Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

The AI-Powered Cyber Attack Assembly Line: 600+ FortiGate Devices Compromised
Amazon Threat Intelligence has uncovered a massive campaign where a technically limited threat actor leveraged multiple commercial generative AI services to compromise over 600 FortiGate devices across 55 countries. This incident marks a significant shift, demonstrating how AI can act as a force multiplier for unsophisticated attackers to orchestrate large-scale operations by targeting basic security hygiene gaps.
Key takeaways:
🤖 AI-Augmented Execution: The attacker used AI to generate comprehensive step-by-step attack plans, develop custom scripts, and even craft post-exploitation commands, effectively automating the technical heavy lifting.
🚪 Hygiene Over Exploits: No new vulnerabilities were used; instead, the campaign succeeded by targeting exposed management ports and weak credentials protected only by single-factor authentication.
🏗️ Pre-Ransomware Staging: Post-compromise activity included Active Directory exploitation and credential harvesting, specifically targeting backup infrastructure—a classic hallmark of preparation for a ransomware deployment.
🛡️ Critical Defense Shift: To mitigate these AI-scaled threats, organizations must move beyond “set and forget” configurations by disabling public management interfaces and enforcing Multi-Factor Authentication (MFA) across all administrative access.
Anthropic Levels Up DevSecOps with AI-Powered Vulnerability Scanning
Anthropic has officially rolled out “Claude Code Security,” a new AI-driven capability designed to scan entire software codebases for deep-seated vulnerabilities and suggest targeted patches. Currently in a limited research preview, this tool aims to give defenders a strategic advantage by leveraging AI reasoning to counter adversaries who are increasingly using similar tech to automate their attacks.
Key takeaways:
🧠 Human-Like Reasoning: Moving beyond simple pattern matching, the tool analyzes data flows and component interactions to identify complex logic flaws that traditional rule-based scanners often overlook.
🤝 Human-in-the-Loop: To maintain code integrity, the system utilizes a multi-stage verification process; while it suggests fixes, no patches are applied without final review and approval from a developer.
📉 Precision Filtering: Each finding is assigned a confidence rating and severity score, helping security teams cut through the “noise” of false positives and focus on the most critical risks first.
⚔️ The AI Arms Race: This launch highlights a critical shift in cybersecurity—using AI not just for productivity, but as a mandatory defensive layer to match the speed of AI-augmented threat actors.
Operation MacroMaze Strikes Europe with “Living-Off-The-Browser” Tactic
Russian state-sponsored actor APT28 (Fancy Bear) has been identified in a sophisticated new campaign targeting Western and Central European entities by weaponizing legitimate webhook services and headless browser sessions. This operation, active through early 2026, demonstrates how threat actors are pivoting to “simple” tools like VBScript and Batch files to achieve high-impact stealth and bypass traditional defenses.
Key takeaways
🌐 Legitimate Service Abuse: The attackers leveraged webhook.site for both initial beaconing, using embedded “tracking pixels” in Word documents, and final data exfiltration, masking malicious traffic as benign web activity.
🚨 Advanced Browser Evasion: The malware executes Base64-encoded HTML payloads by launching Microsoft Edge in “headless” mode or moving the browser window off-screen, allowing it to exfiltrate data without any visible user interaction.
🛡️ Macro Evolution: Analysts observed a shift toward using keyboard simulations (SendKeys) in newer variants, a tactical evolution designed specifically to bypass modern security prompts and automated sandboxes.
🔒 The Power of Simplicity: By cleaning up disk artifacts and outsourcing C2 infrastructure to trusted public platforms, APT28 proves that meticulous orchestration of basic scripts can be more effective than complex, custom malware.
Wormable XMRig Alert: The Dangerous Rise of BYOVD in Cryptojacking
A sophisticated new malware campaign is making waves by combining wormable self-propagation with “Bring Your Own Vulnerable Driver” (BYOVD) tactics to deploy XMRig miners. As an analyst, this represents a significant escalation in cryptojacking, moving from simple resource theft to advanced defense evasion that can blind your security stack.
Key takeaways
🪱 Wormable Self-Propagation: Unlike typical miners that require manual execution, this strain utilizes automated lateral movement to spread across internal networks, turning one infected workstation into a fleet of miners.
🛠️ BYOVD Exploitation: The attackers are leveraging legitimate but vulnerable drivers to gain kernel-level privileges. This allows the malware to forcefully terminate EDR and antivirus processes that would otherwise block the miner.
💰 Persistent Resource Drain: By silencing defenses first, the XMRig payload can operate undetected for longer periods, significantly impacting system performance and driving up electricity and cloud infrastructure costs.
🛡️ Proactive Defense: Organizations should immediately review their driver loading policies. Implementing a strict driver blocklist (such as Microsoft’s vulnerable driver list) is no longer optional; it’s a critical layer of defense.
RoguePilot: The New “Promptware” Threat to Your GitHub Repositories
A sophisticated vulnerability, codenamed RoguePilot, has been discovered in GitHub Codespaces, allowing attackers to seize control of repositories by silently injecting malicious instructions via GitHub issues. This AI-mediated supply chain attack weaponizes GitHub Copilot’s deep integration to exfiltrate sensitive tokens without any visible errors or warnings to developers.
Key takeaways
🚨 Passive Prompt Injection: Attackers can hide malicious HTML comments inside a GitHub issue description. When a developer opens a Codespace from that issue, the built-in Copilot automatically processes these hidden instructions, effectively hijacking the AI agent.
🔓 Token Exfiltration: The exploit demonstrates a practical chain where the AI is tricked into checking out a crafted pull request, following symbolic links to internal files, and leaking the privileged GITHUB_TOKEN to a remote server via a remote JSON schema.
🌐 Emergence of “Promptware”: This flaw highlights a rising class of “promptware”—polymorphic prompts engineered to behave like malware by abusing an AI application’s context and permissions rather than exploiting traditional code vulnerabilities.
🛡️ Verification & Patching: While Microsoft has since patched this specific flaw following disclosure by Orca Security, it serves as a critical reminder that AI collaborators must be monitored as potential attack vectors within trusted developer workflows.
The Rise of 1Campaign: How Malvertising-as-a-Service is Outsmarting Google Ads
A sophisticated new platform called 1Campaign is revolutionizing how cybercriminals bypass security filters to deliver malware via Google Search. By providing advanced “cloaking” technology, this service allows even low-skilled attackers to hide malicious redirects from Google’s detection bots while leading real users straight to infostealer payloads.
Key takeaways
🔒 Advanced Cloaking Techniques: 1Campaign uses geographical and browser-based filtering to show “clean” versions of websites to security scanners and Google’s automated auditors, while serving malware to unsuspecting human targets.
🚨 Targeting Essential Software: Attackers are leveraging the platform to spoof popular tools like WinRAR, VLC, and TeamViewer, tricking users who are looking for routine productivity software into downloading infostealers like Vidar and Rhadamanthys.
💡 The Crime-as-a-Service Model: This platform lowers the barrier to entry for cybercrime by offering a turnkey malvertising infrastructure, meaning we are likely to see a significant surge in high-quality, deceptive “Sponsored” search results.
🛡️ Zero Trust for Search: Security teams must reinforce the “official source only” rule; users should never trust a “Sponsored” link for software downloads, as the verification of these ads is currently being systematically subverted.
Lazarus Group Adopts Medusa Ransomware
The notorious North Korean-linked Lazarus Group has been observed deploying Medusa ransomware in recent campaigns, signaling a strategic shift toward direct financial extortion. This evolution demonstrates how state-sponsored actors are increasingly adopting “commodity” Ransomware-as-a-Service (RaaS) tools to obfuscate their origins while maximizing illicit revenue.
Key takeaways
🚨 Tactical Convergence: Lazarus is moving beyond traditional espionage and cryptocurrency heists, leveraging the Medusa RaaS model to monetize network access through high-pressure extortion.
🔒 Obfuscation through RaaS: By using well-known ransomware variants, state-sponsored groups can blend in with “normal” cybercriminals, making attribution significantly more difficult for incident responders.
🛡️ The Double Extortion Threat: These attacks prioritize both data encryption and sensitive data exfiltration, forcing victims to face the dual threat of operational downtime and public data leaks.
💡 Critical Entry Points: The group continues to exploit unpatched vulnerabilities in web-facing applications for initial access, reinforcing the urgent need for a robust, risk-based patching cycle.
New Phishing Wave Hits US and European Freight Sectors
A high-volume phishing campaign is currently striking the freight and logistics sectors across the US and Europe by hijacking legitimate email threads to spread malware. Attackers are utilizing “ClickFix” social engineering to trick employees into manually executing malicious PowerShell scripts that deploy infostealers and remote access trojans.
Key takeaways
🚨 High-Trust Thread Hijacking: Threat actors are infiltrating existing email conversations using compromised legitimate accounts, making these malicious messages appear as credible follow-ups to routine business discussions.
💡 The “ClickFix” Evolution: Moving beyond simple links, this campaign uses fake “error” overlays that instruct users to copy and paste a command into their terminal to “fix” a document viewing issue, effectively bypassing many automated email filters.
🌐 Tailored Industry Lures: The attacks specifically impersonate industry-standard tools like Samsara and Astra TMS, using the precise language of shipping manifests and fleet management to lower the target’s guard.
🛡️ Critical Defense Shift: Traditional link-scanning is no longer enough; organizations must immediately train staff to recognize “copy-paste” prompts as a major red flag and enforce hardware-backed MFA to stop the account takeovers that power these attacks.s
SLH Group Offers $1,000 Bounties for Female Recruits
The notorious Scattered Lapsus$ Hunters (SLH) cybercrime collective is diversifying its social engineering tactics by offering high-dollar bounties to specifically recruit women for targeted vishing (voice phishing) campaigns against IT help desks. By weaponizing polished scripts and deceptive voice profiles, hackers aim to bypass traditional security training and gain initial network access.
Key takeaways
💰 Monetized Social Engineering: Attackers are paying $500–$1,000 per call to incentivize “insider” recruitment, signaling a shift toward high-reward “Crime-as-a-Service” models.
🎭 Profile Diversification: By specifically seeking female voices, SLH aims to subvert the “traditional” attacker profile that IT help desk personnel are often trained to identify.
⛓️ MFA Bypass Risks: These vishing attempts often result in MFA prompt flooding or SIM swapping, enabling attackers to escalate privileges and deploy ransomware.
🛡️ Hardening Your Defense: Organizations must shift toward phish-resistant MFA and implement rigorous, multi-step identity verification protocols for all help desk interactions.
AI Coding Assistants: The New Frontier for Remote Code Execution
Critical vulnerabilities discovered in Anthropic’s Claude Code highlight a significant shift in the cybersecurity threat landscape. Researchers have demonstrated that simply opening or initializing an untrusted repository can lead to immediate Remote Code Execution (RCE) and the silent exfiltration of sensitive API keys.
Key takeaways
🔒 Configuration as an Exploit: Attackers are now weaponizing AI-specific configuration files (like .claude/settings.json), transforming what was once “operational context” into a direct execution layer for malicious commands.
🚨 Silent API Theft: Vulnerabilities like CVE-2026-21852 allow a crafted repository to redirect authenticated traffic to attacker-controlled endpoints, leaking active Anthropic API keys before a user even sees a trust prompt.
🛡️ Critical Updates Required: If your development team utilizes AI-powered CLI tools, ensure they have updated to Claude Code version 2.0.65 or later to mitigate these disclosed RCE and information disclosure flaws.
🌐 Evolving Supply Chain Risk: As AI agents gain the autonomy to execute shell commands and manage integrations, the definition of a “malicious project” has expanded beyond the source code to the automation layers surrounding it.
Google Shatters Decade-Long Cyber Espionage Network
Google TAG and Mandiant have successfully disrupted “UNC2814,” a prolific China-linked threat actor that spent years spying on government and telecommunications sectors across 42 countries. By weaponizing a novel backdoor called GRIDTIDE, the group effectively masked its malicious commands within legitimate Google Sheets traffic to evade traditional security detection.
Key takeaways
🌐 Global Espionage Apparatus: UNC2814 (also known as Gallium) compromised at least 53 organizations worldwide, focusing on harvesting sensitive PII, including national IDs and phone records, to monitor persons of interest.
🔒 Living-off-the-Cloud: In a sophisticated “hide-in-plain-sight” move, the group used the Google Sheets API as a command-and-control (C2) platform, allowing malicious data transfers to masquerade as benign office activity.
🛡️ Proactive Disruption: The coordinated takedown involved terminating malicious Google Cloud projects, sinkholing domains, and disabling attacker-controlled accounts, dealing a significant blow to the group’s long-standing infrastructure.
💡 The Network Edge Vulnerability: This campaign underscores that state-sponsored actors are still successfully gaining initial entry by exploiting unpatched web servers and edge systems before moving laterally via SSH.
Your Next Job Interview Could Be a Backdoor
A sophisticated cyber campaign is targeting software developers by hiding malware within fake Next.js “technical assessment” repositories. By weaponizing standard development workflows, attackers are successfully gaining Remote Code Execution (RCE) on developer machines to exfiltrate sensitive environment variables and API keys.
Key takeaways
🚨 Triggered on Open: The attack leverages VS Code’s tasks.json with runOn: “folderOpen”, meaning malicious scripts can execute the moment you open the project, before you even run a single command.
🔒 Stealthy Persistence: By embedding loaders in npm run dev scripts and .env files, the malware runs in-memory, polling C2 servers for tasks while avoiding traditional disk-based detection.
🛡️ Isolate Your Tests: Treat every recruitment repository as “untrusted.” Always review coding assessments in a sandboxed VM or containerized environment rather than on your primary machine.
💡 Hardening Best Practices: Enforce “Restricted Mode” in VS Code by default and implement Attack Surface Reduction (ASR) rules to prevent unauthorized Node.js processes from spawning malicious shells.
Ransomware Payment Rates Plunge to All-Time Low as Attack Volumes Soar
Despite a massive surge in ransomware activity, the percentage of victims who choose to pay has dropped to a record low of 27%. This shift reflects a growing resilience among organizations and a fundamental loss of trust in the “honor” of cybercriminals.
Key takeaways:
📉 The 27% Threshold: Payment rates have plummeted from 85% in early 2019 to just 27% today, signaling that organizations are increasingly refusing to fund the cybercrime ecosystem.
🛡️ Resilience Over Ransom: This decline is driven by improved backup and recovery strategies, coupled with the realization that paying does not guarantee data recovery or prevent sensitive information from being leaked anyway.
🚨 Shift to Pure Extortion: As encryption becomes less profitable, threat actors are pivoting to “exfiltration-only” attacks, focusing solely on stealing and threatening to leak data to maintain leverage.
🌐 Law Enforcement Impact: Global disruption of major RaaS (Ransomware-as-a-Service) groups by law enforcement has fractured the landscape, making it harder for criminals to maintain stable operations.
Your “Harmless” Google API Keys Just Got a Dangerous Upgrade
Security researchers have discovered that legacy Google API keys, previously restricted to low-impact services like Google Maps, can now be exploited to access sensitive Gemini AI data. This unintended “scope creep” by Google turns minor credential leaks into major security vulnerabilities and potential data breaches.
Key takeaways:
🚨 The “Permission Creep” Risk: API keys once considered low-risk may now automatically include permissions for the generative-language API, providing an unauthorized gateway to your Gemini AI models.
💸 Financial & Data Exposure: Hijacked keys allow threat actors to run resource-heavy AI queries on your account, leading to massive billing spikes and the potential exfiltration of proprietary data.
🛡️ Immediate Audit Required: Cybersecurity teams must move beyond “set and forget” mentalities; it is critical to revisit the Google Cloud Console and apply strict “API Restrictions” to every active key.
🌐 Consolidation Consequences: This flaw highlights a growing trend in cloud environments where service consolidation can silently expand the power of a single credential without administrative consent.
Aeternum C2 Moves Command-and-Control to the Blockchain
Cybersecurity researchers have uncovered a new threat, Aeternum C2, which has successfully weaponized the Polygon blockchain to create a “takedown-proof” command-and-control (C2) infrastructure. By storing encrypted instructions within public smart contracts, this botnet bypasses traditional server-based defenses and remains operational even under intense scrutiny.
Key takeaways:
⛓️ Blockchain-Backed Resilience: Instead of relying on traditional domains or servers that can be seized, Aeternum uses the Polygon network to host its commands, making the infrastructure effectively permanent and decentralized.
🛡️ Permanent & Immutable: Once a command is written to the blockchain as a transaction, it cannot be deleted or altered by anyone except the attacker, rendering standard “sinkholing” or takedown efforts obsolete.
💸 Negligible Operating Costs: For just $1 worth of MATIC tokens, threat actors can issue over 100 commands to their infected fleet, making this a highly scalable and cost-effective tool for global campaigns.
🕵️ Blending with Legitimate Traffic: The malware communicates via public RPC (Remote Procedure Call) endpoints, the same channels used by legitimate decentralized apps, allowing malicious traffic to hide in plain sight.
Feature Video
Drowning in SOC alerts and wondering if there’s more to cybersecurity than this? There is a clear path to get there, and this video will show you how!
🗺️ The IT → SOC → CTI pathway is real, logical, and people are walking it every day — most just don’t know it exists
🧠 The #1 thing separating those who make the jump isn’t technical skill — it’s how they think
🔍 Every ticket you close and alert you triage is building the foundation for a CTI career, even if it doesn’t feel like it
🚀 You don’t need the title to start acting like a CTI analyst — start writing up patterns, pivoting on indicators, and thinking beyond your organisation’s four walls
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



