Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

International Police Operation Targets”The Com” Violent Cybercrime Ring
Law enforcement agencies across four countries have arrested 30 individuals linked to “The Com,” a notorious cybercrime ecosystem known for blending high-tech SIM swapping with brutal physical violence. This coordinated strike across the US, UK, Spain, and Portugal targeted a group that moved beyond digital theft into “swatting” and physical intimidation to extort victims.
Key takeaways:
🌐 Massive Global Coordination: The operation involved the FBI, the UK’s National Crime Agency, and Spanish and Portuguese police, resulting in 30 arrests and over 40 searches to dismantle a “violent cyber-criminal ecosystem”.
⚔️ Digital Crime Meets Physical Violence: “The Com” was unique for its “offline” tactics, including hiring individuals to perform “brick-through-window” attacks and “swatting” to pressure victims into handing over cryptocurrency and sensitive data.
📱 SIM Swapping & Social Engineering: The group specialized in compromising mobile accounts to bypass multi-factor authentication (MFA), highlighting a critical need for users to move away from SMS-based security.
🛡️ Actionable Defense: This crackdown serves as a reminder to implement hardware security keys or authenticator apps rather than relying on phone numbers, which are increasingly vulnerable to these sophisticated groups.
“ClawJacked” Flaw Allows Malicious Sites to Hijack Your Local AI Agents
A high-severity security vulnerability dubbed “ClawJacked” has been discovered in the OpenClaw AI gateway, enabling malicious websites to take full control of locally running AI agents. By exploiting insecure WebSocket configurations, an attacker can bypass localhost restrictions to steal configuration data, read private logs, and manipulate agent actions.
Key takeaways:
🚨 WebSocket Hijacking: Malicious JavaScript on a standard webpage can open a connection to your local OpenClaw gateway, effectively “jumping” the gap between your browser and your local AI environment.
🔒 Brute-Force Vulnerability: Due to a lack of rate-limiting on the gateway’s password prompt, attackers can automate password-guessing attacks to gain unauthorized access to the agent.
🌐 The “Localhost” Trust Trap: The core system was found to silently approve new device registrations if they originated from localhost, allowing attackers to pair malicious devices without ever prompting the user.
🛡️ Immediate Mitigation: OpenClaw has released a fix in version 2026.2.25. All developers and users running local instances must update immediately and audit their non-human (agentic) identities.
North Korean Hackers Poison npm Ecosystem with 26 Malicious Packages
North Korean threat actors have been caught publishing 26 malicious packages to the npm registry, designed to exfiltrate sensitive data and establish backdoors in developer environments. This sophisticated campaign targets the software supply chain by masquerading as legitimate utility tools to compromise downstream applications.
Key takeaways:
🕵️♂️ Strategic Supply Chain Attack: Attackers published packages with names mimicking popular libraries to trick developers into integrating malicious code directly into their build pipelines.
🦠 Data Exfiltration & Backdoors: Once installed, these packages execute scripts that harvest environment variables, credentials, and system metadata, while frequently deploying a second-stage payload for persistent remote access.
🛠️ Advanced Evasion Tactics: The malware utilized time-based execution delays and legitimate cloud services for command-and-control (C2) communication to bypass standard security scanners.
🔒 Immediate Mitigation: Developers should audit their package-lock.json files, use automated software composition analysis (SCA) tools, and strictly verify package maintainers before installation.
UK Issues Urgent Warning on Rising Iranian Cyber Risks
The UK’s National Cyber Security Centre (NCSC) has officially warned organizations to bolster their defenses against Iranian state-sponsored cyber threats as regional tensions escalate. This advisory highlights a heightened risk of retaliatory or opportunistic attacks targeting critical infrastructure, government entities, and private sector businesses.
Key takeaways:
🏛️ Broad Targeting Profile: While critical national infrastructure remains a primary focus, Iranian threat actors are increasingly targeting commercial sectors and non-governmental organizations to gather intelligence or cause disruption.
🎣 Sophisticated Social Engineering: Expect an uptick in highly targeted spear-phishing campaigns designed to steal credentials or deploy malware, often masquerading as legitimate professional or academic outreach.
🚨 Exploitation of Known Flaws: Attackers are actively scanning for unpatched vulnerabilities in VPNs and other edge-of-network devices to gain initial access to corporate networks.
🔐 Prioritize Basic Hygiene: The NCSC emphasizes that robust Multi-Factor Authentication (MFA), prompt security patching, and diligent monitoring of system logs remain the most effective defenses against these state-level actors.
National Cyber Security Centre (NCSC)
The New AI-Native Framework Powering Autonomous Cyberattacks
The cybersecurity landscape is shifting as threat actors begin adopting CyberStrikeAI, a sophisticated AI-native security testing framework, to automate and scale malicious operations. Originally designed for advanced penetration testing, this Go-based platform is being repurposed by hackers to orchestrate complex, multi-stage attacks with machine-speed efficiency.
Key takeaways:
🤖 Autonomous Attack Orchestration: Attackers are leveraging the tool’s intelligent engine to conduct “agentic” hacking, where AI agents autonomously select and execute the most effective exploits from a library of 100+ integrated security tools.
🛠️ Weaponized Professional Tooling: By repurposing a framework built for ethical hackers, threat actors gain instant access to specialized “security skills” and predefined roles that allow them to execute high-level tactics once reserved for elite APT groups.
🛡️ Adaptive Evasion Techniques: The framework’s Go-based architecture and AI-driven orchestration enable it to modify attack patterns in real-time, making it significantly harder for traditional signature-based defenses to detect or block.
🌐 Scalable Vulnerability Discovery: The tool enables rapid, automated reconnaissance across massive network ranges, allowing attackers to identify and exploit misconfigurations or unpatched flaws within minutes of discovery.
Fake Google Security Site Weaponizes PWAs to Steal MFA Codes
Cybercriminals are now using Progressive Web Apps (PWAs) to create deceptive “Google Security” interfaces designed to harvest user credentials and bypass multi-factor authentication (MFA). By tricking users into installing these “apps,” attackers can operate outside the standard browser interface, effectively hiding the URL and making the phishing attempt look like a legitimate system application.
Key takeaways:
📱 The “No-URL” Deception: Because PWAs run in a standalone window without a traditional browser address bar, users lose their primary visual defense—the ability to verify the website’s domain before entering sensitive data.
🎣 Advanced Social Engineering: Attackers lure victims to a site that mimics a Google security alert, prompting them to “Install the Security App” to resolve a fake account issue, which then places a malicious icon directly on their home screen or desktop.
🔓 Real-Time MFA Theft: The framework is specifically designed to capture login credentials and MFA codes in real-time, allowing attackers to hijack sessions even when secondary security measures are enabled.
🛡️ Defensive Evolution: To mitigate this risk, security teams should prioritize the use of phishing-resistant hardware security keys (FIDO2) and educate users on the dangers of unauthorized “Add to Home Screen” prompts.
Microsoft Warns of OAuth Redirect Abuse Delivering Malware
Microsoft has issued a critical warning regarding phishing campaigns that exploit native OAuth redirection features to bypass traditional security defenses and deliver malware directly to government and public-sector organizations. Attackers are leveraging legitimate identity providers like Entra ID and Google Workspace to craft deceptive URLs that redirect you to malicious landing pages without the need to steal your credentials.
Key takeaways:
🕵️♂️ Native Feature Abuse: The campaign exploits a standard, by-design OAuth feature intended for error scenarios, using manipulated parameters to redirect authenticated users to attacker-controlled infrastructure.
🦠 Malware Delivery Chain: Victims are tricked into downloading ZIP archives via “invalid scope” errors; these files then execute PowerShell scripts and employ DLL side-loading to establish command-and-control (C2) connections.
📧 High-Pressure Lures: Phishing emails use urgent themes like e-signature requests, Teams recordings, and financial or political notifications to bait users into clicking malicious links.
🛠️ Identity-Based Threat: Unlike traditional credential theft, this technique focuses on redirecting you to infect your own device, highlighting a sophisticated shift in how threat actors utilize trusted cloud environments.
New Phishing Alert: When “IT Support” Is Actually a Ransomware Gateway
Cybersecurity researchers have uncovered a sophisticated campaign where attackers overwhelm targets with email spam before calling them personally, masquerading as IT support to deploy the Havoc command-and-control (C2) framework. This multi-layered attack rapidly moves from a simple phone call to full network compromise and persistent lateral movement within hours.
Key takeaways:
📞 The “Human” Hook: Attackers use “email bombing” to create a sense of urgency, then call the victim to offer “help,” leveraging social engineering to gain remote access via tools like Quick Assist or AnyDesk.
🛡️ Advanced Evasion: The campaign utilizes DLL side-loading and techniques like “Hell’s Gate” and “Halo’s Gate” to bypass EDR solutions, making the malware nearly invisible to traditional security software.
🏗️ Diversified Persistence: Beyond the Havoc C2 framework, threat actors are installing legitimate RMM tools (like Level RMM and XEOX) to ensure they maintain access even if their primary malware is detected.
⚡ Aggressive Speed: In observed cases, attackers moved from initial access to nine additional endpoints in just 11 hours, signaling a clear intent for rapid data exfiltration or ransomware deployment.
Massive iOS Exploit Kit “Coruna” Unveiled
Google’s Threat Intelligence Group has uncovered “Coruna,” a highly sophisticated exploit kit leveraging 23 exploits to compromise iPhones running iOS 13 through 17.2.1. This powerful framework, which has transitioned from commercial surveillance to nation-state espionage and criminal use, is currently being deployed to exfiltrate cryptocurrency wallets and sensitive personal data.
Key takeaways:
🚨 Global Proliferation: Coruna represents a dangerous shift in the threat landscape, where “spyware-grade” capabilities have moved from elite surveillance vendors into the hands of broad criminal operations for mass exploitation.
🕵️♂️ Stealthy Execution: The kit utilizes a JavaScript framework to fingerprint your device and selectively deploy Remote Code Execution (RCE) exploits, including those for WebKit vulnerabilities like CVE-2024-23222, to gain full system access.
💰 High-Stakes Data Theft: Infected devices are compromised by the “PlasmaLoader” implant, engineered to target and exfiltrate data from popular cryptocurrency wallets such as MetaMask, Exodus, and Bitget.
🛡️ Your Defense Strategy: The exploit kit is ineffective against the latest iOS versions and automatically skips devices with Lockdown Mode enabled.
Major Strike Against Phishing: Europol Disrupts the Tycoon2FA Network
Europol and international law enforcement have successfully dismantled the infrastructure of Tycoon2FA, a sophisticated “Phishing-as-a-Service” platform used to bypass Multi-Factor Authentication (MFA). This coordinated operation led to server seizures and arrests, striking a significant blow against a toolkit that targeted thousands of Microsoft 365 and Google accounts worldwide.
Key takeaways:
🔒 MFA is Not Invincible: Tycoon2FA specializes in “Adversary-in-the-Middle” (AiTM) attacks, which intercept login credentials and session cookies in real-time to bypass standard MFA protections.
🌐 Lowering the Barrier for Crime: As a Phishing-as-a-Service (PhaaS) provider, Tycoon2FA allowed low-skill hackers to launch high-end attacks for a subscription fee, drastically increasing the volume of global phishing threats.
🛡️ Victory for International Cooperation: This disruption highlights the growing effectiveness of global law enforcement partnerships in taking down the technical backbone of cybercrime syndicates.
💡 Adaptive Defense Needed: While MFA remains a critical layer of security, organizations must now shift toward more phishing-resistant methods, such as hardware security keys (FIDO2) and session monitoring.
Cyber Warfare Escalates: 149 Hacktivist Attacks Strike 110 Global Entities
Following recent military escalations, a massive wave of retaliatory DDoS attacks has hit government and critical infrastructure across 16 countries. New reports indicate that hacktivist groups are increasingly blending disruptive attacks with sophisticated phishing and data-leak strategies to maximize geopolitical and economic impact.
Key takeaways:
🌐 Infrastructure Under Fire: Nearly half of all attacks targeted government sectors, with finance and telecommunications also facing significant disruption from groups like Keymous+ and DieNet.
📱 Deceptive Tactics: Beyond DDoS, attackers are deploying malicious replicas of emergency alert apps to deliver mobile surveillance malware to hyper-vigilant populations.
🛡️ The Resilience Checklist: Organizations must urgently validate network segmentation between IT and OT systems and reduce their external attack surface to mitigate potential fallout.
💡 A Unified Front: As hacktivist groups coordinate across borders, real-time threat intelligence sharing and continuous monitoring are no longer optional—they are critical defense requirements.
FBI Seizes LeakBase and Exposes 142,000 Cybercriminals
The FBI has successfully seized LeakBase.cc, a prominent cybercrime forum used for trading stolen databases and compromised credentials, gaining access to the personal data of over 142,000 members. This major law enforcement operation shifts the “hacker” marketplace into a goldmine of intelligence for federal investigators.
Key takeaways:
🚨 Anonymity is an Illusion: The seizure includes IP addresses, email accounts, and private messages, stripping away the perceived cloak of invisibility for thousands of active threat actors.
🌐 Disrupting the Supply Chain: By dismantling LeakBase, authorities have severed a critical hub in the stolen data economy, making it significantly harder for criminals to monetize leaked information.
🛡️ A Tactical Intelligence Win: Law enforcement can now use this dataset to cross-reference previous breaches, potentially identifying the individuals behind some of the most high-profile hacks of the last year.
💡 The Resilience Test: While this is a victory, history shows threat actors often migrate to new platforms; organizations must remain vigilant and treat every “leaked” credential as a live threat until rotated.
U.S. Department of Justice (DoJ)
Zero-Day Threats on the Rise: Google Reports 90 Exploits in 2025
Google’s latest threat analysis reveals a 15% surge in zero-day exploitation compared to last year, with attackers increasingly pivoting toward enterprise infrastructure and security appliances. For the first time in history, commercial surveillance vendors have overtaken state-sponsored groups as the primary drivers of these sophisticated attacks, signaling a major shift in the global threat landscape.
Key takeaways:
🚨 Enterprise Under Fire: 43 of the 90 tracked zero-days targeted enterprise software, networking equipment, and VPNs—privileged targets that often lack standard endpoint detection (EDR).
🕵️ Spyware Surge: Commercial surveillance vendors (CSVs) are now the lead users of undocumented flaws, selling high-end exploit chains to customers that bypass traditional security hardening.
🏗️ Memory Safety Crisis: Memory corruption vulnerabilities remain a persistent thorn in the side of defenders, accounting for 35% of all exploited zero-day flaws last year.
🛡️ Defensive Priority: Organizations must move beyond basic hygiene; reducing attack surfaces and maintaining rapid incident-response processes are critical to countering actors who are now leveraging AI to accelerate exploit development.
Wikipedia Hit by Self-Propagating JavaScript Worm
Wikipedia recently faced a significant security disruption as a self-propagating JavaScript worm exploited a cross-site scripting (XSS) vulnerability to vandalize thousands of entries. The attack specifically targeted the platform’s “user scripts” feature, turning administrative browsers into unwitting tools for spreading malicious code across the site’s infrastructure.
Key takeaways:
🚨 Automated Infection: The worm functioned by hijacking the browser sessions of users who viewed infected pages, automatically injecting malicious code into their personal JavaScript files to further the spread.
🌐 Privileged Account Risk: Because the worm relied on the permissions of the person viewing the page, administrative accounts were high-value targets that allowed the attack to scale rapidly across protected articles.
🛡️ The Power of Rapid Response: Wikipedia’s security team and volunteer admins were forced to implement global script blocks and mass rollbacks, demonstrating the critical need for “kill switch” capabilities in large-scale web ecosystems.
💡 XSS is Still King: This incident serves as a reminder that stored XSS remains one of the most potent threats to web platforms, necessitating strict input sanitization and Content Security Policies (CSP).
Bing AI Promotes Fake OpenClaw Repo Delivering Malware
Cybercriminals are exploiting the viral popularity of “OpenClaw” AI agents by poisoning search results with malicious GitHub repositories. Alarmingly, Bing’s AI-generated search summaries have been observed recommending these fake links, leading users to install info-stealing malware while believing they are downloading legitimate automation tools.
Key takeaways:
🚨 AI Trust Exploitation: Attackers are leveraging the inherent trust users place in AI-curated answers to bypass the manual scrutiny usually applied to traditional search results.
🦠 Stealthy Payloads: The fake installers deploy “Stealth Packer,” which drops GhostSocks malware to hijack system traffic, bypass firewalls, and evade anti-fraud protections like MFA.
🛡️ Supply Chain Sabotage: With a significant percentage of community-contributed AI “skills” and repos currently flagged as malicious, the open-source AI ecosystem has become a primary target for supply chain attacks.
💡 Critical Verification: This incident highlights the danger of “vibe-based” security; users must manually verify repository stars, contributor history, and official project links rather than trusting AI summaries.
Feature Article

So, you’ve built a Cyber Threat Intelligence (CTI) program. You’re neck-deep in indicators, you’re tracking threat actors, and you’re churning out reports. But when your CISO walks over and asks, “So… is it working? Are we more secure? Are we getting a return on this investment?”—Do you have CTI metrics to give a good answer and demonstrate success?
Too often, CTI teams become bogged down in the details, focusing on the volume of reports produced or indicators collected, rather than on the overall effectiveness of their work. While those numbers are part of the story, they don’t capture the most important things that business values: return on investment (ROI).
Proving your program’s worth can feel like trying to catch smoke.
This guide will help you cut through the noise. We’ll explore why measuring your program is critical, define what success actually looks like for your program, and break down the key CTI metrics you can use to prove your impact to everyone from the SOC analyst to the CEO. Let’s dive in!
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



