Triaging the Week 105

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Legitimate Developer Account Hijacked to Spread GlassWorm Malware

Cybersecurity researchers have uncovered a sophisticated supply chain attack targeting the Open VSX Registry, where four established extensions were poisoned to deliver the GlassWorm malware loader. These legitimate tools, which accumulated over 22,000 downloads, were compromised to harvest macOS credentials and sensitive developer data from enterprise environments.

Key takeaways

🥸  Trusted Accounts Exploited: The campaign bypassed traditional “brandjacking” defenses by hijacking a legitimate developer account (‘oorzc’) to push malicious updates to established, high-trust extensions.

🦠 GlassWorm Stealth Tactics: The poisoned versions use “EtherHiding”—leveraging Solana memos as dynamic dead drops—to fetch C2 instructions, hiding execution behind encrypted loaders to evade static analysis.

🍎 Targeted macOS Data Theft: The malware is specifically tuned to exfiltrate iCloud Keychains, Safari cookies, Apple Notes, and cryptocurrency wallets like MetaMask and Ledger Live from macOS users.

🛡️ Lateral Movement Risk: Attackers are aggressively harvesting AWS tokens, SSH keys, and npm authentication materials, directly threatening private repositories and cloud infrastructure.

💡 Immediate Action Required: Audit your VS Code and Open VSX environments for any extensions published by ‘oorzc.’ Move beyond static indicators toward behavioral detection to spot unauthorized outbound credential exfiltration.

🎯 Threat Hunting Package

Socket

Former Google Engineer Convicted in AI Data Theft Case

A former Google software engineer has been convicted of stealing over 500 confidential files related to proprietary Artificial Intelligence (AI) infrastructure while secretly working for two China-based tech firms. This high-profile case highlights the critical intersection of corporate espionage, national security, and the global race for AI supremacy.

Key takeaways

🚨 The Insider Threat Reality: This case serves as a massive wake-up call that even the world’s most advanced tech giants are vulnerable to “the enemy within” when trusted access is weaponized.

🤖 AI Intellectual Property as a Target: The stolen data specifically detailed Google’s Tensor Processing Unit (TPU) architecture—the “brains” behind their AI—proving that hardware-level trade secrets are now prime targets for industrial espionage.

🕵️ Detection Challenges: The engineer reportedly exfiltrated data into a personal cloud account for months while maintaining secret executive roles overseas, highlighting a desperate need for more robust behavioral monitoring and conflict-of-interest vetting.

🛡️ Zero Tolerance for Trade Secret Theft: The conviction sends a clear message from the Department of Justice: the theft of sensitive AI technology will be met with severe legal consequences and federal prosecution.

💡 Actionable Defense: Organizations must move beyond basic perimeter security and invest in advanced Data Loss Prevention (DLP) and User and Entity Behavior Analytics (UEBA) to identify unusual data movement before it leaves the network.

United States Department of Justice

Critical 1-Click RCE in OpenClaw: AI Assistant Vulnerability Exposed

A high-severity security flaw (CVE-2026-25253) has been discovered in OpenClaw (formerly Moltbot/Clawdbot), allowing attackers to gain full system control through a single malicious link. This vulnerability chains token exfiltration with Cross-Site WebSocket Hijacking to bypass security sandboxes and execute arbitrary shell commands on a user’s machine.

Key takeaways

🔒 Silent Token Theft: The OpenClaw Control UI automatically connects to unvalidated URLs in the query string, leaking sensitive authentication tokens to attacker-controlled servers without user interaction.

🚨 1-Click System Takeover: By exploiting a lack of WebSocket origin validation, an attacker can pivot through a victim’s browser to disable security guardrails and run commands directly on the host OS.

🌐 Widespread Exposure: Current scans reveal over 21,000 publicly exposed OpenClaw instances, many of which remain unpatched and susceptible to immediate exploitation.

🛡️ Immediate Action Required: Admins must upgrade to v2026.1.29 or later immediately, rotate all authentication tokens, and audit any third-party “skills” installed from the ClawHub marketplace.

💡 Deployment Best Practice: Never expose AI agent ports (default TCP/18789) directly to the internet; always use authenticated tunnels like Tailscale or Cloudflare Tunnel to restrict access.

depthfirst

Russian Hackers Exploit Emergency Microsoft Office Flaw

Russian state hackers (APT28) are aggressively weaponizing a newly patched Microsoft Office bypass (CVE-2026-21509) to compromise government entities across Ukraine and the EU. Just days after Microsoft’s emergency update, attackers began using social engineering to deploy the COVENANT malware framework via a sophisticated multi-stage infection chain.

Key takeaways

🚨 Rapid Weaponization: APT28 (Fancy Bear) began exploiting this security bypass just 24 hours after an emergency patch was released, proving that nation-state actors are monitoring patch cycles for immediate exploitation opportunities.

🛡️ Sophisticated Stealth: The attack chain utilizes COM hijacking and shellcode hidden within legitimate-looking image files to execute the COVENANT framework, leveraging the Filen cloud service for command-and-control to blend in with normal traffic.

🔒 Critical Versions Affected: The vulnerability impacts Microsoft Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. Notably, Office 2021 users must restart their applications for the service-side patch to take effect.

🌐 Strategic Targeting: Phishing lures were highly tailored, impersonating EU COREPER consultations and meteorological services to target over 60 government-related addresses across Europe.

💡 Immediate Defense: Security teams should prioritize patching and verifying application restarts. Additionally, monitor or block connections to filen.io and ensure Microsoft Defender’s Protected View is enforced for all internet-sourced documents.

🎯 Threat Hunting Package

CERT-UA

Notepad++ Updates Hijacked by State-Sponsored Actors

State-sponsored hackers compromised Notepad++’s hosting infrastructure to hijack the official update mechanism for over six months, selectively delivering a custom backdoor to high-value targets. This sophisticated supply chain attack exploited infrastructure-level access to redirect update traffic from specific organizations to malicious servers.

Key takeaways

🔒 Infrastructure-Level Hijack: The breach occurred at the shared hosting provider rather than the source code, allowing attackers to intercept and reroute official update traffic (WinGUp) between June and December 2025.

🚨 Precision Targeting: This was not a mass infection; the China-linked threat actor “Lotus Blossom” (APT31) used IP filtering to deliver malware only to specific telecom and financial organizations while millions of others received clean updates.

🌐 Advanced “Chrysalis” Backdoor: Targeted victims were infected with a previously undocumented backdoor capable of spawning interactive shells, stealing files, and deploying Cobalt Strike beacons for long-term espionage.

🛡️ Mandatory Patching: The vulnerability was addressed in Notepad++ version 8.8.9. Users must upgrade to the latest version (v8.9.1+) to ensure the updater strictly enforces digital signature and certificate validation.

💡 Audit Your Systems: Security teams should hunt for suspicious ‘update.exe’ processes in %AppData%\Bluetooth or unexpected network calls from the GUP.exe updater process.

🎯 Threat Hunting Package

Rapid7

Supply Chain Alert: 341 Malicious Skills Discovered on ClawHub

Researchers have identified hundreds of malicious plugins on ClawHub, the marketplace for the OpenClaw AI assistant, designed to hijack systems and steal crypto assets. This campaign, codenamed “ClawHavoc,” weaponizes the popularity of AI agents to deliver info-stealers like Atomic Stealer (AMOS) via deceptive third-party “skills.”

Key takeaways

🦠 Mass Infection Campaign: Over 340 rogue skills are currently targeting the OpenClaw ecosystem, delivering tailored malware to both macOS and Windows systems through fraudulent “Prerequisites” instructions.

🎭 Deceptive Masquerading: Attackers are using typosquatting and impersonating high-demand tools—such as Solana wallet trackers, Polymarket bots, and YouTube summarizers—to lure users into executing malicious scripts.

🔒 Critical Data Exfiltration: The malware is specifically engineered to harvest high-value data, including OpenAI API keys, browser passwords, SSH credentials, and the assistant’s own environment configuration files.

🛡️ Community Defense Active: OpenClaw has launched a new reporting feature; notably, any skill that receives three or more unique reports will now be automatically hidden from the marketplace.

💡 Security Best Practice: Conduct an immediate audit of your installed skills and never execute Terminal or PowerShell scripts from unverified third-party repositories like glot.io.

🎯 Threat Hunting Package

Koi Security

Critical RCE in React Native CLI Under Active Exploitation

Threat actors are weaponizing a critical remote code execution flaw (CVE-2025-11953) in the popular @react-native-community/cli npm package, allowing them to take full control of developer environments. This vulnerability, dubbed “Metro4Shell,” poses a severe risk as it bypasses authentication to execute arbitrary commands on the underlying host.

Key takeaways:

🚨 Critical Severity: With a near-perfect CVSS score of 9.8, “Metro4Shell” allows remote, unauthenticated attackers to execute operating system commands via the Metro Development Server.

🕵️‍♂️ Active Malware Delivery: Cybersecurity researchers have observed attackers using the flaw to deliver Base64-encoded PowerShell scripts that deploy sophisticated, anti-analytic Rust-based malware.

🛡️ Stealth Tactics: Current attacks are designed to evade detection by automatically configuring Microsoft Defender exclusions for the current working directory and temporary folders.

🌐 Infrastructure Risk: This campaign highlights a recurring danger: development infrastructure becomes a production-level liability the moment it is reachable over the internet.

🔒 Immediate Mitigation: Developers must audit their network configurations to ensure Metro servers are not internet-facing and update their CLI packages to the latest secured versions immediately.

🎯 Threat Hunting Package

VulnCheck

Critical “DockerDash” Vulnerability in Docker’s AI Assistant Fixed

Cybersecurity researchers have unveiled a major security flaw, codenamed “DockerDash,” impacting “Ask Gordon,” the AI assistant integrated into Docker Desktop and CLI. This critical vulnerability allows attackers to execute arbitrary code or exfiltrate sensitive environment data by simply embedding malicious instructions within Docker image metadata.

Key takeaways:

⚠️ Meta-Context Injection: The “Ask Gordon” AI fails to distinguish between informational metadata (like standard Docker labels) and pre-authorized internal instructions, leading to unintended command execution.

🏗️ Weaponized Metadata: Attackers can craft malicious Docker images where the LABEL fields in a Dockerfile act as a payload, triggering an attack chain the moment a user asks the AI about that image.

🔓 Zero-Trust Failure: The flaw exploits the Model Context Protocol (MCP) Gateway, which executes commands without validation, effectively giving the AI’s instructions the same privileges as the local user.

📂 Data Exfiltration Risk: Beyond code execution, the flaw can be used to silently harvest details about your network topology, container configurations, and installed tools.

🛡️ Immediate Action Required: Docker has patched this in version 4.50.0. If you are using an older version of Docker Desktop or the CLI with AI features enabled, you must update immediately to secure your environment.

Noma Labs

Critical RCE in n8n: Patch CVE-2026-25049 Immediately

Cybersecurity researchers have disclosed a critical Remote Code Execution (RCE) flaw in the n8n workflow automation platform that allows attackers to bypass sandbox restrictions and take full control of the server. This vulnerability, tracked as CVE-2026-25049 (CVSS 9.4), represents a significant threat to organizations leveraging AI and automated workflows.

Key takeaways:

🚨 Severe System Impact: The flaw enables authenticated users to execute arbitrary system commands via crafted JavaScript expressions, leading to full server compromise and data exfiltration.

🔓 Public Webhook Exposure: Risks escalate dramatically when malicious workflows are paired with public webhooks, potentially allowing unauthenticated adversaries to trigger payloads remotely.

🧩 Bypass of Legacy Patches: This vulnerability successfully bypasses security measures previously implemented for CVE-2025-68613, exposing gaps in how dynamic runtime inputs are sanitized.

🛡️ Lateral Movement Risk: A compromised instance gives attackers a “skeleton key” to integrated CRM platforms, database passwords, and cloud provider API keys.

🛠️ Immediate Remediation: You must upgrade to n8n versions 1.123.17 or 2.5.2 (and above) immediately to secure your infrastructure.

SecureLayer7

Python Infostealers are Jumping to macOS

Microsoft security researchers have issued a warning regarding a surge in Python-based information stealers that are successfully bypassing traditional platform boundaries to target macOS environments. By leveraging the cross-platform nature of Python and sophisticated “ClickFix” social engineering, attackers are now hunting for iCloud Keychains, developer secrets, and crypto wallets at scale.

Key takeaways:

🍎 macOS in the Crosshairs: Attackers are using Python’s flexibility to deploy malware like AMOS and MacSync, proving that macOS is increasingly targeted by threats once reserved for Windows.

🖱️ Deceptive “ClickFix” Tactics: Malicious campaigns are abusing Google Ads and fake software installers to trick users into running malicious AppleScripts via deceptive “copy-paste” prompts.

💎 High-Value Data Exfiltration: These stealers don’t just stop at passwords; they are specifically optimized to harvest session cookies, authentication tokens, and sensitive developer credentials.

🛡️ Proactive Monitoring: Organizations must tighten security by monitoring for unusual Terminal activity, unauthorized iCloud Keychain access, and suspicious network egress to newly registered domains.

💡 Defense Through Education: Training users to recognize malvertising redirect chains and fake “fix” prompts remains the most effective way to break the initial infection chain.

🎯 Threat Hunting Package

Microsoft Security

Legitimate Forensic Tools Turned Against Us: The Rise of the EnCase EDR Killer

Cybersecurity researchers have uncovered a sophisticated “EDR killer” tool that weaponizes a legitimate, old kernel driver from the EnCase forensic suite to systematically blind security defenses. By exploiting the “Bring Your Own Vulnerable Driver” (BYOVD) technique, attackers are now able to terminate 59 different security processes, including top-tier EDR and antivirus solutions.

Key takeaways:

🚨 Weaponizing Trust: Attackers are abusing EnPortv.sys, an old EnCase kernel driver, to gain high-level system access and bypass modern Windows protections like Protected Process Light (PPL).

🔓 The Revocation Gap: Despite the driver’s certificate being revoked years ago, it remains effective because Windows validates timestamps rather than active Certificate Revocation Lists (CRLs) for legacy drivers.

🛠️ Deep Persistence: The tool disguises itself as a legitimate “OEM hardware service,” ensuring it remains active even after system reboots to continuously kill security services as they restart.

🌐 Credential Entry Point: The initial breach was traced back to compromised VPN credentials lacking Multi-Factor Authentication (MFA), highlighting that basic security hygiene is still a primary failure point.

🛡️ Actionable Defense: To mitigate this risk, organizations must enable HVCI/Memory Integrity, enforce strict MFA on all remote access, and use Windows Defender Application Control (WDAC) to block known vulnerable drivers.

🎯 Threat Hunting Package

Huntress

NGINX Servers Targeted in Stealthy Traffic Hijacking Campaign

Threat actors are silently compromising NGINX configurations to redirect user traffic through malicious backend infrastructure, effectively creating a persistent Man-in-the-Middle (MitM) environment. This campaign specifically targets high-value government and educational sectors, leveraging legitimate server directives to evade traditional detection.

Key takeaways:

🕵️ Invisible Redirection: Attackers inject malicious location blocks and proxy_pass directives into NGINX config files, rerouting traffic through attacker-owned domains while preserving original headers to maintain the appearance of legitimacy.

🎯 High-Profile Targets: The campaign has been observed focusing on .gov and .edu domains, alongside specific regional TLDs, indicating a strategic interest in sensitive institutional data and credentials.

⚙️ Automated Malicious Toolkit: A sophisticated 5-stage scripted toolkit automates the entire process—from enumerating configuration files to validating changes with nginx -t—ensuring the server remains operational and “healthy” while compromised.

🔍 Evasion of Security Tools: Because the attack abuses standard NGINX features rather than exploiting a software bug, it often bypasses automated security scanners that are not specifically looking for unauthorized configuration drift.

🛡️ Actionable Defense: Web administrators should immediately implement File Integrity Monitoring (FIM) for /etc/nginx/ and audit configurations for unauthorized proxy_pass entries. Additionally, ensure hosting management panels like Baota are secured with robust MFA.

🎯 Threat Hunting Package

DataDog Security Labs

Claude Opus 4.6 Uncovers 500+ High-Severity Flaws in Open-Source Libraries

Anthropic’s latest AI model, Claude Opus 4.6, has identified over 500 previously unknown high-severity vulnerabilities across critical open-source projects. This milestone demonstrates AI’s growing ability to reason through complex logic and identify flaws that traditional automated tools often miss.

Key takeaways:

🚨 500+ Zero-Day Flaws: The model discovered high-severity defects in widely used libraries, including Ghostscript, OpenSC, and CGIF, most of which have now been patched.

🧠 Human-Like Reasoning: Unlike traditional fuzzers, Opus 4.6 identifies vulnerabilities by analyzing past fixes and understanding conceptual data structures like the LZW algorithm.

🛡️ Defensive Advantage: Anthropic is positioning these AI capabilities as a “force multiplier” for security researchers to proactively secure the open-source ecosystem.

⚠️ Rising Threat Landscape: As AI lowers the barrier for autonomous cyberattacks, the urgency for prompt patching and robust security fundamentals has never been higher.

🔒 Action Required: Ensure your environments are updated to the latest versions of Ghostscript and CGIF (v0.5.1+) to mitigate these newly disclosed risks.

Anthropic

Ransomware Groups Weaponize ISPsystem VMs for Stealthy Payload Delivery

Cybercriminals are evolving their tactics by leveraging ISPsystem software to deploy malicious virtual machines that act as “jump boxes” for ransomware. By operating within these virtualized environments, attackers can effectively bypass traditional security monitoring and deliver payloads with a high degree of stealth.

Key takeaways:

🚨 Detection Evasion: Attackers are using ISPsystem’s VMmanager to create transient virtual machines, allowing them to execute malicious code away from the host’s Endpoint Detection and Response (EDR) tools.

🌐 Infrastructure Abuse: The campaign focuses on compromising administrative hosting accounts to gain control over the virtualization management plane, turning legitimate tools into attack platforms.

🔒 Credential Security: A primary entry point for these attacks is weak or stolen credentials; implementing robust Multi-Factor Authentication (MFA) across all management interfaces is no longer optional.

🛡️ Visibility Gaps: This “living-off-the-cloud” technique highlights the need for organizations to monitor for unauthorized VM creation and unusual API activity within their hosting environments.

💡 Proactive Defense: Security teams must treat the virtualization layer as a critical attack surface, ensuring that management software is patched and audit logs are regularly reviewed for anomalies.

Sophos

Italy Thwarts Russian-Linked Cyber Offensive Targeting Winter Olympics

Italian authorities have successfully neutralized a wave of coordinated DDoS attacks aimed at the Milan-Cortina Winter Games and several diplomatic offices abroad. Attributed to the pro-Russian group NoName057(16), these strikes underscore the growing trend of weaponizing cyber disruption to influence geopolitical narratives during high-profile global events.

Key takeaways:

🚨 120+ Targets Identified: The campaign hit a wide range of infrastructure, from the Italian Foreign Ministry in Washington to hospitality services and hotels in the host town of Cortina d’Ampezzo.

🌐 Retaliatory Hacktivism: The attackers explicitly stated the strikes were “punishment” for Italy’s support of Ukraine, demonstrating how national policy can instantly elevate an organization’s risk profile.

🛡️ Success in Neutralization: By “getting ahead” of the threat, Italian cybersecurity agencies prevented significant disruption, proving that proactive monitoring is the best defense against high-volume traffic attacks.

💡 Psychological Impact: While these DDoS attacks were largely mitigated, their goal remains to erode public confidence and create a sense of instability on the world stage.

🔒 Sustained Vigilance: With the Games ongoing, the threat landscape remains volatile; organizations associated with the event must maintain heightened security protocols to counter potential follow-up attempts.

France 24


Feature Video

Ever feel like Cyber Threat Intelligence requires you to be a malware-reversing, Mandarin-speaking data scientist all in one?

It’s an overwhelming field to break into, but this video lays out a “zero to hero” roadmap to demystify it.

It’s all built on three core pillars:

💻 Pillar 1: The Technical Foundation.

You can’t track an adversary if you don’t understand the battlefield. This is where you master core SOC skills, learn the MITRE ATT&CK framework as your common language, and use Python to automate the boring stuff (not become a full-stack dev!).

🧠 Pillar 2: The Analyst Tradecraft.

This is the “intelligence” in CTI. It’s about learning the formal intelligence cycle, using Structured Analytical Techniques (SATs) to combat your own cognitive biases, and transitioning from tactical (”block this IP”) to strategic (”here’s what they’ll target next quarter”).

✍️ Pillar 3: The Soft Skill Amplifier.

This is the most overlooked, yet most critical, pillar. Your brilliant analysis is worthless if it stays in your head: “You are a professional writer who just happens to be a cyber security expert”. Your report is the product.

This video breaks down the books, courses, and other learning resources you can use to conquer each of these pillars! No affiliate links, no paid promotions, just actionable advice. 

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools