
🛠️ Weaponized Feature: Attackers exploited this flaw to access setup pages, create a new admin account, and then configure the platform’s antivirus scanner to run a malicious script.
🛡️ Privilege Escalation: The “antivirus” script inherited SYSTEM privileges from the parent Triofox process, enabling the attackers to deploy remote access tools like Zoho Assist and AnyDesk.
🌐 Lateral Movement: Post-exploitation, the threat actors used Plink and PuTTY to create SSH tunnels, forwarding traffic to the compromised host’s RDP port for further network movement.
💡 Action Required: Administrators are urged to update to Triofox version 16.10.10408.56683 or later, audit admin accounts, and verify that the AV engine is not configured to run unauthorized scripts.
Google Threat Intelligence Group (GTIG)
UK Introduces New Laws to Harden Critical Infrastructure
The UK has introduced the Cyber Security and Resilience Bill, a major overhaul of its laws to protect essential services like hospitals, energy, and water from cyber-attacks. This move addresses the growing threat and aims to prevent massive disruptions to the UK’s economy and national security.
Key takeaways:
🛡️ Wider Scope: The new laws expand on the 2018 NIS Regulations to include managed IT service providers (MSPs), data centers, and even smart energy infrastructure for the first time.
🚨 Strict Incident Reporting: Significant cyber incidents must be reported to the NCSC within 24 hours, with full reports due in 72 hours, ensuring rapid response and awareness.
⛓️ Supply Chain Security: Regulators can now designate “critical suppliers” (e.g., healthcare diagnostic providers) and mandate that they meet minimum security standards, tackling supply chain vulnerabilities.
💸 Tougher Penalties: The legislation introduces turnover-based fines for serious breaches, making robust cybersecurity a more cost-effective option than cutting corners.
Department for Science, Innovation and Technology
Google Sues to Dismantle Chinese Phishing-as-a-Service Platform Behind US Toll Scams
Google has filed a lawsuit to disrupt “Lighthouse,” a sophisticated Phishing-as-a-Service (PhaaS) platform operated by Chinese threat actors. This platform enabled a massive wave of “smishing” (SMS phishing) attacks impersonating US road toll services and package delivery to steal credit card data from over a million victims.
Key takeaways:
💡 Phishing-as-a-Service (PhaaS): The platform provided cybercriminals with a full suite of tools, including phishing templates, hosting, and support, for a subscription fee, making it easy for low-skill attackers to launch large-scale campaigns.
📱 Massive “Smishing” Campaign: The primary attacks involved text messages claiming “unsettled toll charges” from services like E-ZPass, tricking users into entering personal information and payment details on spoofed websites.
☁️ Infrastructure Abuse: The operators utilized legitimate services for their infrastructure and created over 100 phishing templates that exploited Google’s branding to appear legitimate, thereby violating trademark and anti-fraud laws.
🛡️ Legal Takedown: Google’s lawsuit uses federal racketeering and fraud statutes (including RICO and the CFAA) to dismantle the platform’s infrastructure and block the operators, highlighting a multi-pronged strategy to combat cybercrime.
Third-Party Vendor Breach Hits DoorDash: Customer Info Stolen
DoorDash is notifying customers of a data breach resulting from a successful phishing attack on a third-party vendor in October. The breach exposed sensitive user information, including names, emails, phone numbers, and delivery addresses.
Key takeaways:
🌐 Supply Chain Vulnerability: The attack succeeded by compromising a third-party vendor via phishing, highlighting the persistent risk of interconnected services.
🔒 PII Exposed: Stolen data includes customer names, email addresses, phone numbers, and physical delivery addresses. Payment and password data were reportedly not affected.
🚨 High Phishing Risk: Attackers will almost certainly use this specific data to launch highly targeted phishing scams. Be extremely vigilant of any communications asking for login or payment details.
🛡️ User Action: All users should watch for suspicious emails/texts, enable multi-factor authentication (MFA) on their DoorDash account, and never click links from unverified sources.
New Kraken Ransomware ‘Benchmarks’ Systems Before Encrypting
A sophisticated new ransomware variant, Kraken, is actively benchmarking victim systems before launching its main attack. This allows it to choose the most efficient encryption method to maximize damage while evading detection.
Key takeaways:
🔬 Performance Analysis: Kraken first assesses a system’s performance to determine how quickly it can operate without causing a system overload that might trigger security alerts.
⚡ Optimized Attack: Based on the benchmark, the ransomware selects the most effective strategy (like full or partial encryption) to operate with maximum speed and minimal resource usage.
🛡️ Stealth & Evasion: This novel benchmarking feature is designed to ensure maximum damage in minimal time, helping the malware evade detection tools that monitor for high resource exhaustion.
🌐 Cross-Platform Threat: Kraken is a significant enterprise threat, with distinct encryptors built for Windows, Linux, and VMware ESXi environments.
“IndonesianFoods” Worm Floods npm with 100,000+ Packages
A massive package-flooding attack, dubbed “IndonesianFoods,” has overwhelmed the npm registry with over 100,000 junk packages. This campaign appears to be a stress test or setup for a future large-scale dependency confusion attack.
Key takeaways:
🌊 Massive Flood Attack: Over 100,000 packages were published to npm in a short period, all named after various Indonesian foods, in a highly automated “worm-like” fashion.
💡 No Active Payload (Yet): Researchers note the packages are currently placeholders and do not contain malicious code, suggesting this is a preparatory phase or a test of npm’s limits.
🎯 Dependency Confusion Risk: The high volume is a classic setup for dependency confusion or typosquatting, aiming to trick developers into accidentally installing a malicious package instead of a legitimate one.
🛡️ Supply Chain Stress Test: This incident highlights the vulnerability of open-source registries to large-scale automated attacks, posing a significant risk to the software supply chain.
Popular Android Photo Frames Ship with Malware
Security researchers have found that popular Android-based digital photo frames, particularly those using the “Uhale” platform, are downloading and executing malware upon startup. These compromised devices are reportedly connecting to the Vo1d botnet and Mzmess malware families, turning a simple picture frame into a security risk.
Key takeaways:
🌐 Supply Chain Attack: Devices are compromised “out-of-the-box,” downloading malicious payloads from servers in China after their initial boot and app update process.
🦠 Botnet & Malware: Payloads are linked to the Vo1d botnet and Mzmess malware, turning the photo frame into a remotely controlled zombie device on your network.
🔒 Fundamentally Insecure: Many of the tested frames are shipped already rooted, with SELinux disabled, and using public AOSP test-keys, meaning they are “fully compromised out of the box”.
🛡️ Multiple Critical Flaws: Researchers discovered 17 other security issues, including command injection and insecure update processes that allow for remote code execution as root.
Top Tips of the Week

Threat Intelligence
- Regularly update and validate your CTI. Keep it current, relevant, and aligned with the evolving threat landscape.
- Integrate threat intelligence into threat modeling. Enhance your security posture by identifying potential threats early in the development process.
Threat Hunting
- Foster a mindset of continuous learning in cyber threat hunting. Encourage your team to stay updated on the latest threat trends and technologies.
- Incorporate threat intelligence into cyber threat hunting. Stay ahead with up-to-date insights on emerging threats.
- Stay aware of geopolitical events. Understand global impacts on cyber threats and adjust your strategy accordingly.
- Foster a culture of information sharing in cyber threat hunting. Open communication channels enhance the collective ability to respond to threats.
Custom Tooling
- Collaborate with your team when creating custom tools. Multiple perspectives can lead to more robust and effective solutions.
Feature Article
Ever feel like Cyber Threat Intelligence requires you to be a malware-reversing, Mandarin-speaking data scientist all in one?
It’s an overwhelming field to break into, but this video lays out a “zero to hero” roadmap to demystify it.
It’s all built on three core pillars:
💻 Pillar 1: The Technical Foundation.
You can’t track an adversary if you don’t understand the battlefield. This is where you master core SOC skills, learn the MITRE ATT&CK framework as your common language, and use Python to automate the boring stuff (not become a full-stack dev!).
🧠 Pillar 2: The Analyst Tradecraft.
This is the “intelligence” in CTI. It’s about learning the formal intelligence cycle, using Structured Analytical Techniques (SATs) to combat your own cognitive biases, and transitioning from tactical (“block this IP”) to strategic (“here’s what they’ll target next quarter”).
✍️ Pillar 3: The Soft Skill Amplifier.
This is the most overlooked, yet most critical, pillar. Your brilliant analysis is worthless if it stays in your head: “You are a professional writer who just happens to be a cyber security expert”. Your report is the product.
This video breaks down the books, courses, and other learning resources you can use to conquer each of these pillars! No affiliate links, no paid promotions, just actionable advice.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



