Triaging the Week 102

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing

The FBI has issued an urgent advisory regarding the North Korean state-sponsored group Kimsuky (APT43) leveraging malicious QR codes to bypass traditional enterprise security. This “quishing” tactic forces victims to move from secured computers to unmanaged mobile devices to steal credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA).

Key takeaways

🕵️‍♂️ Tactical Shift to “Quishing”: Attackers embed QR codes in tailored spear-phishing emails to evade URL inspection, rewriting, and sandboxing tools that typically catch malicious links.

🦠 Mobile-Optimized Harvesting: Scanning these codes redirects users to fraudulent, mobile-optimized login pages impersonating Microsoft 365, Okta, and VPN portals to capture sensitive credentials.

🚨 MFA-Resilient Intrusions: The campaign focuses on session token theft and replay, allowing hackers to hijack cloud identities and maintain persistent access without triggering “MFA failed” alerts.

🛡️ Strategic Targeting: The group is specifically targeting think tanks, academic institutions, and government entities involved in North Korea-related policy and research.

💡 Critical Defenses: Organizations are urged to educate staff on quishing risks, implement secondary verification for unsolicited QR codes, and transition to phishing-resistant MFA.

Federal Bureau of Investigation (FBI)

Your AI Budget is Under Attack: Hackers Hijacking Paid LLM Services

Cybercriminals are now exploiting misconfigured proxy servers to tunnel into premium Large Language Model (LLM) APIs, effectively forcing organizations to foot the bill for their malicious AI activities. By leveraging open proxies, threat actors can bypass geographic restrictions and cost barriers to power their own automated attacks using your paid subscriptions.

Key takeaways

🚨 Exploiting the Proxy Gap: Attackers are using automated scanners to find unsecured HTTP and SOCKS proxies, using them as “stepping stones” to access paid AI services like OpenAI and Claude anonymously.

🔒 Financial & Resource Theft: Beyond data risks, this is a direct hit to the bottom line; victims often discover the breach only after receiving massive, unexpected invoices for API overages.

🌐 Infrastructure Masking: By routing traffic through your misconfigured servers, hackers hide their true location and identity, making it significantly harder for AI providers to flag and block malicious requests.

🛡️ Hardening Your Perimeter: It is critical to disable unauthenticated proxies and implement strict Access Control Lists (ACLs) to ensure only authorized internal traffic can reach external API endpoints.

💡 Usage Monitoring: Organizations must implement real-time alerts for spikes in LLM API consumption, as sudden usage surges are often the first—and only—sign of a “quishing” or proxy-jacking incident.

🎯 Threat Hunting Package

GreyNoise

The Hunter Becomes the Hunted: 324,000 BreachForums Accounts Exposed

The cybercriminal underworld has been rocked by a massive database leak exposing over 324,000 accounts from the notorious BreachForums hacking community. This unprecedented exposure provides a treasure trove of metadata, potentially unmasking thousands of threat actors and providing law enforcement with critical new leads.

Key takeaways

🕵️‍♂️ Massive Anonymity Loss: The leak includes usernames, email addresses, and registration IP addresses for 323,986 members, making it significantly easier for investigators to de-anonymize prolific hackers.

📂 Evidence Goldmine: Beyond login credentials, the database contains hashed passwords and backend metadata that can be cross-referenced to link individuals to historical high-profile corporate breaches.

🚨 Law Enforcement Pressure: This dump follows a series of high-profile seizures and arrests by the FBI and French authorities, indicating that the forum’s infrastructure has been thoroughly compromised.

🛡️ Zero-Day Exploits: Analysts suggest the data was extracted via a zero-day vulnerability in the MyBB forum software, proving that even criminal marketplaces are vulnerable to the same technical flaws they exploit in others.

📉 Operational Disarray: The leak highlights the ongoing infighting and instability within the hacking community as rival factions and law enforcement battle for control over dark web domains.

BleepingComputer

Don’t Get Fooled by the New “Browser-in-the-Browser” Phishing Trick

Cybercriminals are now deploying a sophisticated “Browser-in-the-Browser” (BitB) technique to create fake Facebook login windows that appear identical to legitimate OAuth pop-ups, complete with forged address bars. This advanced social engineering tactic is designed to steal credentials by exploiting your trust in standard login prompts on third-party websites.

Key takeaways:

🖥️ Simulated Windows: Attackers use HTML and JavaScript to render a fake browser window inside the web page you are currently visiting, mimicking the look and feel of a real Chrome, Edge, or Firefox pop-up.

🌐 Forged URL Bars: Unlike traditional phishing, this method displays a perfectly replicated address bar showing the correct domain and a “https” padlock, bypassing the common security advice to “check the URL.”

💡 The “Drag Test”: A simple way to detect this is to try and drag the login pop-up window outside the bounds of your main browser window. If the pop-up gets cut off at the edge or stays stuck inside the page, it is a fake element.

🔒 Technical Defenses: Always utilize a reputable password manager, as these tools will fail to recognize and autofill credentials into a simulated BitB window, and ensure Multi-Factor Authentication (MFA) is active on all accounts.

🎯 Threat Hunting Package

Trellix

University of Hawaii Cancer Center Targeted in Sophisticated Ransomware Attack

The University of Hawaii Cancer Center has confirmed it was hit by a ransomware attack orchestrated by the Daixin Team, a threat group notorious for targeting the healthcare sector. This breach highlights the increasing vulnerability of medical research institutions and the high value cybercriminals place on sensitive patient and research data.

Key takeaways:

🚨 High-Value Targets: The Daixin Team specifically targets healthcare and research organizations, recognizing that the sensitivity of their data and the critical nature of their operations increase the pressure to pay ransoms.

📁 Sensitive Data Exposure: The attack led to the potential exfiltration of personal information, including names and Social Security numbers, as well as sensitive health and research data belonging to participants.

🛡️ The Complexity of Recovery: Although the initial breach occurred earlier this year, the extensive time required for forensic analysis and data mining underscores how difficult it is to identify exactly who was impacted after a ransomware event.

💡 Proactive Defense is Vital: This incident serves as a stark reminder for research institutions to implement rigorous data segmentation, robust encryption for “data at rest,” and multi-factor authentication (MFA) to hinder lateral movement by attackers.

🌐 Systemic Risk to Research: Beyond data loss, these attacks threaten the integrity of clinical trials and medical research, making cybersecurity a fundamental pillar of patient safety and scientific progress.

BleepingComputer

Your Automation Workflows Could Be the Next Entry Point for Cybercriminals

Security researchers have uncovered a sophisticated supply chain attack targeting the n8n workflow automation platform through malicious npm packages disguised as legitimate community nodes. These “trojan” integrations exploit n8n’s role as a centralized credential vault to decrypt and exfiltrate highly sensitive OAuth tokens and API keys to attacker-controlled servers.

Key takeaways:

🚨 Malicious Community Nodes: Threat actors are uploading fake integrations to the npm registry—such as counterfeit Google Ads connectors—to infiltrate and compromise established n8n ecosystems.

🔑 Credential Exfiltration: Once installed, these malicious nodes can bypass standard encryption to steal stored credentials for critical business services like Stripe, Salesforce, and Google.

🌐 The Risk of No Sandboxing: Because community nodes run with the same level of access as the n8n application itself, a single malicious package can gain deep visibility into your entire automation environment.

🛡️ Hardening Your Instance: Administrators of self-hosted instances should consider disabling community nodes entirely or strictly auditing every third-party package before installation.

📈 A Shift in Strategy: This campaign marks a significant escalation in supply chain threats, as attackers move away from targeting individual developers to weaponizing the trusted tools that manage corporate data flows.

Endor Labs

A sophisticated new malware framework dubbed “VoidLink” has emerged, specifically engineered to compromise Linux cloud servers through a stealthy, modular approach. It utilizes advanced persistence mechanisms and modular payloads to facilitate data exfiltration and resource hijacking while evading traditional security detection.

Key takeaways:

🚨 Modular Attack Framework: VoidLink is built with a highly flexible architecture, enabling attackers to swap modules for various malicious activities, including cryptomining, lateral movement, and sensitive data theft.

🕸️ Exploiting D-Bus for Evasion: The framework uniquely leverages the Linux D-Bus inter-process communication system to coordinate between its components, a tactic designed to bypass standard security monitoring tools.

🔑 Initial Entry Points: Threat actors are primarily gaining access by targeting exposed SSH services through credential brute-forcing and the exploitation of known vulnerabilities in cloud-facing Linux applications.

🛑 Memory-Resident Persistence: By utilizing a specialized loader that remains in memory, VoidLink minimizes its disk footprint, allowing it to maintain a persistent presence on infected servers while avoiding signature-based scans.

💡 Actionable Defense: Organizations should prioritize hardening SSH access with Multi-Factor Authentication (MFA), monitoring for unusual inter-process communication traffic, and maintaining an aggressive patching schedule for all Linux cloud instances.

🎯 Threat Hunting Package

Check Point

SHADOW#REACTOR Campaign Exploits Windows Tools to Deploy Remcos RAT

Cybersecurity researchers have uncovered a sophisticated, multi-stage attack chain dubbed “SHADOW#REACTOR” that is actively targeting enterprise and SMB environments to establish covert remote access. By utilizing a modular, self-healing design and leveraging legitimate Windows binaries, this campaign is specifically engineered to bypass modern endpoint protection and facilitate long-term persistence.

Key takeaways:

🚨 High-Impact Backdoor: The campaign delivers the Remcos RAT, a commercially available but powerful Remote Administration Tool that grants attackers full control over a compromised system, including file exfiltration and keystroke logging.

🎭 Stealth via LOLBins: The final stage of the attack hijacks MSBuild.exe, a legitimate Microsoft development tool, to execute malicious code—a “Living-off-the-Land” (LOLBin) tactic designed to blend in with normal system activity.

🛡️ Advanced Evasion Techniques: To frustrate analysts, the malware uses .NET Reactor-protected loaders and executes almost entirely in-memory, leaving a minimal footprint for traditional antivirus software to detect on the disk.

🏗️ Resilient “Self-Healing” Design: The infection chain includes a unique logic loop that validates the integrity of downloaded fragments; if a payload is blocked or corrupted, the stager automatically attempts to re-fetch it until the infection is complete.

💡 Actionable Defense: Organizations should prioritize monitoring for suspicious child processes of wscript.exe and powershell.exe, and consider restricting the execution of developer tools like MSBuild on non-technical workstations.

🎯 Threat Hunting Package

Secureonix

New LinkedIn Phishing Tactic Exploits Trust in Comment Replies

Threat actors are now weaponizing LinkedIn’s comment section by replying to user inquiries with malicious links designed to steal credentials and bypass MFA. This highly targeted approach exploits the professional trust of the platform to deliver sophisticated phishing pages that look indistinguishable from legitimate login portals.

Key takeaways:

🚨 Weaponized Interactions: Attackers monitor popular industry posts and “helpfully” reply to users asking for whitepapers or resources, making the malicious link appear like a legitimate response to their request.

🔒 MFA Bypass Capability: This campaign frequently utilizes “Adversary-in-the-Middle” (AiTM) frameworks to harvest session cookies, allowing hackers to bypass Multi-Factor Authentication and gain full account access.

🎭 Deceptive Redirection: To evade security filters, the phishing links often use legitimate cloud-hosting services or URL shorteners that mask the final malicious destination.

🛡️ Zero-Trust Networking: Professional context does not equal security; users must remain vigilant and verify the profile of anyone sending “resource” links, even if it appears to be a direct reply to their own comment.

💡 Immediate Action: Security teams should update employee awareness training to include “social media phishing” and consider implementing hardware-based security keys (FIDO2) to mitigate session-stealing risks.

BleepingComputer

Exploit Code Public for FortiSIEM RCE Flaw

A maximum-severity command injection vulnerability in FortiSIEM (CVE-2024-23108) now has a public proof-of-concept (PoC) exploit, allowing unauthenticated attackers to execute arbitrary code with root privileges. This flaw is a variant of a previously patched issue, highlighting the persistent threat to exposed security monitoring appliances.

Key takeaways

🚨 Maximum Severity: With a CVSS score of 10.0, this unauthenticated remote code execution (RCE) flaw allows for total system takeover.

🕵️‍♂️ Public Exploit Available: Functional exploit code has been released by researchers, significantly increasing the risk of widespread exploitation.

🌐 Active Probing: Reports indicate that threat actors are actively scanning for and attempting to exploit this vulnerability in the wild.

🛡️ Immediate Mitigation: Administrators should upgrade to version 7.1.2 or higher immediately. If patching is delayed, restrict access to the phMonitor port (TCP 7900).

Horizon3.ai

Node.js Vulnerability Threatens Nearly Every Production App

A newly disclosed vulnerability (CVE-2025-59466) in Node.js can cause unrecoverable server crashes by bypassing standard error handling during stack overflows. This high-impact issue affects the core async_hooks module, directly impacting major frameworks like Next.js and React, as well as essential monitoring tools like Datadog and OpenTelemetry.

Key takeaways

🚨 Massive Ecosystem Risk: The vulnerability is described as impacting “virtually every production Node.js app,” particularly those using modern frameworks or Application Performance Monitoring (APM) tools.

💥 Fatal DoS Attacks: Unlike typical errors, this bug causes Node.js to exit immediately (Code 7), preventing frameworks from recovering and leaving services completely offline after a stack overflow.

🔍 The Hidden Trigger: The issue stems from the async_hooks module, where unsanitized recursive input can exhaust stack space without triggering a catchable exception.

🛡️ Immediate Action Required: Admins must update to Node.js versions 20.20.0, 22.22.0, 24.13.0, or 25.3.0. Note that End-of-Life versions like 18.x will not receive a patch.

🌐 Widespread Exposure: Impact extends to React Server Components, Next.js, New Relic, and Dynatrace—essentially any tool relying on AsyncLocalStorage.

Node.js

“ConsentFix” Bypasses MFA to Hijack Microsoft Accounts

A sophisticated new attack technique dubbed ConsentFix is targeting Entra ID (Azure AD) environments by merging ClickFix-style social engineering with OAuth consent phishing. Linked to the Russian state-affiliated group APT29, this method effectively sidesteps traditional security layers, including MFA and passkeys, by weaponizing the authorization flow of trusted first-party applications.

Key takeaways

🔒 MFA & Passkey Bypass: Because the attack hijacks the OAuth authorization code after the user has already authenticated, even the strongest phishing-resistant MFA methods offer no protection.

🎯 Exploiting Trusted Apps: ConsentFix specifically targets pre-consented first-party Microsoft apps like Azure CLI, Teams, and VS Code, which are often exempt from strict Conditional Access policies.

🇷🇺 State-Sponsored Sophistication: Attribution to APT29 highlights a high level of stealth, using legacy scopes and “localhost” redirects to evade standard detection and logging.

🛡️ Urgent Mitigation: Security teams should immediately restrict access to vulnerable Service Principals and ensure AADGraphActivityLogs are enabled for monitoring.

🌐 The Browser Attack Surface: This campaign underscores the need for browser-native security, as traditional EDR tools often fail to detect these purely browser-based interactions.

🎯 Threat Hunting Package

Push Security

GootLoader Alert: New “1,000-Part” Stealth ZIPs Evade Detection

The notorious GootLoader malware has evolved its delivery mechanism, utilizing malformed ZIP archives composed of up to 1,000 concatenated parts to bypass automated security scanners. This sophisticated technique allows the malicious payload to hide in plain sight, often appearing as a harmless text file or even as an empty archive to traditional analysis tools while remaining fully functional on Windows systems.

Key takeaways

🕵️‍♂️ Sophisticated Evasion: By concatenating a massive number of ZIP parts, attackers create malformed archives that confuse tools like 7-Zip or VirusTotal, yet extract a valid malicious JavaScript payload through standard Windows File Explorer.

📉 SEO Poisoning Lures: Threat actors continue to hijack legitimate, high-ranking WordPress sites to host these archives, targeting users searching for specific business or legal document templates.

💨 Terrifying Speed: Recent campaigns show extreme operational efficiency, with attackers moving from initial infection to full Domain Controller compromise in as little as 17 hours.

🛠️ Ransomware Gateway: GootLoader acts as a primary entry point for sophisticated ransomware groups like Vanilla Tempest and Rhysida, facilitating rapid lateral movement and data exfiltration.

🛡️ Critical Mitigation: Defenders should implement behavioral monitoring for suspicious wscript.exe or PowerShell activity and educate staff to remain skeptical of document downloads from unfamiliar “message board” style websites.

Expel

The “Reprompt” Attack: One Click to Siphon Microsoft Copilot Data

Cybersecurity researchers have unveiled a critical “reprompt” attack method that enables silent data exfiltration from Microsoft Copilot with just a single click. By exploiting simple URL parameters, attackers can bypass security guardrails to steal sensitive user information, maintaining access even after a chat session is closed.

Key takeaways

🔒 One-Click Compromise: The attack leverages the “q” URL parameter to inject malicious instructions directly into Copilot, requiring no further user interaction or complex plugins.

🚨 Guardrail Bypass: Attackers successfully tricked the AI into ignoring safety controls by using a “double-request” technique, as built-in protections were found to apply only to the initial request.

🌐 Persistent Threat: Because the exploit operates within the active session context, data exfiltration can continue silently in the background even if the victim closes their Copilot window.

🛡️ Vulnerability Status: While Microsoft has patched the flaw for personal users and confirmed that enterprise Microsoft 365 Copilot was unaffected, the discovery highlights a massive “blind spot” in AI assistant security.

💡 Critical Lesson: This research underscores the persistent risk of indirect prompt injections, proving that LLMs still struggle to distinguish between legitimate user commands and malicious smuggled inputs.

Varonis

Cisco Patches CVSS 10.0 Zero-Day Exploited by APT

Cisco has officially released emergency patches for a maximum-severity remote command execution (RCE) vulnerability in its Secure Email Gateway, which has been under active exploitation by a China-linked threat actor since late 2025. This flaw allows unauthenticated attackers to gain full root access to affected appliances by sending malformed HTTP requests to the Spam Quarantine feature.

Key takeaways

🛡️ Critical Vulnerability: Tracked as CVE-2025-20393, this 10.0-rated flaw provides attackers with ultimate “root” control over the underlying operating system of critical email infrastructure.

🕵️‍♂️ Active Exploitation: A China-nexus threat actor (UAT-9686) has been using this zero-day to deploy a suite of custom tools, including the “AquaShell” Python backdoor and “AquaPurge” log cleaner, to maintain stealthy persistence.

⚠️ Specific Requirements: The risk is highest for organizations where the Spam Quarantine feature is enabled and exposed directly to the internet—a configuration common in many enterprise environments.

🔄 Immediate Patching Required: Updates are now available for Cisco AsyncOS Software; administrators must prioritize moving to fixed versions (e.g., 15.0.5-016 or 16.0.4-016) to eliminate existing persistence mechanisms.

💡 Hardening Strategy: Beyond patching, Cisco urges teams to disable HTTP for admin portals, enforce MFA (SAML/LDAP), and place these appliances behind a robust firewall to limit the attack surface.

The Hacker News


Feature Article

image

If your CISO asked you how your CTI team plans to increase the value it provides in 2026, could you give a solid answer?

Most of us have been in that moment, scrambling for a strategy while wishing we had a concrete action plan.

The CTI-Capability Maturity Model (Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)) helps solve this problem. I wrote my take on how to use the framework and I’m excited to share it’s now live on Feedly’s TI Essentials.

It covers:

→ A realistic 60-day sprint to move from foundational to advanced maturity

→ Which domains to prioritize first

→ How to run stakeholder discovery interviews (with a template)

→ The metrics that prove value vs. the metrics that just measure busywork

→ Common pitfalls I’ve seen teams fall into

The guide also features insights from Michael DeBolt, Founder of the CTI-CMM and Chief Intelligence Officer at Intel 471, on why the framework was created and his top tip for getting started.

2026 is the year to stop guessing and start maturing.

Thanks to the CTI-CMM team for contributing the framework and to Feedly for partnering on this guide.

Read Now

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools