Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Malicious Chrome Extensions Hijack Enterprise HR Sessions
A coordinated campaign of Chrome extensions has been discovered targeting Workday, NetSuite, and SAP SuccessFactors to steal session cookies and block security management pages. These tools masquerade as productivity enhancers but are designed for stealthy, full-account takeovers.
Key takeaways:
🚨 Coordinated Exploitation: Researchers identified five malicious extensions, such as “Data By Cloud 2” and “Tool Access 11,” designed to infiltrate high-value enterprise ERP and HR environments.
🍪 Session Hijacking: The malware exfiltrates authentication cookies every 60 seconds, enabling attackers to bypass Multi-Factor Authentication (MFA) and maintain access even after a user logs out.
🛡️ Defensive Sabotage: Specific extensions were found to block over 50 different security administration pages, effectively “blinding” IT teams and preventing them from responding to the breach.
💉 Advanced Infiltration: The campaign utilizes bidirectional cookie injection to take over authenticated sessions directly, allowing for immediate account access without needing a username or password.
🔒 Immediate Action: If these tools were used, notify your security team immediately, rotate all platform credentials, and audit active sessions for any unauthorized activity.
The Hunters Become the Hunted: Researchers Infiltrate Malware Control Panels
Cybersecurity researchers have successfully turned the tables on the Stealc info-stealer operators by exploiting critical vulnerabilities within the malware’s own administration panels. By “hacking the hackers,” analysts gained unprecedented access to attacker databases, revealing victim logs and the inner workings of a major “Malware-as-a-Service” operation.
Key takeaways:
🚨 Table-Turning Infiltration: Researchers exploited basic security flaws, like SQL injection, in the Stealc admin interface to hijack the very servers used to coordinate global cyberattacks.
🕵️ Intelligence Goldmine: Accessing these control panels allowed defenders to see real-time data on how over 40 different criminal groups were using the malware to target users and what specific data was being stolen.
🏗️ Infrastructure Exposed: By mapping the backend systems, researchers identified how the malware exfiltrates sensitive information, providing a clear blueprint for organizations to build more effective defenses.
💡 Flawed Criminal Code: This incident highlights a massive irony: malware authors often prioritize speed over their own security, leaving “backdoors” that professional defenders can use to dismantle their business models.
🛡️ Proactive Defense: While complex, this “proactive threat hunting” approach shows that disrupting a hacker’s home base is one of the most effective ways to protect the public and stop data theft at the source.
New Malware Strategy Uses Real Browser Crashes to Breach Corporate Networks
A dangerous malvertising campaign is deploying a fake ad-blocker extension named “NexShield” that intentionally crashes your browser to set the stage for a “CrashFix” social engineering attack. Once the browser is restarted, users are lured into executing malicious PowerShell commands that install the sophisticated ModeloRAT in corporate environments.
Key takeaways
🎭 Highly Deceptive Impersonation: The malicious “NexShield” extension was promoted as a lightweight ad-blocker from the creator of uBlock Origin to trick users into a false sense of security before striking.
📉 Intentional DoS Attack: The malware creates an infinite loop that exhausts memory resources, forcing a real browser crash to create the high-stress urgency needed for its subsequent “fake fix” scam.
⌨️ The Clipboard Trap: Following the “ClickFix” playbook, the attack tricks users into copying and pasting a “fixing” command into their Windows Command Prompt, which triggers a multi-stage PowerShell infection chain.
🏢 Corporate Reconnaissance: On enterprise systems, the campaign deploys “ModeloRAT,” a Python-based remote access tool designed for system fingerprinting, registry modification, and remote command execution.
🛡️ Persistence Warning: Simply uninstalling the browser extension is not enough; infected systems require a comprehensive security cleanup as the RAT operates independently of the browser once it gains a foothold.
The “Invisible” Spy in Your Calendar: Google Gemini Vulnerability Uncovered
A critical security flaw in Google Gemini has been revealed, demonstrating how attackers could use malicious calendar invites to trick the AI into exfiltrating private meeting data. This “indirect prompt injection” attack turns a simple AI schedule query into a tool for corporate espionage.
Key takeaways:
📅 Malicious Invites as Attack Vectors: Attackers can hide dormant natural language prompts inside standard calendar descriptions that remain inactive until a user interacts with the AI.
🎭 The “Silent” Exfiltration: When asked about a schedule, the AI is manipulated to create new, visible events containing summaries of sensitive, private data—effectively acting as a “double agent” within the corporate network.
🔍 Language is the New Code: This vulnerability underscores that security risks are no longer confined to traditional software code; they now live in the language, context, and runtime behavior of LLMs.
🛡️ Action-Capable AI Risks: If an AI agent has the permission to write to any field, log, or database entry, that field becomes a potential exfiltration channel, regardless of how “locked down” the chat interface appears.
🌐 Systemic AI Surface Area: While this specific flaw has been addressed, it serves as a stark reminder that AI-native features broaden the attack surface, often introducing risks that automated scanners can easily miss.
Russian Hacktivist Groups Intensify Attacks on Critical Infrastructure
The UK’s National Cyber Security Centre (NCSC) has issued a critical warning regarding the evolving threat from Russian-aligned hacktivist groups. These actors are increasingly targeting Critical National Infrastructure (CNI) and private sector organizations to cause public disruption and project a sense of instability.
Key takeaways
🇷🇺 Geopolitical Motivation: Groups like NoName057(16) are launching opportunistic attacks driven by ideological alignment with Russia, specifically targeting nations supporting Ukraine.
⚡ DDoS as a Primary Weapon: Distributed Denial of Service (DDoS) remains the tactic of choice, designed to knock essential services offline and undermine public confidence through high-visibility downtime.
🏛️ Broad Target Profile: While CNI is the focus, any high-profile organization—from energy and water to government services—is at risk of being used as a pawn in these “nuisance” campaigns.
🛡️ Unpredictable Nature: Unlike state-sponsored APTs that favor stealth, these hacktivists seek maximum noise, making their timing and targets harder to predict through traditional intelligence.
🔒 Urgent Resilience Needs: The NCSC emphasizes that organizations must bolster DDoS mitigation strategies and ensure incident response plans are ready for multi-day disruption attempts.
National Cyber Security Centre (NCSC)
EU Fortifies Digital Borders: New Rules Target High-Risk Tech Suppliers
The European Union is advancing a major cybersecurity overhaul designed to tighten control over managed security services and block “high-risk” foreign providers from entering critical infrastructure. This initiative aims to bolster regional digital sovereignty, ensuring that the tools protecting European data are not subject to foreign state influence or intrusive intelligence laws.
Key takeaways:
🔒 Uniform Certification Standards: The EU is introducing a rigorous certification scheme for Managed Security Services (MSS) to ensure a high, consistent level of protection across all member states.
🚨 Excluding High-Risk Vendors: New regulations will empower the EU to block suppliers from countries whose laws may compel them to engage in state-sponsored espionage or data interference.
🛡️ Shielding Critical Sectors: This overhaul specifically targets the resilience of essential sectors like energy, healthcare, and finance, which are increasingly reliant on third-party security providers.
🌐 A Push for Digital Sovereignty: This move reflects a broader geopolitical trend of decoupling from foreign tech dependencies in favor of trusted, locally compliant alternatives.
💡 Proactive Vendor Vetting: Organizations operating within the EU will soon need to re-evaluate their third-party partnerships to ensure compliance with these emerging certification requirements.
New VS Code Job Interview Scam Delivers Stealthy Backdoors!
A sophisticated “Contagious Interview” campaign is targeting software engineers by using malicious Visual Studio Code (VS Code) projects disguised as technical assessments to deploy remote access trojans. Attackers are luring developers into cloning repositories that automatically execute malicious payloads the moment the project folder is opened.
Key takeaways:
🚨 The “Folder Open” Trap: Attackers are abusing the tasks.json configuration in VS Code; by setting the runOn: folderOpen option, malicious commands execute automatically if a user grants “Trust” to the repository.
🔒 Targeted Sector Attacks: This campaign specifically focuses on developers within the cryptocurrency, fintech, and blockchain sectors, aiming to hijack privileged access to financial assets and intellectual property.
🛡️ Sophisticated Evasion: Recent iterations of the malware (BeaverTail and InvisibleFerret) use AI-assisted scripts to disguise malicious code as harmless spell-check dictionaries and bypass traditional security filters.
🌐 Infrastructure Exploitation: By hosting payloads on legitimate platforms like Vercel and using GitHub/Bitbucket for delivery, threat actors effectively blend their malicious traffic with standard development workflows.
💡 Critical Defense Tip: Never grant “Trust” to a VS Code project from an unverified source without first auditing the .vscode/tasks.json and hidden scripts within the repository.
New Phishing Campaign Exploits DM Trust to Deploy Stealthy RATs
Cybersecurity researchers have uncovered a sophisticated phishing campaign targeting high-value individuals directly through LinkedIn private messages to deploy Remote Access Trojans (RATs). By establishing professional trust with DMs, attackers can bypass traditional email security filters and deliver malicious payloads via DLL sideloading.
Key takeaways:
🚨 Social Engineering Trap: Attackers initiate professional conversations to build rapport before deceiving targets into downloading a malicious WinRAR archive disguised as a legitimate document or job assessment.
🛡️ Stealthy DLL Sideloading: The campaign weaponizes a legitimate, open-source PDF reader to sideload a rogue DLL, allowing the malware to hide within trusted processes and evade standard detection.
🔒 Persistent Remote Access: Once executed, the attack installs a Python interpreter and modifies Windows Registry keys to ensure the malware runs automatically upon every login, granting hackers long-term control.
🌐 The “Visibility Gap”: Unlike corporate email, social media private messages often lack robust security monitoring, making them a highly effective and under-guarded entry point for corporate breaches.
💡 Proactive Defense: Organizations must extend their threat detection beyond email and train high-value targets, including executives and developers, to vet all files received via social media platforms.
Cisco Issues Critical Patches for Actively Exploited Zero-Day Vulnerability
Cisco has released emergency security updates to address a critical remote code execution (RCE) flaw impacting several Unified Communications products and Webex Calling instances. This vulnerability, tracked as CVE-2026-20045, is currently being exploited in the wild, posing a significant risk to organizational communication infrastructure.
Key takeaways
🚨 Critical Vulnerability (CVE-2026-20045): A high-severity flaw (CVSS 8.2) allows unauthenticated remote attackers to execute arbitrary commands on a susceptible device’s underlying operating system.
🛡️ Root Access Risk: Exploitation occurs via crafted HTTP requests to the web-based management interface, potentially allowing attackers to escalate privileges from user-level to full root access.
🌐 Broad Product Impact: Affected systems include Cisco Unified Communications Manager (Unified CM), Unity Connection, and Webex Calling Dedicated Instance.
⚠️ Active Exploitation: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate mitigation by federal agencies.
🔒 Immediate Action Required: Administrators should urgently apply the provided patches or migrate to fixed releases to prevent unauthorized system takeovers.
The Rise of AI-Coded Malware Meet VoidLink, the 88,000-Line Linux Threat Built in One Week
Cybersecurity researchers have uncovered “VoidLink,” a sophisticated Linux malware framework developed almost entirely by AI under the direction of a single human actor. This discovery marks a pivotal moment where AI industrializes malware production, enabling the rapid development of complex, modular threats that previously required nation-state resources and months of effort.
Key takeaways
🚨 Hyper-Speed Development: VoidLink reached a functional 88,000 lines of code in under seven days, leveraging AI “Spec Driven Development” to turn a concept into a working implant with unprecedented speed.
🔒 Zig-Powered Stealth: Built using the Zig programming language, the framework is specifically engineered for long-term, stealthy persistence within enterprise Linux-based cloud environments.
🤖 AI “Fingerprints”: Despite its complexity, analysts identified tell-tale AI artifacts such as perfectly systematic debug logs and generic “John Doe” placeholders, tracing the code back to AI coding agents.
🌐 Lowering the Barrier: VoidLink signals a shift in threat economics, allowing individual actors to deploy sophisticated, modular architectures that were once the exclusive domain of coordinated hacking groups.
🛡️ Defense Evolution: As AI-generated threats scale, organizations must prioritize monitoring for Zig-compiled binaries and unusual systematic logging patterns that deviate from standard application behavior.
Don’t Fall for the New LastPass “Maintenance” Phishing Scam
LastPass has issued an urgent advisory regarding a sophisticated phishing campaign targeting its users with fraudulent “scheduled maintenance” notifications. These deceptive emails aim to steal Master Passwords and gain unauthorized access to encrypted user vaults by creating a false sense of urgency.
Key takeaways
🚨 Sophisticated Social Engineering: Attackers are deploying high-quality emails that perfectly mimic official LastPass branding to trick even tech-savvy users.
💡 The “Maintenance” Trap: The scam claims your account requires “re-synchronization” or “update verification” due to a backend system migration.
🔍 Credential Harvesting: Clicking the “Login” button leads to a pixel-perfect replica of the LastPass sign-in page designed to capture your Master Password and 2FA codes in real-time.
🛡️ Verify the Source: Always navigate directly to the official website (lastpass.com) or use your trusted browser extension rather than clicking links embedded in emails.
🔒 Zero-Trust Policy: Remember, legitimate password manager services will never ask you to provide your Master Password through an email link or a support ticket.
Zoom and GitLab Issue Emergency Patches for RCE and 2FA Bypass Flaws
Zoom and GitLab have released urgent security updates to address multiple high-severity vulnerabilities, including a critical 9.9 CVSS-rated command injection flaw in Zoom and a two-factor authentication (2FA) bypass in GitLab. These vulnerabilities could allow attackers to execute remote code or gain unauthorized account access if left unpatched.
Key takeaways
🚨 Critical Zoom RCE (CVSS 9.9): A severe vulnerability in Zoom Node Multimedia Routers (MMRs) could allow a meeting participant to conduct remote code execution via network access.
🛡️ GitLab 2FA Bypass: A high-severity flaw in GitLab enables attackers with knowledge of a victim’s credential ID to circumvent 2FA protections by submitting forged device responses.
🌐 Service Disruption Risks: GitLab also patched multiple vulnerabilities that allow unauthenticated users to trigger Denial-of-Service (DoS) conditions through malformed API requests.
🛠️ Priority Updates: Administrators are urged to update Zoom Node MMR to version 5.2.1716.0 and GitLab instances to versions 18.8.2, 18.7.2, or 18.6.4 immediately.
🔒 Proactive Defense: While there is currently no evidence of active exploitation in the wild, the high severity of these flaws makes them prime targets for future attacks.
Why Your Help Desk is the Weakest Link in Okta Security
Cybercriminals are aggressively using voice phishing (vishing) to impersonate employees and trick IT help desks into resetting Multi-Factor Authentication (MFA), granting unauthorized access to sensitive Okta SSO accounts. This sophisticated social engineering tactic bypasses traditional technical defenses by targeting the human element of your security perimeter.
Key takeaways
📞 Vishing Escalation: Attackers call IT support, providing stolen personal data to appear legitimate while requesting an MFA reset for “lost” or “broken” devices.
🚨 SSO Takeover: Once unauthorized access is gained to an Okta account, threat actors can move laterally across your entire cloud environment to exfiltrate proprietary data and sensitive credentials.
🛡️ Stricter Verification: Organizations must implement robust, out-of-band identity verification processes for all help desk requests—never rely on a phone call alone to reset security protocols.
💡 The Human Firewall: Regular vishing simulations and specialized social engineering training for support staff are essential to recognize high-pressure tactics and “urgent” false claims.
🌐 Proactive Monitoring: Admins should monitor system logs for unusual MFA reset patterns or administrative changes occurring immediately after a help desk interaction.
Osiris Ransomware Disarms Security with BYOVD Tactics
Cybersecurity researchers have uncovered a new ransomware family, Osiris, that is actively neutralizing defenses using the “Bring Your Own Vulnerable Driver” (BYOVD) technique. By deploying a malicious driver called POORTRY, attackers successfully terminate security software, paving the way for data exfiltration and full-scale encryption.
Key takeaways
🛡️ EDR Neutralization: Osiris uses the POORTRY driver to bypass and disable Endpoint Detection and Response (EDR) and antivirus tools, rendering traditional security layers ineffective.
📦 Cloud Exfiltration: Before triggering encryption, the threat actors use Rclone to siphon sensitive data into Wasabi cloud storage buckets, increasing the pressure for extortion.
🔗 INC Ransomware Link: Technical overlaps—including the use of a specific Mimikatz variant (kaz.exe)—suggest this new strain may be operated by affiliates previously linked to the notorious INC ransomware group.
🛠️ Dual-Use Tool Abuse: The attackers leverage legitimate tools like Rustdesk, Netexec, and MeshAgent to maintain persistence and move laterally within the network undetected.
🔒 Proactive Defense: To counter this, organizations must restrict administrative privileges to prevent driver installation and closely monitor for unauthorized use of cloud-syncing tools like Rclone.
Automated Attacks Exploiting FortiGate SSO Vulnerabilities
Cybersecurity researchers have detected a wave of automated attacks targeting Fortinet FortiGate devices by exploiting critical SSO authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719). Threat actors are using malicious SAML messages to gain unauthorized access, alter firewall configurations, and establish long-term persistence within corporate networks.
Key takeaways
🚨 Automated Exploitation: Attackers are using high-speed scripts to bypass SSO authentication, allowing them to log in as administrators and export sensitive configuration files within seconds.
🔒 Persistence Tactics: Once inside, the threat actors create multiple secondary accounts—such as “secadmin,” “itadmin,” and “backup”—to maintain access even if the initial entry point is closed.
🌐 Infrastructure Risk: The attack impacts multiple Fortinet products, including FortiOS, FortiWeb, and FortiProxy, potentially exposing entire network architectures to data exfiltration.
🛡️ Immediate Mitigation: Security teams are strongly advised to disable the “admin-forticloud-sso-login” setting immediately while awaiting further clarification on patch efficacy for all versions.
💡 Proactive Hunting: Admins should scan system logs for unauthorized logins from the “[email protected]” account or any unfamiliar administrative account creation.
Feature Video
⏱️ Attackers now move from initial compromise to lateral movement in just 7 MINUTES. How long does your CTI team take to analyze and respond to a threat?
If you’re measuring in hours or days, you’re not losing because adversaries are smarter… you’re losing because they’re faster.
Key takeaways:
🔥 The speed gap is widening — Breakout times dropped from 84 minutes (2019) to 7 minutes today. Batch processing logs every hour? You’ve already lost.
🤖 You can’t fight automation with manual processes — Modern attackers use polymorphic malware, domain generation algorithms, and AI. Spreadsheets and copy-paste workflows won’t cut it anymore.
⚡ Streaming architectures are the new standard — Tools like Apache Kafka enable millisecond latency detection, feeding real-time alerts, data lakes, and ML models simultaneously.
🎯 You don’t need to become a data scientist — Start with one pain point, prove value, then scale. Platforms like Sentinel, Splunk, and Elastic offer built-in ML capabilities out of the box.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



