Triaging the Week 101

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Resecurity’s “Honeypot” Defense: Hackers Duped by Decoy Data

In a striking display of active deception, the cybersecurity firm Resecurity successfully neutralized a breach attempt by the “Scattered Lapsus$ Hunters” group using a high-fidelity honeypot. While the threat actors claimed to have stolen massive amounts of internal data, they were actually interacting with synthetic datasets and isolated systems designed specifically to monitor their behavior.

Key takeaways:

🚨 The False Claim: Threat actors publicly announced “full access” to Resecurity’s systems, claiming they exfiltrated employee data, client lists, and internal chats.

💡 Strategic Deception: Resecurity detected the initial reconnaissance in November 2025 and responded by deploying a monitored, isolated environment populated with over 218,000 synthetic records.

🕵️‍♂️ Actionable Intelligence: The operation allowed researchers to capture the attackers’ Tactics, Techniques, and Procedures (TTPs) and even identify real IP addresses during proxy failures, which have been shared with law enforcement.

🛡️ Active Defense: This incident demonstrates that proactive deception can be an effective tool for threat attribution and protecting actual production environments from high-level adversaries.

🌐 Global Reach: The attackers utilized automated tools and residential proxies to mask their origin, highlighting the sophisticated automation used by modern cybercriminal collectives.

BleepingComputer

Over 10,000 Fortinet Firewalls Exposed to Critical 2FA Bypass Attacks

More than 10,000 internet-facing Fortinet firewalls remain unpatched against a five-year-old critical security flaw that allows attackers to bypass two-factor authentication (2FA). Threat actors are currently exploiting this legacy vulnerability to gain unauthorized access to enterprise networks through SSL VPN gateways.

Key takeaways:

🚨 Active Exploitation: The CVE-2020-12812 vulnerability (Severity 9.8/10) is being targeted in the wild to bypass FortiToken 2FA requirements.

🔓 Simple Bypass Method: Attackers can circumvent authentication by simply changing the case of a username when LDAP is enabled in the system configuration.

📅 Legacy Threat Persistence: Although Fortinet released patches in July 2020, security watchdog Shadowserver reports thousands of devices remain unpatched and exposed globally.

🛠️ Immediate Action Required: Organizations must upgrade to secure FortiOS versions (6.4.1, 6.2.4, 6.0.10 or later) or disable username case-sensitivity as a temporary safeguard.

🕵️‍♂️ State-Sponsored Target: CISA and the FBI have previously warned that state-sponsored groups and ransomware actors frequently use this flaw to backdoor critical networks.

BleepingComputer

Google Cloud Abuse: Phishing Bypasses Security Filters via Trusted Infrastructure

Cybercriminals are weaponizing Google Cloud’s automation tools to distribute highly convincing phishing emails that originate from legitimate Google domains, effectively evading traditional security filters. This sophisticated “Living off the Cloud” campaign leverages the inherent trust of Google’s infrastructure to target thousands of organizations worldwide.

Key takeaways:

🚨 Legitimate Domain Abuse: Attackers misused Google Cloud’s “Application Integration” service to send emails from [email protected], ensuring messages bypass DMARC and SPF checks.

🛡️ Multi-Stage Redirection: The attack chain uses a series of trusted hops—including storage.cloud.google.com and googleusercontent.com—to host malicious links and lower recipient suspicion.

🤖 Scanner Evasion: The campaign employs a fake CAPTCHA phase that acts as a barrier, successfully blocking automated security tools and scanners from scrutinizing the final attack infrastructure.

🔑 High-Value Objectives: The primary goal is harvesting Microsoft 365 credentials and executing OAuth consent phishing to gain persistent, unauthorized access to cloud resources.

🔒 Broad Industry Impact: Over 9,000 phishing emails targeted approximately 3,200 customers across manufacturing, finance, and technology sectors during a single 14-day period in December 2025.

Check Point

Cloud File-Sharing Sites Targeted by “Zestix” in Major Corporate Data Theft Campaign

A threat actor known as Zestix is advertising terabytes of stolen data from dozens of organizations after breaching their ShareFile, Nextcloud, and OwnCloud instances. The attacks highlight a systemic failure in basic security hygiene and session management across multiple sectors, including defense, healthcare, and government.

Key takeaways:

🚨 Infostealer Entry Points: Attackers are leveraging credentials harvested by malware like RedLine, Lumma, and Vidar, which are frequently spread via malvertising and “ClickFix” phishing tactics.

🔓 Absence of MFA: Unauthorized access is primarily achieved by logging into cloud services with valid credentials where Multi-Factor Authentication (MFA) has not been implemented, making the breach as simple as a standard login.

📁 Massive Data Exposure: Stolen archives include sensitive defense contracts, healthcare records, aircraft maintenance manuals, and network configurations, creating severe risks for industrial espionage and national security.

⏳ Stale Credential Risks: Intelligence shows that some exploited credentials have been available in criminal databases for years, indicating a critical failure to rotate passwords or terminate old sessions.

🛡️ Urgent Defenses: To mitigate this threat, organizations must enforce mandatory MFA, monitor for infostealer infections on employee hardware, and implement regular secret rotation to invalidate old data.

Hudson Rock

Think Your Computer Just Crashed? It Might Be a ClickFix Trap!

A sophisticated new “ClickFix” social engineering campaign is targeting the hospitality sector in Europe by using fake Windows Blue Screen of Death (BSOD) screens to trick users into manually installing malware. Attackers use high-fidelity clones of Booking.com to lure staff into executing malicious PowerShell commands under the guise of “fixing” a system crash.

Key takeaways:

💻 Deceptive Full-Screen Hijacking: The attack triggers browser full-screen mode to display a realistic Windows BSOD, making it nearly indistinguishable from a legitimate system failure.

⌨️ Clipboard Command Manipulation: Victims are instructed to open the Windows “Run” dialog and paste (Ctrl+V) a malicious command that the website has silently copied to their clipboard.

🏨 Exploiting Industry Urgency: Phishing emails impersonating Booking.com reservation cancellations create a high-pressure environment for hospitality staff, increasing the likelihood they will follow “recovery” instructions without hesitation.

⚙️ Multi-Stage Malware Deployment: Executing the command installs the DCRAT remote access trojan, which can log keystrokes, hijack desktops, and even deploy cryptocurrency miners while bypassing Windows Defender.

🛡️ Verify Before You Act: Remember that a real Windows BSOD never provides interactive recovery steps asking you to paste or execute terminal commands—always treat such prompts as a high-risk security threat.

🎯 Threat Hunting Package

Secureonix

New VVS Stealer Malware: Is Your Discord Account Being Sold for €10?

Cybersecurity researchers have uncovered VVS Stealer (also known as VVS $tealer), a stealthy Python-based malware being sold on Telegram that specifically targets Discord users and browser data. This “ultimate stealer” uses advanced obfuscation to hijack active Discord sessions and siphon sensitive information, ranging from credit card details to private screenshots.

Key takeaways:

🚨 Advanced Obfuscation: The malware uses Pyarmor and PyInstaller to bypass traditional antivirus detection, making it highly effective at remaining undetected on infected systems.

🐍 Discord Injection Attacks: VVS Stealer doesn’t just steal tokens; it injects malicious JavaScript into the Discord client to hijack active sessions and monitor network traffic via Chrome DevTools.

📦 Comprehensive Data Harvesting: Beyond Discord, it extracts passwords, cookies, and autofill data from Chromium and Firefox browsers, compressing the stolen data into ZIP archives for exfiltration.

💸 Low Barrier to Entry: With subscriptions starting as low as €10 per week, this malware is widely accessible to entry-level cybercriminals, increasing the scale of potential attacks.

🛡️ Persistence & Deception: It ensures longevity by adding itself to the Windows Startup folder and uses fake “Fatal Error” pop-ups to trick users into restarting their devices.

🎯 Threat Hunting Package

Palo Alto Unit42

A newly discovered critical security flaw (CVE-2026-0625) in legacy D-Link DSL gateway routers is currently under active exploitation, allowing unauthenticated remote attackers to execute arbitrary shell commands and hijack DNS settings. As these devices have reached end-of-life status and are no longer patchable, they represent a significant and persistent risk to any network environment they support.

Key takeaways

🚨 Critical Severity: Tracked as CVE-2026-0625 with a CVSS score of 9.3, the flaw involves command injection in the “dnscfg.cgi” endpoint due to improper sanitization.

🌐 DNS Hijacking Risk: Attackers can silently redirect, intercept, or block downstream traffic, effectively gaining direct control over DNS settings without requiring credentials.

⚠️ No Patches Available: Impacted models—including the DSL-2640B, DSL-2740R, and DSL-2780B—are End-of-Life (EoL) and will not receive firmware updates to address this threat.

🛡️ Urgent Mitigation: Experts strongly advise that owners of these legacy gateway products retire them immediately and upgrade to actively supported hardware.

🕵️‍♂️ Ongoing Exploitation: Malicious activity was recorded as early as November 2025, indicating that threat actors are actively scanning for and compromising these vulnerable units in the wild.

Field Effect

Taiwan’s Energy Sector Faces Staggering 10x Surge in Cyberattacks

Taiwan has reported a massive escalation in cyberactivity targeting its energy infrastructure, with monthly attacks jumping from 100,000 to over one million. This surge highlights a concerted effort by state-sponsored actors to infiltrate and potentially destabilize critical national power systems through persistent probing and espionage.

Key takeaways

🚨 Massive Escalation: Cyberattacks against Taiwan’s energy sector have increased tenfold, signaling a shift from routine scanning to aggressive, high-volume targeting.

🌐 Nation-State Threats: The Bureau of Energy attributes the majority of these sophisticated campaigns to Chinese state-sponsored actors aiming to weaken regional resilience.

🛡️ Strategic Pre-positioning: Analysts warn that these incursions are likely designed for “pre-positioning”—gaining long-term access to trigger potential sabotage during future geopolitical conflicts.

🔒 Focus on Resilience: In response to the over 12 million annual attacks, Taiwan is aggressively fortifying its grid defenses to prevent catastrophic outages and data breaches.

💡 A Global Warning: This trend underscores the urgent need for critical infrastructure providers worldwide to adopt “Assume Breach” mindsets and harden industrial control systems.

Taiwan’s National Security Bureau (NSB)

“Prompt Poaching” Alert: Over 900,000 Users Affected by Malicious AI Chrome Extensions

Cybersecurity researchers have uncovered two malicious Chrome extensions—”Chat GPT for Chrome” and “AI Sidebar”—that are actively exfiltrating private ChatGPT and DeepSeek conversations alongside full browsing histories. These rogue tools impersonate legitimate AI assistants to trick users into granting broad data permissions under the guise of providing “anonymous analytics.”

Key takeaways

🚨 Targeted AI Data Theft: This campaign, codenamed “Prompt Poaching,” specifically harvests entire AI chatbot sessions, potentially exposing sensitive corporate intellectual property, customer data, and personal secrets.

🎭 Deceptive Tactics: The extensions impersonate popular tools and even leveraged Chrome’s “Featured” badge status to build false trust while silently sending harvested data to a C2 server every 30 minutes.

🌐 Massive Scale: With over 900,000 collective installations, the reach of this data exfiltration is vast, representing a significant breach of privacy for both individual users and organizations.

🛡️ Immediate Action Required: Check your browser for extensions named “Chat GPT for Chrome with GPT-5” or “AI Sidebar” and remove them immediately to stop active data exfiltration.

🔒 Enterprise Risk: This incident highlights the need for strict browser extension policies; one “anonymous” click can bypass traditional security layers and leak your most sensitive AI-driven workflows.

🎯 Threat Hunting Package

OX Security

The UK’s £210M Cyber Reset

The UK government has launched a major £210 million “Government Cyber Action Plan” to overhaul public sector defenses and establish a new centralized Cyber Unit. This strategy marks a shift toward mandatory standards to protect vital services like the NHS and national infrastructure from increasingly sophisticated threats.

Key takeaways

🚨 Centralized Oversight: A new “Government Cyber Unit” will now centralize risk management and coordinate incident responses across all departments to eliminate defensive gaps.

🔒 Mandatory Security Standards: The plan moves away from voluntary guidance, introducing strict minimum security requirements that departments must meet to protect citizen data.

🤝 Public-Private Collaboration: A “Software Security Ambassador Scheme” involving firms like Cisco and Palo Alto Networks will promote best practices and strengthen the software supply chain.

🚫 No-Ransom Mandate: Backed by the Cyber Security and Resilience Bill, the strategy reinforces a ban on public-sector ransom payments to discourage criminal targeting.

📈 Leadership Accountability: Senior leaders will be held responsible for cyber outcomes, ensuring security is treated as a core business risk rather than just a technical issue.

Department of Science, Innovation and Technology

Stop Hackers from Stealing Secrets via jsPDF-Generated Documents

A critical vulnerability has been discovered in the widely used jsPDF library, which could allow attackers to execute Server-Side Request Forgery (SSRF) attacks. This flaw enables malicious actors to exfiltrate sensitive internal data and cloud metadata by hiding it within seemingly harmless generated PDF files.

Key takeaways

🚨 Critical SSRF Risk: The flaw (tracked as CVE-2024-43369) allows hackers to trick a server into fetching internal resources, bypassing traditional network perimeters.

🔒 Secret Exfiltration: Attackers can exploit this to embed sensitive secrets—such as AWS/Azure metadata or internal configuration files—directly into the PDF documents your application generates.

🌐 Massive Impact Surface: As one of the most popular JavaScript libraries for PDF generation, this vulnerability affects thousands of web applications and services globally.

🛡️ Immediate Patching Required: Security teams and developers must prioritize updating to jsPDF version 2.5.2 or later to mitigate this risk.

💡 Audit Your Dependencies: This is a stark reminder to regularly scan your Software Bill of Materials (SBOM) for hidden risks in popular third-party libraries.

Endor Labs

GoBruteforcer Botnet Targets Crypto and Blockchain Infrastructure

A new and aggressive wave of GoBruteforcer attacks is currently targeting PHP-based web applications within the cryptocurrency and blockchain sectors. This Golang-based botnet uses sophisticated brute-forcing techniques to breach servers, deploy web shells, and pivot through internal networks to compromise high-value data.

Key takeaways

🌐 High-Value Targets: Attackers are specifically focusing on the crypto and blockchain industry, looking for weak points in web-facing PHP services like phpMyAdmin and MySQL.

🚨 Multi-Vector Assault: The botnet systematically brute-forces common services, including FTP, SSH, and database management tools, to find an entry point.

🦠 Lateral Movement: Once a single node is compromised, the malware scans the entire internal network to spread its reach and maximize the impact of the breach.

🛡️ Stealthy Execution: By leveraging the Golang programming language, the botnet is designed to be cross-platform and more difficult for traditional antivirus solutions to detect.

💡 Critical Defense: Organizations must prioritize hardening their external perimeters by enforcing strong password policies, implementing Multi-Factor Authentication (MFA), and disabling unnecessary public-facing services.

🎯 Threat Hunting Package

Check Point

New China-Linked Hackers Breach Telcos Using Edge Device Exploits

A sophisticated China-linked threat actor, tracked as UAT-7290, has expanded its cyber-espionage operations to target telecommunications providers in Southeastern Europe. By exploiting public-facing edge devices to establish an Operational Relay Box (ORB) infrastructure, the group facilitates persistent, stealthy access for wider state-aligned intelligence gathering.

Key takeaways:

🕵️‍♂️ Exploitation of Edge Hardware: The group leverages “one-day” exploits and target-specific SSH brute forcing to compromise edge network devices, emphasizing the urgent need for organizations to harden public-facing hardware and enforce robust authentication.

🦠 Specialized Linux Malware Suite: UAT-7290 utilizes a modular arsenal, including the RushDrop initial dropper and the plugin-based SilentRaid implant, which allows for remote shell access, file exfiltration, and lateral movement within critical networks.

🌐 Operational Relay Box (ORB) Stealth: Through the Bulbature implant, compromised devices are converted into relay nodes, enabling the threat actor to mask its traffic and provide persistent pivot points for other China-nexus hacking groups.

🔍 Advanced Evasion Tactics: The malware employs anti-analysis checks, hidden directories (such as .pkgdb), and Google’s public DNS resolvers to stay hidden from traditional detection mechanisms and security filters.

🛡️ Proactive Defense Mandate: To mitigate this risk, security teams must prioritize the immediate patching of known edge vulnerabilities and monitor systems for the specific Indicators of Compromise (IoCs) associated with the UAT-7290 toolkit.

🎯 Threat Hunting Package

Cisco Talos

NodeCordRAT Hides in Plain Sight via Steganography

Cybersecurity researchers have identified a sophisticated Remote Access Trojan (RAT) dubbed NodeCordRAT that utilizes steganography to conceal malicious code within seemingly harmless image files. This campaign targets users by bypassing traditional security perimeters, allowing attackers to gain persistent remote control and harvest sensitive data without detection.

Key takeaways:

🚨 Steganographic Camouflage: NodeCordRAT hides its payload inside the pixels of image files (like PNGs), making it nearly invisible to standard antivirus tools that only scan for known malicious file signatures.

🔒 Cross-Platform Risk: Built using Node.js, this malware is designed to be highly adaptable, targeting various environments and leveraging common frameworks to maintain a low profile.

💡 Advanced Surveillance Capabilities: Once the RAT is executed, it grants attackers the ability to capture screenshots, log keystrokes, and exfiltrate credentials, leading to full account and system takeover.

🛡️ Detection Challenges: Because the malicious activity is triggered by a “clean” looking file, organizations must rely on behavioral analysis and deep file inspection to identify these hidden threats.

🌐 Evolving Attack Vectors: The use of steganography marks a shift toward more “fileless” and obfuscated techniques, requiring a proactive shift in how security teams validate incoming media assets.

Zscalar

11 Critical Vulnerabilities Discovered in Coolify

Researchers have identified 11 critical security flaws in Coolify, a popular open-source self-hosting platform, that could enable a complete server takeover via Remote Code Execution (RCE). These vulnerabilities expose self-hosted environments to unauthorized access and privilege escalation, making immediate patching a top priority for all administrators.

Key takeaways:

🚨 High-Impact RCE Risks: Multiple vulnerabilities allow unauthenticated attackers to execute arbitrary commands on the host system, bypassing security controls to gain full administrative access.

🔒 SSH Key Exposure: One of the most severe flaws involves the insecure handling of private SSH keys, which could allow an attacker to pivot from the application to the underlying infrastructure.

🛡️ Critical Patch Available: Users must update to Coolify version 4.0.0-beta.350 or higher immediately to close these security gaps and protect their data.

🌐 Targeting Self-Hosted PaaS: These disclosures highlight the growing risks associated with self-hosted “Platform-as-a-Service” (PaaS) tools that manage sensitive deployment credentials.

💡 Security Best Practices: In addition to patching, ensure your management dashboards are behind a VPN or restricted to trusted IP addresses to minimize the attack surface.

The Hacker News


Feature Video

How many times did you open the MITRE ATT&CK website yesterday? 

If you’re like most CTI analysts, that number is somewhere between 30 and 60. And every single lookup is silently killing your productivity.

Here’s what I learned about reclaiming your focus:

🧠 Research shows it takes 23 minutes to return to peak focus after an interruption—even a brief one. Those “quick” ATT&CK lookups aren’t quick at all.

⏱️ 40 lookups/day × 45 seconds = 30 minutes of daily overhead. That’s 130+ hours per year lost to managing browser tabs.

🔧 The ATT&CK Powered Suit is a free browser extension that embeds the entire framework into your workflow. Right-click any text, get instant results. No tab switching required.

🏢 500+ security teams already use it—including JPMorgan Chase, Microsoft, and Verizon.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools