Triaging the Week 112

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

New VoidStealer Malware Bypasses Chrome Security via “Debugger Trick”

A sophisticated new information stealer, VoidStealer, is bypassing Google’s Application-Bound Encryption (ABE) by using hardware breakpoints to snatch master keys directly from browser memory. This novel technique allows attackers to decrypt and exfiltrate sensitive data without requiring privilege escalation or traditional code injection.

Key takeaways:

🚨 Stealthy Memory Extraction: VoidStealer attaches to hidden browser processes as a debugger, waiting for the exact moment the master key is in plaintext during startup to extract it using hardware breakpoints.

🦠 Bypassing Advanced Protections: This method effectively neutralizes Google’s ABE security (introduced in Chrome 127), which was designed to keep encryption keys inaccessible to user-level malware.

🛡️ Weaponized Open-Source Research: The malware likely adopted this exploit from open-source projects such as ‘ElevationKatz,’ highlighting a dangerous trend in which Malware-as-a-Service (MaaS) platforms rapidly integrate public security research.

💡 Proactive Monitoring Needed: To counter this threat, security teams should monitor for unauthorized processes attempting to attach to browsers as debuggers or launch with debugging flags.

Gen Digital

Supply Chain Alert: Trivy Vulnerability Scanner Hijacked to Spread Malware

The popular Trivy vulnerability scanner was recently compromised in a sophisticated supply chain attack in which attackers hijacked GitHub Actions to distribute an infostealer targeting sensitive CI/CD credentials. By compromising maintainer tokens, the threat actor “TeamPCP” poisoned nearly all version tags of the official repository, turning a trusted security tool into a vehicle for massive data exfiltration.

Key takeaways:

🔒 Supply Chain Poisoning: Attackers force-pushed malicious code to 75 out of 76 tags in the trivy-action repository, ensuring that any workflow pulling standard version tags automatically executed the malware.

⚙️ High-Value Data Harvest: The infostealer was specifically designed to snatch AWS/GCP/Azure keys, Kubernetes configs, SSH keys, and environment variables directly from the memory of CI/CD runners.

🦠 Persistence & Backdoors: Beyond immediate theft, the malware installs a Python-based persistent backdoor via a systemd service, allowing the attackers to maintain long-term access to compromised environments.

🛡️ Immediate Remediation Required: If your pipelines utilized Trivy during the breach window, simply updating isn’t enough; you must rotate all secrets, tokens, and cloud credentials exposed to that environment.

🎯 Threat Hunting Package

Wiz

FBI Warns of Russian Intelligence Targeting Signal & WhatsApp

A widespread phishing campaign by Russian-linked actors is currently hijacking thousands of Signal and WhatsApp accounts by exploiting human trust rather than technical vulnerabilities. These sophisticated “account takeovers” allow attackers to exfiltrate private messages and impersonate high-value targets, including government officials, military personnel, and journalists.

Key takeaways:

🔒 Encryption Bypassed via Linking: Attackers aren’t “cracking” encryption; instead, they use social engineering to trick victims into scanning QR codes that link the attacker’s device to the victim’s account, granting full access to message history.

🕵️‍♂️ Mass Impersonation Tactics: Once an account is compromised, threat actors leverage the victim’s trusted identity to send malicious links to their contacts, creating a dangerous ripple effect across secure professional networks.

🌐 Fake “Support” Bots: The campaign frequently uses non-existent “Signal Support” bots or fake security prompts to request verification PINs—a major red flag, as official support will never initiate contact this way.

🛡️ Immediate Defense Steps: Secure your identity by enabling “Registration Lock” (PIN) within your app settings and immediately auditing your “Linked Devices” list to remove any unrecognized entries.

U.S. Cybersecurity and Infrastructure Security Agency (CISA)

North Korean Hackers Hijack VS Code Auto-Updates for Malware Delivery

North Korean state-sponsored threat actors are exploiting Visual Studio Code’s auto-update mechanism to distribute malicious payloads directly to developers. This advanced supply chain attack targets the tools used to build secure software, turning a trusted update process into a critical entry point for network compromise.

Key takeaways: 

🕵️‍♂️ Developer-Centric Targeting: Attackers are focusing on development environments to gain high-level access to corporate infrastructure and sensitive source code.

🦠 Mechanism Abuse: The campaign leverages the trusted auto-update feature of VS Code, allowing malware to bypass traditional security filters by masquerading as legitimate software traffic.

🛡️ Defensive Action: Organizations should implement strict monitoring for developer tool processes via EDR/XDR and consider manual verification for updates on sensitive workstations.

🚨 Global Risk: This tactic highlights an evolving trend of targeting developer communities to achieve significant downstream impact through supply chain exploitation.

🎯 Threat Hunting Package

NTT Security 

The Return of Tycoon2FA: Sophisticated MFA-Bypassing Phishing Platform Resurfaces

Despite a major law enforcement disruption earlier this year, the notorious Tycoon2FA phishing-as-a-service (PhaaS) platform has returned with a stealthier, upgraded version. This Adversary-in-the-Middle (AitM) kit is specifically designed to bypass Multi-Factor Authentication (MFA) and hijack Microsoft 365 and Gmail accounts.

Key takeaways:

🛡️ Advanced AitM Attacks: Tycoon2fa remains a top-tier threat, using sophisticated proxying techniques to intercept session tokens, rendering standard SMS or app-based MFA ineffective.

🔒 Improved Stealth: The new version features enhanced obfuscation and updated delivery mechanisms to evade modern email security filters and automated detection systems.

🚨 Persistent Threat Landscape: This resurgence highlights the extreme resilience of Phishing-as-a-Service operations; law enforcement “takedowns” are often temporary setbacks rather than permanent solutions.

💡 Security Recommendation: To counter these AitM threats, organizations should prioritize the transition to phishing-resistant MFA (such as FIDO2 security keys) and monitor for anomalous login locations or session behaviors.

🎯 Threat Hunting Package

CrowdStrike

Massive IRS Phishing Campaign Hits 29,000+ Organizations

Microsoft security researchers have detected a widespread phishing operation that exploits the urgency of tax season to target tens of thousands of users across organizations worldwide. The campaign employs highly convincing IRS-themed lures designed to harvest Microsoft 365 credentials and compromise corporate environments.

Key takeaways:

📈 Seasonal Exploitation: Attackers are leveraging “timeliness” by syncing their campaign with the 2026 tax filing season to maximize user engagement and curiosity.

🎭 Authority Impersonation: By using the “prominence” of the IRS, threat actors create a sense of urgency and conflict that pressures users into making quick, poorly vetted decisions.

🔒 Proactive Defense: Organizations should immediately alert staff to be wary of “tax-related” emails and enforce phishing-resistant Multi-Factor Authentication (MFA) to mitigate the risk of account takeover.

🛡️ Broad Impact: With over 29,000 organizations affected, this “ocean-level” threat highlights how attackers are moving from niche targets to broad, high-impact supply chain-style targeting. 

🎯 Threat Hunting Package

Microsoft Security

Hackers are Using AI-Powered Resumes to Infiltrate Networks

A sophisticated new cyber campaign is targeting HR departments and recruiters by using AI-generated resumes and deepfake personas to deploy malware. These attackers are moving beyond simple phishing, conducting full “interviews” using forged video and audio to trick staff into downloading malicious payloads.

Key takeaways:

🤖 AI-Enhanced Deception: Threat actors are using generative AI to create highly convincing digital footprints, including professional LinkedIn profiles and GitHub repositories, to appear as legitimate job seekers.

🎥 Deepfake Interviews: In an alarming escalation, attackers are using real-time deepfake technology to bypass video interviews and impersonate executives during internal calls to authorize malicious downloads.

🦠 Malware Delivery: The “resumes” often contain hidden scripts or links to cloud-hosted malware that, once opened, provide attackers with a persistent foothold in the corporate network.

🛡️ Verification is Vital: Organizations must implement multi-factor identity verification for remote candidates and treat any request to download software or disable security settings during the hiring process as a high-risk red flag.

🎯 Threat Hunting Package

Securonix

FCC Bans New Foreign-Made Routers Over Cyber Risks

The U.S. Federal Communications Commission (FCC) has officially added all new foreign-produced consumer routers to its “Covered List,” effectively banning their import and sale due to “unacceptable risks” to national security. This sweeping move aims to secure the digital supply chain after state-sponsored actors were found exploiting vulnerabilities in home and small-office routers to infiltrate critical infrastructure.

Key takeaways:

🚨 National Security Threat: The FCC cited evidence that foreign-made routers have been “directly implicated” in major cyber campaigns, including Volt, Flax, and Salt Typhoon, in hosting malicious activities and targeting U.S. infrastructure.

📦 Broad Impact on Manufacturers: The ban covers any new router model where major stages of design, development, or assembly occur outside the U.S., impacting nearly every major brand from TP-Link to Netgear unless they have onshore production.

🛡️ Existing Devices are Safe: While you don’t need to replace your current hardware immediately, the FCC noted that firmware and security updates for authorized foreign-made routers are only guaranteed until at least early 2027.

💡 Strict Exemption Rules: To receive a “Conditional Approval” for new models, manufacturers must now provide a transparent bill of materials and a time-bound plan to move critical manufacturing components to the United States.

BleepingComputer

New Device Code Phishing Wave Hitting Microsoft Tenants

A highly sophisticated phishing campaign is currently exploiting the Microsoft “Device Code” flow to bypass Multi-Factor Authentication (MFA) and gain unauthorized access to hundreds of organizational environments. This attack strategy leverages legitimate Microsoft authentication processes to deceive users into granting attackers full account tokens, effectively “living off the land” to evade traditional security filters.

Key takeaways 

🚨 MFA Bypass Vulnerability: Attackers use the Device Code flow to trick users into authorizing a malicious session on a legitimate Microsoft page, potentially rendering standard MFA protections ineffective.

💡 Infrastructure Exploitation: By using legitimate Microsoft URLs (microsoft.com/devicelogin) for the code entry, the campaign successfully bypasses many automated email security systems that look for malicious links.

🛡️ Defensive Hardening: Organizations should immediately review Entra ID (Azure AD) sign-in logs for unusual device code requests and consider disabling this flow if it is not required for your specific business operations.

🔒 Critical User Training: Ensure your team understands that a 9-character code should only be entered if they personally initiated a login on a secondary device without a browser; unexpected code requests are a red flag for an active attack.

🎯 Threat Hunting Package

Huntress

Bubble AI App Builder Exploited for Microsoft Credential Theft

Cybercriminals are now abusing the Bubble.io AI-powered app builder to host sophisticated phishing applications that bypass traditional email security filters. By using legitimate platform domains, these “no-code” malicious apps trick users into a redirect chain that harvests Microsoft 365 credentials and session cookies in real time.

Key takeaways

🌐 Infrastructure Abuse: Attackers use the trusted reputation of the bubbleapps.io domain to ensure phishing links reach your inbox without being flagged by standard reputation-based filters.

🚨 Detection Evasion: The AI-generated code creates a complex jumble of JavaScript and Shadow DOM structures, making it extremely difficult for automated security scanners to analyze the malicious intent.

💡 MFA Bypass Risk: These campaigns often employ Adversary-in-the-Middle (AiTM) techniques, enabling threat actors to intercept 2FA tokens and gain full access to corporate accounts, even when multifactor authentication is enabled.

🛡️ Defensive Action: Transition your team toward FIDO2-compliant hardware security keys, which are resistant to this type of session hijacking, and ensure all employees are trained to never enter credentials on non-company domains.

Kaspersky

GitHub Unveils AI-Powered Security Detections

GitHub is fundamentally shifting the security landscape by integrating AI-based scanning into its Code Security suite to find vulnerabilities that traditional static analysis (SAST) often misses. This hybrid approach combines the precision of CodeQL with the contextual power of AI to secure ecosystems such as Terraform, Docker, and Bash scripts directly in the developer’s pull request.

Key takeaways

🌐 Expanded Ecosystem Coverage: The new AI engine moves beyond core application logic to secure critical “infrastructure-as-code” and scripting environments, including Shell, PHP, and HCL, which are historically difficult to scan accurately.

🚨 Shift-Left Integration: By triggering these detections at the Pull Request level, security is enforced at the point of merge, preventing vulnerable configurations from ever reaching production.

💡 Accelerated Remediation: Paired with Copilot Autofix, the system not only identifies bugs but suggests code-level fixes, reportedly reducing the time to resolve security alerts by nearly 50%.

🛡️ Proven Efficacy: Internal testing across 170,000 findings yielded an 80% developer satisfaction rate, signaling a major reduction in the “false positive” fatigue that often plagues traditional security tools.

BleepingComputer

New Coruna iOS Exploit Kit Reuses 2023 Flaws to Target iPhones

Security researchers have uncovered a sophisticated mobile threat dubbed the “Coruna” exploit kit that reuses vulnerabilities first identified in 2023 to infiltrate iOS devices. This discovery highlights a growing trend where threat actors weaponize older, known flaws to bypass modern security standards.

Key takeaways:

🔄 Exploit Recycling: The Coruna kit demonstrates that “N-day” vulnerabilities remain highly effective when repackaged into new, stealthy delivery frameworks, proving that threat actors can find value in older code.

🕵️‍♂️ Targeted Espionage: Engineered for high-precision surveillance, this toolset uses advanced obfuscation to bypass standard mobile monitoring and exfiltrate sensitive user data.

🛡️ Strategic Pressure: The persistence of these kits emphasizes that simply releasing a patch is not enough; rapid adoption of updates is critical to closing the window of opportunity for attackers.

🔒 Proactive Defense: High-risk individuals and organizations should activate iOS Lockdown Mode and enforce strict mobile device management (MDM) policies to mitigate these sophisticated attack chains.

Kaspersky

Claude Extension Flaw Enabled Zero-Click Prompt Injection via Any Website

Cybersecurity researchers have uncovered a critical vulnerability in Anthropic’s Claude Google Chrome Extension that allowed malicious websites to silently hijack the AI assistant. This “zero-click” flaw enabled attackers to inject arbitrary prompts as if they were written by the user, potentially compromising sensitive data without any user interaction.

Key takeaways:

🚨 Zero-Click Exploitation: The vulnerability bypassed traditional security prompts, allowing any website to “shadow-write” instructions to the Claude extension the moment a user visited a malicious page.

💉 XSS-Driven Injection: The flaw combined Cross-Site Scripting (XSS) with prompt injection, effectively turning the AI agent into a tool for data exfiltration or unauthorized actions.

🛡️ Critical Patch Released: Anthropic has addressed the issue in version 1.0.41 of the extension by implementing strict origin checks that restrict communication solely to the claude.ai domain.

💡 AI Governance Gap: This incident highlights the growing security risks of browser-based AI agents and the urgent need for robust “sandboxing” when extensions bridge the gap between web content and LLMs.

Koi Security

New Phishing Wave Targets TikTok for Business Accounts

A sophisticated phishing campaign is currently impersonating TikTok Support to hijack high-value business and creator accounts. Attackers use deceptive “policy violation” warnings to lure users into providing credentials or scanning malicious QR codes.

Key takeaways:

🚨 Policy Fear-Mongering: The attack starts with urgent emails claiming “trademark infringement,” pressuring users to act quickly to avoid account suspension, a classic social engineering tactic designed to bypass critical thinking.

🔗 Look-alike Domains: Scammers direct victims to highly convincing fake support portals designed to harvest credentials and session cookies, which can enable account takeover even if multi-factor authentication is active.

🤳 QR Code Risks: Some variations of this campaign use QR codes to redirect mobile users to phishing sites, a technique known as “quishing” that often bypasses traditional email security filters.

🛡️ Verification is Vital: Always verify your account status directly through the official TikTok app or Business Suite. Never click links or download attachments from unexpected emails regarding “legal issues” or “copyright claims.”

🎯 Threat Hunting Package

Push Security

Stealthy Chinese Backdoor Targets Linux Infrastructure

Cybersecurity researchers have identified a sophisticated new variant of the BPFdoor malware, linked to the China-based threat actor Red Menshen, targeting Linux systems. This “passive” backdoor is specifically engineered to infiltrate telecommunications and government sectors while remaining nearly invisible to traditional security monitoring.

Key takeaways:

🚨 Passive Stealth: BPFdoor avoids opening traditional network ports, instead using Berkeley Packet Filter (BPF) technology to “sniff” for specific trigger packets. This allows it to bypass firewalls and stay hidden from standard port scans.

🌐 Strategic Espionage: The campaign’s focus on critical infrastructure and government entities suggests a high-priority mission centered on long-term intelligence gathering and persistent network access.

🛡️ Advanced Evasion: This latest iteration features enhanced obfuscation and anti-analysis techniques, making it significantly harder for standard Endpoint Detection and Response (EDR) tools to identify malicious kernel-level activity.

💡 Detection Shift: Defense teams must evolve beyond monitoring open ports. Identifying this threat requires deep packet inspection and auditing for unauthorized raw sockets or unexpected BPF filters within the Linux kernel.

🎯 Threat Hunting Package

Rapid7 Labs


Feature Video

Your security team isn’t losing because they lack data. They’re losing because data alone has never stopped a breach. Intelligence does!

Communicating that intelligence with executives is a challenge we all face. This video breaks down how you can do just that. It walks you through effectively explaining to leadership how your CTI team turns raw data into actionable insights.

🔍 Data tells you something happened — a log entry, a file hash, a packet capture. Raw and context-free.

⚙️ Information tells you what happened — structured, enriched, answering who, where, and when.

🧠 Intelligence tells you what to do about it — adversary context, likelihood of impact, and recommended controls. Most organizations haven’t built this step yet.

🗣️ Communicating these distinctions is the key — no TTPs, no Pyramid of Pain. Translate everything into a business context: dwell time, breach cost, regulatory exposure, ROI.

Collecting data is a cost. Turning it into intelligence is where the return on your security investment actually lives.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defense strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training equips students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools