Triaging the Week 099

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

‘React2Shell’ Flaw Exploited to Breach 30 Organizations

State-sponsored actors are actively exploiting a critical, maximum-severity vulnerability (CVSS 10.0) in React and Next.js, with reports confirming breaches in at least 30 organizations. Security researchers warn that over 77,000 IP addresses remain exposed to this unauthenticated remote code execution flaw.

Key takeaways:

🌐 Widespread Impact: Approximately 77,000 internet-exposed IP addresses are currently vulnerable to the “React2Shell” (CVE-2025-55182) flaw, with 30 organizations already confirmed compromised.

🕵️ Active Exploitation: China-linked threat groups, including Earth Lamia and Jackpot Panda, are weaponizing the flaw to execute arbitrary code and deploy malware.

⚙️ Technical Root Cause: The vulnerability stems from unsafe deserialization in the “Flight” protocol used by React Server Components (RSC) and Next.js, allowing attacks via a single malicious HTTP request.

🛡️ Immediate Action Required: Organizations using React 19.x or Next.js 15.x/16.x must patch immediately to fixed versions (e.g., React 19.0.1+, Next.js 16.0.7+) to prevent full system compromise.

🦠 Post-Exploitation Risks: Successful breaches have led to credential theft, lateral movement, and the deployment of cryptominers and remote access trojans.

BleepingComputer

A new FinCEN report analyzing nearly 4,200 incidents from 2022 to 2024 reveals that ransomware actors extorted over $2.1 billion, with 2023 marking a record-breaking year for criminal profits. While 2024 saw a notable decline in payments due to targeted law enforcement disruptions, the threat landscape remains highly volatile for critical infrastructure.

Key takeaways:

💰 Historic Losses: Between January 2022 and December 2024, organizations paid over $2.1 billion in ransoms, nearly equaling the total reported in the previous eight years combined (2013-2021).

📉 Impact of Disruption: Total ransom payments fell from a peak of $1.1 billion in 2023 to $734 million in 2024, a decrease directly attributed to operations targeting major groups like ALPHV/BlackCat and LockBit.

🎯 Targeted Sectors: The Manufacturing, Financial Services, and Healthcare industries suffered the most attacks, with Financial Services reporting the highest total dollar losses at approximately $365.6 million.

🏴‍☠️ Top Threat Actors: The Akira gang led in incident volume (376 reports), while ALPHV/BlackCat generated the highest revenue (~$395 million), followed by LockBit (~$252.4 million).

🪙 Crypto Dominance: Bitcoin remains the currency of choice for cybercriminals, accounting for 97% of all tracked ransomware payments.

FinCEN

Malicious VSCode Extensions Dropping Infostealers Found on Microsoft’s Registry

Two malicious extensions, “Bitcoin Black” and “Codo AI,” have been discovered on the Visual Studio Code Marketplace, targeting developers with info-stealing malware. These extensions, masquerading as a theme and an AI assistant, execute hidden scripts to deploy malware capable of stealing credentials, crypto wallets, and browser sessions.

Key takeaways:

🕵️ Deceptive Tactics: The extensions disguised themselves as legitimate tools—a “Bitcoin Black” color theme and a “Codo AI” assistant—to trick developers into installing them.

🦠 Malicious Payload: Once installed, they execute hidden batch scripts to download a malicious DLL and a legitimate Lightshot executable, using DLL hijacking to launch the infostealer “runtime.exe”.

🔓 Data Theft: The malware targets sensitive data, including system info, clipboard content, WiFi credentials, screenshots, and cryptocurrency wallets like Phantom and Metamask.

🌐 Browser Hijacking: It launches Chrome and Edge in headless mode to steal stored cookies and hijack active user sessions, bypassing standard authentication.

🛡️ Risk Mitigation: Developers are urged to verify publishers carefully, as even low-download extensions can pose severe risks; check for red flags like unnecessary permissions or suspicious scripts.

Koi Security

Google Chrome Unveils ‘User Alignment Critic’ to Secure Gemini AI Agentic Browsing

Google has introduced a sophisticated security architecture for Chrome’s upcoming Gemini-powered agentic browsing features, designed to protect users from indirect prompt injection and unauthorized actions. This new system employs a “User Alignment Critic” model to independently vet AI decisions before execution.

Key takeaways:

🤖 User Alignment Critic: A dedicated, isolated LLM acts as a “high-trust” component to verify every AI action against the user’s goals, blocking malicious attempts to manipulate the agent.

🚧 Agent Origin Sets: Chrome will strictly limit the AI’s access to only task-relevant websites, preventing cross-site data leakage and containing the “blast radius” of a compromised agent.

👤 Mandatory User Oversight: Sensitive actions—such as financial transactions, medical data access, or password usage—will trigger a mandatory pause, requiring manual user confirmation to proceed.

🕵️ Prompt Injection Defense: A specialized classifier runs in parallel to detect and block indirect prompt injection attempts hidden in malicious web content or user reviews.

💰 Bug Bounty Program: Google is offering up to $20,000 in rewards for security researchers who can successfully bypass these new agentic defenses to strengthen the framework.

Google Security Blog

Ransomware Gangs Adopt ‘Shanya’ Packer to Hide EDR Killers

A new packer-as-a-service called “Shanya” has become a go-to tool for major ransomware gangs, allowing them to cloak “EDR killers” and stealthily dismantle security defenses before encrypting networks. Security researchers warn that this advanced obfuscation service is fueling a surge in sophisticated attacks by groups like Medusa, Qilin, and BlackSuit.

Key takeaways:

📦 Packer-as-a-Service: Shanya (also known as “VX Crypt”) is a commercial obfuscation service sold on underground forums, enabling multiple ransomware groups to bypass detection using the same advanced techniques.

⚔️ EDR Killer Deployment: The packer is primarily used to hide tools that terminate Endpoint Detection and Response (EDR) agents, often leveraging the “Bring Your Own Vulnerable Driver” (BYOVD) technique to disable security software.

🛡️ Advanced Evasion: Shanya employs complex evasion techniques, including “junk code” insertion, API hashing, and unhooking mechanisms, to evade security tools and frustrate manual analysis.

🌐 Widespread Adoption: Beyond ransomware, the packer has been observed delivering various other malware strains, including the BumbleBee loader and Lumma information stealer.

🤝 Cross-Gang Collaboration: The shared use of Shanya suggests a level of tool/knowledge leakage or coordination between competing ransomware cartels, complicating defense efforts.

🎯 Threat Hunting Package

Sophos

North Korea-Linked Actors Exploit Critical React2Shell Flaw to Deploy EtherRAT

North Korean threat actors are actively exploiting a maximum-severity vulnerability in React Server Components (CVE-2025-55182) to deploy “EtherRAT,” a stealthy new malware that leverages Ethereum smart contracts for command-and-control. This campaign marks a significant shift toward persistent, long-term espionage, with strong overlaps with the notorious “Contagious Interview” attacks targeting developers.

Key takeaways:

🚨 Critical Exploit: Attackers are leveraging the “React2Shell” flaw (CVSS 10.0) to execute remote commands and deploy payloads, bypassing traditional defenses with high-severity impact.

🛡️ EtherRAT Malware: The new RAT uses “EtherHiding” to fetch C2 URLs from Ethereum smart contracts via a consensus mechanism across nine public RPC endpoints, making takedowns extremely difficult.

🔒 Extreme Persistence: To ensure long-term access, the malware establishes persistence using five different Linux mechanisms, including Systemd services, Cron jobs, and .bashrc injection.

🕵️‍♂️ Campaign Evolution: The activity links back to the “Contagious Interview” campaign, known for using fake job offers to lure Web3 developers, but now demonstrates more sophisticated, stealthy tradecraft.

💻 New Attack Vector: Recent variants also target Microsoft VS Code users by tricking them into cloning malicious repositories that auto-execute code via a manipulated tasks.json file.

Sysdig

Fortinet Alerts on Critical Authentication Bypass Flaws in FortiCloud SSO

Fortinet has issued urgent security updates to address two critical vulnerabilities in FortiOS, FortiWeb, and other products that could allow attackers to bypass FortiCloud SSO authentication using malicious SAML messages. Administrators are strongly advised to patch immediately or temporarily disable the affected feature to prevent unauthorized access.

Key takeaways

🚨 Critical Flaws: Two severe vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affect FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb, enabling authentication bypass.

🔓 Attack Vector: Threat actors can exploit improper cryptographic signature verification by sending a crafted SAML message to vulnerable devices.

🛠️ Mitigation: If immediate patching isn’t possible, admins should disable the “Allow administrative login using FortiCloud SSO” feature via the GUI or CLI command.

⚠️ Default Settings: The vulnerable feature is not enabled by default but is automatically turned on when an administrator registers the device to FortiCare.

📉 High Risk: Fortinet vulnerabilities are frequent targets for ransomware gangs and state-sponsored groups, making rapid remediation essential.

BleepingComputer

Ivanti Issues Warning on Critical Code Execution Flaw in Endpoint Manager

Ivanti has released a crucial update to patch a high-severity vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) solution. This flaw allows unauthenticated attackers to execute arbitrary code via a cross-site scripting (XSS) attack, potentially compromising administrator sessions and granting full control over the management dashboard.

Key takeaways:

🚨 Critical Vulnerability: CVE-2025-10573 allows unauthenticated attackers to execute arbitrary JavaScript code on the EPM dashboard, leading to potential session hijacking.

🕵️‍♂️ Attack Vector: Attackers can join “fake” managed endpoints to the EPM server to poison the admin dashboard; the exploit triggers when an admin views the poisoned interface.

🛡️ Patch Available: Ivanti has released EPM version 2024 SU4 SR1 to fix the flaw. Administrators are urged to update immediately.

⚠️ Exposure Risk: While Ivanti advises against exposing EPM online, hundreds of instances remain accessible via the internet, primarily in the US, Germany, and Japan.

📉 History of Targeting: Ivanti EPM flaws are frequent targets for threat actors; CISA has previously mandated federal agencies to patch similar vulnerabilities due to active exploitation.

Rapid7

Over 10,000 Docker Hub Images Found Leaking Critical Secrets

A new analysis reveals that thousands of container images on Docker Hub are exposing live credentials, including cloud access tokens and over 4,000 AI model keys, putting major organizations at risk of supply chain attacks.

Key takeaways:

🚨 Massive Exposure: Security researchers found over 10,000 Docker Hub images leaking sensitive secrets, such as live API keys, private SSH keys, and database credentials.

🤖 AI Keys at Risk: The study highlights a surge in leaked AI infrastructure access, with nearly 4,000 keys for models like OpenAI, HuggingFace, and Gemini exposed.

🏢 Major Targets: The leaks impact over 100 organizations, including a Fortune 500 company and a major national bank, granting potential admin access to production environments.

💡 Root Cause: The primary drivers of these leaks remain poor secrets management, such as hardcoding credentials in Dockerfiles or accidentally copying local .env files into public images.

Flare

Spiderman Phishing Kit Entraps European Bank Customers in Real-Time

A sophisticated new Phishing-as-a-Service (PhaaS) toolkit dubbed “Spiderman” is being sold on the dark web, allowing even low-skill attackers to clone European bank login pages and intercept 2FA codes in real-time. This “full-stack” kit lowers the barrier for cybercriminals, enabling them to target major institutions across Germany, Austria, and Spain with terrifying ease.

Key takeaways:

🕷️ Turnkey Fraud: The “Spiderman” kit features a user-friendly control panel that lets criminals deploy pixel-perfect phishing sites for dozens of banks (e.g., Deutsche Bank, ING, CaixaBank) without needing any coding skills.

🔓 Real-Time 2FA Bypass: Unlike static phishing pages, this toolkit captures One-Time Passwords (OTPs) and PhotoTAN codes live, enabling immediate account takeovers and unauthorized transactions before the victim realizes something is wrong.

🛡️ Stealth Mode: To avoid detection by security researchers and automated scanners, the kit employs advanced evasion tactics such as ISP whitelisting, geo-blocking, and device filtering.

📉 Hybrid Threat: Beyond traditional banking, the kit includes modules to harvest cryptocurrency wallet seed phrases (e.g., Ledger, MetaMask), reflecting a dangerous convergence of financial fraud tactics.

Varonis

New DroidLock Android Malware Locks Screens, Steals Data, and Demands Ransom

A dangerous new Android malware strain called DroidLock has been discovered targeting users with screen-locking ransomware tactics and advanced data theft capabilities. Discovered by Zimperium, this threat exploits accessibility permissions to not only hold devices hostage but also gain full remote control over them.

Key takeaways:

🔒 Screen Locker: DroidLock functions primarily as a screen locker, freezing your device with an overlay that demands payment via a Proton email address to avoid “data destruction.”

🕵️ Data Espionage: Unlike simple lockers, DroidLock is a powerful spy tool capable of harvesting SMS messages, call logs, contacts, and even recording audio from the device.

📱 Total Remote Control: The malware includes VNC (Virtual Network Computing) capabilities, allowing attackers to remotely view and control the victim’s screen in real-time.

⚠️ Permission Abuse: To operate, DroidLock tricks users into granting “Accessibility Services” and “Device Admin” rights, which it then abuses to change PINs, factory reset phones, or uninstall other apps.

🛡️ Stay Protected: Google Play Protect has been updated to detect DroidLock. Users are urged to avoid side-loading apps from third-party sites and to strictly review app permissions.

🎯 Threat Hunting Package

Zimperium

Malicious VSCode Extensions Hide Rust Trojan in Fake PNG Files

Hackers have been caught distributing 19 malicious extensions on the official Visual Studio Code Marketplace that conceal a Rust-based trojan within a fake image file. These extensions, disguised as themes, execute malicious code automatically upon startup by leveraging modified dependencies to evade detection.

Key takeaways:

🕵️‍♂️ Stealthy Evasion: Attackers bundled a pre-packaged node_modules folder to bypass npm registry checks, hiding malicious code in modified path-is-absolute or @actions/io packages.

🖼️ Fake Image Payload: The attack utilizes a file named banner.png that isn’t an image at all—it contains a Rust-based trojan and a “living-off-the-land” binary (cmstp.exe).

📦 Targeted Extensions: 19 specific extensions were identified, including “Malkolm Theme,” “PandaExpress Theme,” and “Prada 555 Theme,” all published as version 1.0.0.

🛡️ Immediate Action: Microsoft has removed the offending extensions, but users who installed them should immediately scan their systems for signs of compromise.

🔗 Supply Chain Risk: This highlights the ongoing danger of supply-chain attacks where trusted platforms like the VSCode Marketplace are used to distribute malware to developers.

🎯 Threat Hunting Package

ReversingLabs

UK Fines LastPass £1.2M Over 2022 Breach Affecting 1.6M Users

The UK’s Information Commissioner’s Office (ICO) has fined password management firm LastPass £1.2 million for security failures that allowed attackers to steal the personal data and encrypted vaults of 1.6 million UK users. The regulator ruled that the company failed to implement appropriate security measures, enabling a multi-stage attack that began with a compromised employee device.

Key takeaways:

💰 Significant Penalty: The £1.2 million fine reflects the severity of the failure to secure user data against targeted attacks.

🔓 Home Device Vector: The breach started when hackers exploited a vulnerability in a media app (Plex) on a senior employee’s personal computer to deploy a keylogger.

⚠️ Credential Reuse: The attackers captured the employee’s master password because they used the exact same password for both their personal and corporate vaults.

📉 Data Exposure: Attackers pivoted from the employee’s device to cloud storage backups, stealing encrypted password vaults, email addresses, phone numbers, and billing addresses.

🛡️ Regulatory Warning: The ICO emphasized that firms must harden internal systems and cannot rely solely on “Zero Knowledge” claims when access controls are weak.

The Register

Hackers Exploit Unpatched Gogs Zero-Day to Breach 700+ Servers

Attackers are actively exploiting an unpatched remote code execution (RCE) zero-day vulnerability (CVE-2025-8110) in Gogs, a popular self-hosted Git service, compromising hundreds of Internet-facing servers. The flaw allows threat actors to bypass previous security patches using symbolic links to overwrite system files and execute arbitrary commands.

Key takeaways:

🔓 Zero-Day Exploit: The vulnerability, tracked as CVE-2025-8110, is a path traversal weakness in the PutContents API that bypasses protections for a previous RCE bug (CVE-2024-55947).

🌍 Widespread Impact: Researchers have identified over 1,400 exposed Gogs servers, with more than 700 already showing signs of compromise, such as random 8-character repository names.

🤖 Automated Attacks: The campaign appears to be driven by a single actor using automated tools to deploy malware based on the Supershell C2 framework.

🛠️ No Patch Yet: Gogs maintainers acknowledged the flaw in late October but a patch is still in development; a second wave of attacks began in November.

🛡️ Mitigation Now: Admins should immediately disable “Open Registration,” restrict server access via VPN or allow lists, and scan for suspicious API activity.

🎯 Threat Hunting Package

Wiz


Top Tips of the Week

Triaging the Week Tops Tips of the Week

Threat Intelligence

  • Share threat intelligence with trusted partners. Strengthen collective defense efforts and enhance overall cybersecurity posture.
  • Integrate CTI with vulnerability management. Prioritize patching based on real-time threat intelligence.
  • Integrate threat intelligence into incident response. Proactive measures are as crucial as swift and effective responses.
  • Diversify your CTI sources. A broad range ensures a comprehensive understanding of potential threats.

Threat Hunting

  • Foster a threat hunting community. Collaborate with peers, share experiences, and learn from one another.
  • Trust your instincts. Intuition is a powerful tool in threat hunting. Investigate anything that feels off.

Custom Tooling

  • Consider threat modeling in custom tool design. Identify potential risks and vulnerabilities during the development phase.

Feature Video

Thinking you blocked an attack just because you stopped it at the perimeter? That mindset belongs in 2010. 🛑

The “break one link and win” strategy preached by the original Cyber Kill Chain is failing!  

Modern adversaries don’t just knock on the door—they live in your network. Here is why the Unified Kill Chain might be the meta-model your SOC has been missing:

💀 The Original Kill Chain is Obsolete: It focuses heavily on the perimeter and ignores the critical internal battle—pivoting, privilege escalation, and lateral movement—where the real damage happens. 

🔄 Attacks Are Non-Linear: Attackers can bypass entire phases (like weaponization and delivery) by using stolen credentials. If your model assumes a straight line, you’re blind. 

🤝 The Ultimate Team-Up: Stop pitting frameworks against each other! Use the Unified Kill Chain for the narrative storyboard, MITRE ATT&CK for the specific tactics, and the Diamond Model for event attribution.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools