Triaging the Week 111

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Android 17 to Shield Users by Blocking Malicious Use of Accessibility Services

Google is introducing significant security hardening in Android 17 that, by default, prevents sideloaded apps from accessing sensitive Accessibility Services. This strategic move is designed to dismantle a primary vector for “vishing” (voice phishing) and banking trojans that trick users into granting deep system control to steal credentials. 

Key takeaways:

🚨 Restricted Settings Expanded: Building on features from previous versions, Android 17 will automatically categorize apps installed from third-party sources as “restricted,” blocking their ability to request Accessibility API access unless a user manually navigates deep into system settings to allow it. 

📱 Combatting Vishing: Scammers often use social engineering to walk victims through installing malicious APKs; by adding these friction points, Google aims to stop attackers from remotely “reading” the screen or capturing keystrokes via these hijacked services. 

🛡️ Security by Default: The update focuses on protecting the majority of users from automated malware delivery and “ClickFix” tactics, while still preserving the ability for power users to utilize legitimate niche tools. 

🛠️ Targeting Banking Trojans: Many modern mobile threats rely on “screen overlay” and “event monitoring” capabilities found in Accessibility Services to intercept one-time passwords (OTPs) and banking logins, actions this update significantly complicates.

Android Authority

Fake VPN Installers Used to Hijack Enterprise Credentials

Threat actors are increasingly using “malvertising” and SEO poisoning to trick employees into downloading malicious clones of popular VPN software like Cisco AnyConnect and Fortinet. These fake installers deploy infostealers designed to harvest corporate credentials and bypass MFA by stealing active session cookies.

Key takeaways:

🚨 Search Engine Sabotage: Attackers are buying ad space to place malicious download links at the top of search results, leading users to pixel-perfect replicas of official software pages.

🔒 Targeting Corporate Access: By mimicking trusted enterprise tools, hackers gain a direct foothold in your network by stealing login credentials and session tokens directly from employees’ browsers.

🌐 Sophisticated Impersonation: This campaign specifically targets high-value users by cloning the look and feel of software from vendors like Cisco, Fortinet, and Palo Alto Networks.

🛡️ Enforce Verified Portals: The best defense is a “Managed Software” approach—ensure employees only install tools via your company’s official IT portal or MDM, never from a random search result.

🎯 Threat Hunting Package

Microsoft Security

CrackArmor: 9 Flaws in Linux AppArmor Expose Millions of Systems to Root Exploitation

A collective of nine vulnerabilities, dubbed “CrackArmor,” has been discovered in the Linux kernel’s AppArmor module, allowing attackers to bypass critical security boundaries. These flaws enable unprivileged local users to escalate to root privileges and completely break container isolation across major distributions like Ubuntu, Debian, and SUSE.

Key takeaways:

🚨 The “Confused Deputy” Attack: Attackers can trick privileged tools (like Sudo or Postfix) into modifying AppArmor security profiles through pseudo-files, allowing unprivileged users to disable protections or enforce “deny-all” policies to trigger a Denial of Service (DoS).

🔒 Breaking Container Isolation: The vulnerabilities allow for the creation of fully capable user namespaces, effectively circumventing the security guarantees of containers and Kubernetes environments that rely on AppArmor for least-privilege enforcement.

🛡️ Long-Standing Risk: These flaws have existed since 2017 (Kernel v4.11) and affect an estimated 12.6 million enterprise Linux instances, highlighting a massive, hidden attack surface in “default” security configurations.

💡 Immediate Action Required: Security teams must prioritize immediate kernel patching, as interim mitigations may not fully neutralize the exploitation path. Additionally, it’s recommended to monitor /sys/kernel/security/apparmor/ for unauthorized profile modifications.

Qualys Threat Research Unit (TRU)

MacOS Alert: New ClickFix Campaigns Weaponize AI Tool Installers

Hackers are exploiting developers’ common “curl | sh” installation habit to deploy the MacSync infostealer on macOS systems. These campaigns target high-value assets like SSH keys and crypto wallets by masquerading as legitimate AI and “vibe coding” tools.

Key takeaways

🚨 The “InstallFix” Pretext: Threat actors are shifting from fake browser errors to “InstallFix” tactics that mimic legitimate software setup. Because the curl | sh pattern is common in developer tools like Homebrew or Rust, the malicious commands hide in plain sight.

🕵️‍♂️ Targeted at Developers: The malware specifically targets users of AI agents, code editors, and LLM platforms. These users are high-value targets because they often possess sensitive cloud tokens, SSH keys, and cryptocurrency seed phrases.

🏢 Enterprise-Level Espionage: The malware identifies corporate domains and security software before proceeding. This indicates a strategic shift toward targeted enterprise breaches rather than broad, opportunistic infections.

🛡️ Verify Before You Paste: I strongly recommend a zero-trust mindset for Terminal-based installations. Never copy-paste scripts from unverified websites, and always inspect the content of a shell script before execution to prevent the deployment of obfuscated payloads.

Sophos

Iranian Conflict Sparks 245% Surge in Global Attacks

A massive 245% spike in cybercrime has been recorded since the start of the war in Iran, with banking and critical infrastructure bearing the brunt of the onslaught. This surge, driven primarily by automated reconnaissance and credential harvesting, highlights how physical conflicts now immediately destabilize the global digital landscape.

Key takeaways

🏦 High-Value Targets Under Fire: Banking and fintech are the hardest hit, accounting for 40% of all malicious traffic, followed by e-commerce at 25%.

🕵️‍♂️ Proxies Masking Origin: Only 14% of malicious IPs originate directly from Iran; attackers are heavily utilizing proxies in Russia and China to bypass geographic blocks and maintain stealth.

🔍 Infrastructure Scanning Peak: Reconnaissance efforts have exploded, with botnet-driven discovery traffic jumping 70% and infrastructure scanning up 52%, signaling a massive “softening” of targets for potential follow-up attacks.

🛡️ Actionable Defense: For organizations without a legitimate regional presence, researchers recommend implementing a “deny-all” policy on traffic originating from outside their specific service geographies to mitigate opportunistic probes.

Akamai

GlassWorm Hijacks GitHub Repos via “Force-Push” Malware

The new “ForceMemo” campaign by the GlassWorm threat actor is infiltrating hundreds of Python repositories by exploiting stolen GitHub tokens to inject malicious code. By leveraging history-rewriting techniques, these attackers bypass traditional security alerts, leaving no visible trace in the GitHub UI for unsuspecting developers.

Key takeaways

🚨 Invisible Git Hijacking: Attackers use “force-push” commands to rewrite repository history, preserving the original commit messages and authors to hide malicious injections into setup.py and main.py files.

🔒 IDE Extensions as Entry Points: Initial compromises often stem from malicious VS Code and Cursor extensions designed to steal GitHub Personal Access Tokens (PATs) directly from developer workstations.

🛡️ Zero-Trust for Dependencies: The campaign targets high-value ML research, Django apps, and PyPI packages; always verify the integrity of local clones and use automated secret scanning to detect leaked tokens.

🌐 Stealthy C2 via Blockchain: To evade network detection, the malware fetches its payload URLs from Solana transaction memo fields, effectively using the blockchain as a resilient command-and-control (C2) infrastructure.

🎯 Threat Hunting Package

StepSecurity

LeakNet Ransomware: The Rise of “Bring Your Own Runtime” (BYOR) Attacks

The LeakNet ransomware group is evolving its tactics, moving away from traditional malware loaders to a “Bring Your Own Runtime” (BYOR) strategy. By abusing the legitimate, signed Deno runtime for JavaScript/TypeScript, attackers can bypass application blocklists and execute malicious code directly in system memory.

Key takeaways:

🛠️ Abusing Legitimate Tools: Instead of a custom loader that might trigger alerts, LeakNet installs the signed Deno executable to run malicious scripts, allowing them to slip past filters that only block “untrusted” binaries.

🔒 Fileless Stealth: Malicious payloads are decoded and executed entirely in memory, leaving minimal forensic artifacts on the disk and significantly lowering the chances of detection by standard security tools.

🚨 ClickFix Deception: The attack relies on “ClickFix” social engineering—fake browser prompts that trick users into running malicious PowerShell or VBS scripts to initiate the infection.

🛡️ Actionable Defense: Organizations must monitor for Deno or similar runtimes (like Node.js) appearing in non-developer environments and audit for abnormal outbound traffic to Amazon S3 buckets used for exfiltration.

🎯 Threat Hunting Package

ReliaQuest

AI’s Visual Blind Spot: Malicious Commands Hidden in Plain Sight

A novel “font-rendering” attack exploits a critical disconnect between how AI assistants parse HTML and how browsers render text, allowing attackers to hide dangerous commands that AI assistants mistakenly label as “safe”. By remapping font glyphs, threat actors can present one thing to a human while feeding benign data to the AI’s text-processing engine.

Key takeaways:

🕵️‍♂️ Deceptive Obfuscation: The attack uses custom fonts to perform glyph substitution, displaying malicious instructions (like reverse shell commands) to the user while the underlying HTML contains harmless, “safe” text for the AI to read.

⚠️ Widespread Vulnerability: As of late 2025, this technique successfully bypassed the security filters of major AI models, including ChatGPT, Claude, Copilot, and Gemini, which failed to reconcile the visual output with the raw code.

🚨 Weaponized Trust: This method turns AI assistants into unintentional accomplices; victims are more likely to execute malicious code because the AI provided a false “all-clear” security assessment.

🛡️ Multi-Modal Defense: Traditional text-based scanning is no longer sufficient; organizations must adopt multi-modal security tools that can analyze a page’s visual representation alongside its raw DOM data.

LayerX

Critical Vulnerabilities Discovered in AI Infrastructure: Amazon Bedrock, LangSmith, and SGLang Under Threat

Cybersecurity researchers have uncovered high-severity flaws in major AI development platforms that could lead to stealthy data exfiltration, account takeovers, and remote code execution (RCE). These vulnerabilities highlight a significant disconnect between the “isolated” environments promised by AI providers and the actual network controls in place.

Key takeaways:

🌐 Sandbox Escape via DNS: Amazon Bedrock’s AgentCore Code Interpreter was found to permit outbound DNS queries even in “no network access” mode, enabling attackers to establish command-and-control channels and exfiltrate data via DNS subdomains.

🔑 High-Severity Account Takeover: A URL parameter injection flaw in LangSmith (CVE-2026-25750, CVSS 8.5) allows attackers to steal user bearer tokens and gain unauthorized access to internal SQL queries and proprietary code.

🚨 Unauthenticated RCE: Multiple critical vulnerabilities in SGLang (CVSS 9.8) expose deployments to remote code execution through insecure deserialization of untrusted data, underscoring the risks of unvetted AI generation modules.

🛡️ Actionable Defense: To mitigate these risks, security teams must implement Route53 Resolver DNS Firewalls to block unauthorized resolution and strictly audit IAM roles to enforce the principle of least privilege for all AI agents.

The Hacker News

Nordstrom’s Official Email Infrastructure Weaponized for Stealthy Crypto Scams

Cybercriminals have successfully hijacked Nordstrom’s legitimate email system to send authentic-looking cryptocurrency phishing lures, effectively turning the brand’s high reputation against its own customers. By exploiting misconfigured web triggers, attackers are bypassing all standard security filters, including SPF, DKIM, and DMARC, because the scams originate from Nordstrom’s official servers.

Key takeaways:

🚨 Infrastructure Hijacking: Attackers exploited a flaw in Nordstrom’s automated email triggers (such as a “Share with a Friend” or “Contact Us” form) to blast thousands of malicious messages directly from a trusted domain.

🎣 High-Trust Phishing: Because these emails pass all authentication checks, they are nearly impossible for standard email security tools to flag as “spam” or “spoofing,” making them highly effective at deceiving you.

🛡️ Actionable Defense: You should remain extremely skeptical of any unsolicited crypto or financial offers, even from household brands; always verify urgent requests through a separate, known-good communication channel.

💡 Admin Best Practices: To protect your own brand, ensure all user-input fields in customer-facing forms are strictly sanitized and rate-limited to prevent them from being used as a personal megaphone for hackers.

BleepingComputer

Inside the $500M Fake IT Worker Army: How North Korean Infiltrators Are Hiding in Plain Sight

A new report from IBM X-Force and Flare Research reveals that over 100,000 North Korean “fake” IT workers are successfully infiltrating Western companies, funneling half a billion dollars annually back to Pyongyang. These highly skilled operatives utilize AI-enhanced deception and sophisticated recruitment networks to secure high-paying remote roles in critical sectors like healthcare, finance, and AI.

Key takeaways:

🚨 Sophisticated Deception: Attackers use AI face and voice changers during video interviews and legitimate-looking “stealth startup” identities (often “C Digital LLC”) to bypass standard HR screening processes.

🔒 Infrastructure Indicators: Security teams should audit networks for unauthorized North Korean-linked VPNs such as OConnect/NetKey and serverless messaging apps like IP Messenger (IPMsg) used for covert communication.

💡 The “Team-Hire” Trap: Once embedded, these workers often operate in clandestine groups to maintain high performance and gain privileged system access, making them appear as “star employees” while they funnel funds or exfiltrate data.

🛡️ Advanced Vetting: Defend your organization by looking for resume-to-interview discrepancies regarding location and language, and train hiring managers to spot the subtle audiovisual “glitches” typical of AI-generated personas.

Flare

New “DarkSword” Exploit Chain Targeting iPhones for Mass Data & Crypto Theft

Cybersecurity researchers have uncovered “DarkSword,” a sophisticated iOS exploit kit used by both espionage and financially motivated actors to bypass mobile security. This campaign leverages a chain of vulnerabilities to silently exfiltrate sensitive data, including cryptocurrency wallets, private messages, and photos, directly from iPhones via compromised websites.

Key takeaways:

🔒 Critical Updates Required: DarkSword specifically targets unpatched devices (iOS 18.4–18.7); the most effective defense is ensuring your iPhone is updated to the latest OS version immediately.

🚨 High-Value Data Siphoning: The toolkit deploys malware families like GHOSTBLADE, designed to strip cryptocurrency wallets (Binance, Ledger, Coinbase), Telegram databases, and saved keychain passwords.

🌐 Watering Hole Attacks: Attackers are compromising legitimate websites, including government portals, to inject malicious iframes that trigger the exploit chain the moment a victim visits the page via Safari.

🛡️ Advanced Protection: For users at high risk of targeted attacks, enabling iOS “Lockdown Mode” can provide a vital layer of security against these types of sophisticated browser-based exploits.

🎯 Threat Hunting Package

Lookout

Marquis Data Breach: 672,000 Records Stolen & 74 Banks Disrupted in Supply Chain Fallout

Financial services giant Marquis has revealed that a 2025 ransomware attack led to the theft of sensitive data for over 672,000 individuals, triggering a massive legal battle over vendor negligence. The breach, which originated from a compromised firewall, underscores the devastating “domino effect” that a single entry point can have on the entire U.S. banking infrastructure.

Key takeaways:

🚨 The Vendor Link: The attack was traced back to a vulnerability in SonicWall firewalls, highlighting how even robust perimeter defenses can become a liability if cloud backup credentials or tokens are exposed.

🔒 Sensitive Data Exposure: Stolen information includes Social Security numbers, Taxpayer IDs, and financial account details, placing over half a million people at high risk for identity theft and targeted phishing.

⚖️ Legal & Reputational Storm: Marquis is currently navigating 36 consumer class action lawsuits while simultaneously suing their security vendor for gross negligence—a stark reminder that the costs of a breach extend far beyond the ransom.

🛡️ Actionable Defense: Organizations must treat firewall management as a high-priority task, ensuring that multi-factor authentication (MFA) is enforced for all administrative accounts and that vendor-issued security advisories are acted upon immediately.

BleepingComputer

Is Your Notes App a Goldmine for Hackers?

A sophisticated new Android malware named “Perseus” has been discovered targeting personal note-taking apps to steal highly sensitive data, including passwords and cryptocurrency recovery phrases. Disguised as unofficial IPTV streaming services, this malware grants attackers full remote control over infected devices while systematically scanning for your “digital secrets.”

Key takeaways

🔒 Targets Personal Notes: In a first for Android threats, Perseus specifically scans apps like Google Keep, Samsung Notes, and Microsoft OneNote to harvest manually saved credentials and financial data.

📺 The IPTV Lure: The malware spreads through unofficial APKs (like “Roja Directa TV”) found on third-party stores, exploiting users looking for free sports broadcasts to bypass standard security checks.

🕵️ Complete Device Takeover: By abusing Accessibility Services, Perseus can capture screenshots, simulate user taps, and even deploy “black screen” overlays to hide malicious activity from the victim.

🛡️ Advanced Evasion: The malware calculates a “suspicion score” based on your device’s hardware and battery data to detect if it’s being analyzed by security researchers before it begins its attack.

🎯 Threat Hunting Package

ThreatFabric

DOJ Disrupts Massive 3-Million-Device IoT Botnet Behind Record 31.4 Tbps DDoS Attacks

The U.S. Department of Justice, in coordination with international partners, has successfully dismantled the command-and-control infrastructure of four major IoT botnets—AISURU, Kimwolf, JackSkid, and Mossad. These botnets hijacked over three million devices, including off-brand Android TVs and routers, to launch some of the most powerful distributed denial-of-service (DDoS) attacks ever recorded.

Key takeaways

🚨 Unprecedented Scale: The botnets were responsible for record-breaking DDoS attacks peaking at 31.4 Terabits per second (Tbps), capable of knocking almost any target offline in seconds.

📺 IoT Vulnerabilities: Threat actors primarily targeted “off-brand” Android TVs and consumer routers running outdated firmware or using factory-default credentials to build their malicious network.

💸 Criminal Ecosystem: Beyond DDoS attacks, the infrastructure was monetized as “residential proxy” services, allowing other cybercriminals to mask their identity for fraud, extortion, and romance scams.

🛡️ Defense Strategy: This operation underscores the critical need for “security by design” in IoT devices; organizations and consumers must immediately update firmware and replace default administrative passwords.

U.S. Department of Justice (DoJ)


Feature Video

Tired of jumping between 10 tabs and static Word docs during an incident? 😴 

What if your security playbooks were “living” documents that could actually execute code?

Jupyter Notebooks aren’t just for data scientists; they are a total game-changer for security operations. This video breaks down how to use them as your new “single pane of glass.”

Here’s what you’ll learn:

💻 What they are: Jupyter Notebooks combine rich markdown (your playbook) with live Python code (your tools) in one interactive document.

🤖 How to use them: Automate your IR process! Pull data from your SIEM/EDR, enrich IOCs via APIs (like VirusTotal), and visualize results all in one place.

🤝 Why they rock: Create shareable, interactive tools for your whole team, perfectly blending documentation with execution.

🚀 A head start: We check out the “Juniverse” project, a massive library of pre-built cybersecurity notebooks you can use right now.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools