Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

QEMU Abused to Evade Detection and Enable Ransomware Delivery
Sophos researchers identified threat actors using the QEMU emulator to create hidden VMs, masking malicious activity from security tools. Linked to STAC4713 and STAC3725, this technique enables credential theft and the deployment of the PayoutsKing ransomware.
Key takeaways
🎯 Target: Corporate networks with exposed, non-MFA VPNs (SonicWall, Cisco) or unpatched vulnerabilities in SolarWinds Web Help Desk and Citrix NetScaler.
💡 Insight: By running an Alpine Linux VM via QEMU on a Windows host, attackers create a “black box” where they can compile and execute attack toolkits (like Impacket and BloodHound) without triggering host-based EDR or antivirus alerts.
☑️ Recommendation 1: (Short-term) Audit environments for unauthorized installations of qemu-system-x86_64.exe and investigate suspicious scheduled tasks, such as “TPMProfiler,” which may be used for persistence.
☑️ Recommendation 2: (Short-term) Monitor for unusual outbound SSH tunnels on non-standard ports and flag virtual disk images using deceptive extensions like .db or .dll.
☑️ Recommendation 3: (Long-term) Enforce multi-factor authentication (MFA) across all remote access points and implement strict application control policies to prevent the execution of unauthorized virtualization software.
Vercel Data Breach: AI-Accelerated Attack Compromises Internal Systems
Vercel confirmed a security breach after attackers used a compromised third-party AI tool to infiltrate internal environments. The incident highlights a shift in which “non-sensitive” data was weaponized to gain deeper access, reportedly risking the exposure of source code and internal tokens.
Key takeaways
🎯 Target: Vercel’s internal infrastructure (GitHub, Linear) and a “limited” subset of customers whose environment variables were exposed.
💡 Insight: The breach originated from a compromised OAuth application associated with Context.ai, an AI platform; attackers used AI-driven automation to move with “surprising velocity,” enumerating “non-sensitive” environment variables to pivot into sensitive production areas.
☑️ Recommendation 1: (Short-term) Google Workspace administrators should immediately audit and revoke any unauthorized OAuth tokens, with a focus on integrations linked to third-party AI platforms such as Context.ai.
☑️ Recommendation 2: (Short-term) Developers should rotate all GitHub, NPM, and cloud access tokens and re-classify “non-sensitive” environment variables that could provide a roadmap for attackers during enumeration.
☑️ Recommendation 3: (Long-term) Implement a “Least Privilege” OAuth governance policy and integrate AI supply chain risk assessments into your vendor security reviews to mitigate “shadow AI” risks.
Apple ID Alerts Abused in MFA Fatigue Attacks
Attackers are using Apple’s password reset system to flood users with alerts, creating “MFA fatigue” to trick victims into granting access. They then use spoofed “Apple Support” calls to steal account recovery keys and one-time codes.
Key takeaways
🎯 Target: Apple users whose email addresses and phone numbers have been exposed in previous data breaches.
💡 Insight: This attack is particularly dangerous because the prompts are legitimate system notifications that bypass browser-based security, making the subsequent “support call” appear highly credible to the average user.
☑️ Recommendation 1: (Short-term) If your device is flooded with reset prompts, do not select “Allow.” Treat any unsolicited “Apple Support” call as a phishing attempt; Apple will never call you to ask for your recovery key or a one-time code.
☑️ Recommendation 2: (Short-term) If you suspect your information is being targeted, ensure your Apple ID password is strong and unique, and audit your “Trusted Devices” list for any unfamiliar hardware.
☑️ Recommendation 3: (Long-term) Transition from SMS-based 2FA to using physical security keys (e.g., YubiKey) for your Apple ID, which provides a hardware-level defense that neutralizes remote credential harvesting and “Push Bombing” tactics.
Systemic RCE Risks Found in Model Context Protocol (MCP)
Researchers have identified a “by design” vulnerability in Anthropic’s Model Context Protocol (MCP) that enables Remote Code Execution (RCE). This flaw allows attackers to weaponize AI connections to local tools, potentially leading to full system takeovers via simple prompts.
Key takeaways
🎯 Target: Enterprises and developers utilizing the Model Context Protocol (MCP) to integrate LLMs with local environments, including users of popular AI IDEs like Windsurf, Cursor, and Claude Desktop.
💡 Insight: This isn’t a traditional coding error but a systemic design choice in the MCP SDK’s STDIO interface; it allows arbitrary OS commands to execute during server initialization, even if the process fails, effectively bypassing existing security boundaries.
☑️ Recommendation 1: Immediately audit all third-party MCP server configurations and restrict installations to verified, official registries to avoid “market-poisoning” attacks and typosquatting.
☑️ Recommendation 2: Implement strict sandboxing (e.g., via Docker or gVisor) for any service or agent running MCP to ensure that an exploited server cannot access sensitive host files, API keys, or internal networks.
☑️ Recommendation 3: Establish a “Human-In-The-Loop” requirement for all MCP configuration changes and tool invocations, treating any external or prompt-driven configuration input as highly untrusted.
How Phishing Apps Are Sneaking Into the Apple App Store to Drain Crypto
Researchers identified 20+ malicious apps on the Apple App Store masquerading as crypto wallets like MetaMask and Ledger. These apps use iOS provisioning profiles to install trojanized versions of legitimate software, bypassing standard security reviews to steal recovery phrases.
Key takeaways
🎯 Target: iOS users and cryptocurrency investors who use hot wallets like MetaMask, Coinbase, Ledger Live, and Trust Wallet.
💡 Insight: This campaign exploits a “hidden in plain sight” strategy, using the App Store’s reputation as a first-stage lure, then leveraging iOS configuration profiles (typically used for enterprise app testing) to install malware that traditional App Store reviews can’t easily detect.
☑️ Recommendation 1: Immediately audit your iOS device for any unfamiliar “Configuration Profiles” in Settings > General > VPN & Device Management and delete any that you did not explicitly authorize for work or known trusted services.
☑️ Recommendation 2: For long-term asset protection, transition the majority of your holdings to a dedicated hardware wallet and never enter your seed phrase into any mobile app or website, even if it appears to be linked from an official store.
☑️ Recommendation 3: Stay vigilant by double-checking the “Developer” information in the App Store before downloading; many of these fake apps use generic or suspicious developer names that do not match the official companies (e.g., ConsenSys for MetaMask).
Inside the High-Velocity RaaS Operation Redefining Ransomware Speed
Check Point Research’s report on “The Gentlemen” reveals a RaaS group that’s become the #2 most active threat actor in 2026. Their aggressive 90/10 revenue split attracts elite affiliates capable of domain-wide encryption within hours.
Key takeaways
🎯 Target: Global corporate environments with a heavy focus on the manufacturing, technology, and healthcare sectors, particularly those utilizing unpatched internet-facing VPNs and firewalls.
💡 Insight: The group utilizes a “Bring Your Own Vulnerable Driver” (BYOVD) technique to systematically neutralize EDR and antivirus tools, combined with the SystemBC proxy malware to create covert tunnels for data exfiltration.
☑️ Recommendation 1: (Short-term) Immediately audit and patch all edge devices—specifically VPN gateways and firewalls—as these remain the group’s primary entry point for initial access.
☑️ Recommendation 2: (Long-term) Implement strict Driver Allowlisting (such as Windows Defender Application Control) to prevent the loading of the unauthorized kernel drivers that The Gentlemen use to kill security software.
☑️ Recommendation 3: Establish real-time monitoring for anomalous Active Directory behavior, specifically focusing on sudden Group Policy Object (GPO) modifications or mass service terminations.
New NGate Malware Variant Relays NFC Data for Fraudulent ATM Withdrawals
Researchers have identified a sophisticated NGate malware variant that hides within trojanized NFC payment apps to intercept and relay card data to attackers. By capturing NFC signals, threat actors can emulate physical cards to perform unauthorized ATM withdrawals and point-of-sale transactions.
Key takeaways
🎯 Target: Clients of financial institutions who are targeted through phishing campaigns and social engineering to install malicious applications.
💡 Insight: NGate uses a specialized tool to relay data from a victim’s physical card to an attacker’s smartphone in real time, enabling “contactless” theft without the card ever leaving the victim’s possession.
☑️ Recommendation 1: Strictly avoid side-loading applications or clicking links in unsolicited SMS or emails; ensure all banking apps are sourced exclusively from official app stores.
☑️ Recommendation 2: Disable NFC on your mobile device when not in use, and consider using physical RFID-blocking sleeves to protect cards from unauthorized proximity scanning.
New macOS ClickFix Campaign Bypasses Security via Terminal Social Engineering
A macOS ClickFix campaign uses social engineering to trick users into running malicious AppleScript in the Terminal. By posing as software fixes, it bypasses security like Gatekeeper by getting users to self-authorize the infection.
Key takeaways
🎯 Target: macOS users interacting with compromised websites or fake landing pages designed to mimic legitimate services like Google Meet, Zoom, or software update prompts.
💡 Insight: The “ClickFix” strategy avoids traditional file-based malware detection by persuading the victim to copy-paste obfuscated code directly into the Terminal, turning the user into the delivery mechanism for info-stealers.
☑️ Recommendation 1: Implement a “Zero Trust” approach to Terminal usage; strictly prohibit executing any commands or scripts sourced from third-party websites or “troubleshooting” pop-ups.
☑️ Recommendation 2: Accelerate the transition to macOS Sequoia to utilize its enhanced permissions model, which requires explicit user consent before the Terminal can access sensitive data or interact with other applications.
Google Patches Critical RCE Flaw in Antigravity AI IDE
Pillar Security researchers discovered a critical vulnerability in Google’s Antigravity IDE. This flaw allows prompt injection to escalate into full Remote Code Execution (RCE) and a complete sandbox escape. By exploiting a native file-search tool, attackers can bypass restrictive security settings to run arbitrary binaries on the host system.
Key takeaways
🎯 Target: Software developers and engineers using AI-powered agentic IDEs, particularly those who work with untrusted source code, public repositories, or external pull requests.
💡 Insight: The exploit bypasses “Secure Mode” because the native find_by_name tool call is executed before security policies are evaluated, allowing an attacker to use the -X (exec-batch) flag to transform a simple search query into a malicious execution engine.
☑️ Recommendation 1: Immediately update your Antigravity IDE to version 1.19.4 or higher to apply the critical sanitization patch for the find_by_name tool.
☑️ Recommendation 2: Treat all external input, including code comments, PR descriptions, and issue bodies, as untrusted instructions that can potentially hijack your AI agent’s privileged tools.
☑️ Recommendation 3: For enterprise environments, shift toward “Execution Isolation” by running autonomous AI agents within hypervisor-level sandboxes to ensure that native tool compromises cannot reach the underlying host or sensitive secrets.
GoGra Malware Leverages Microsoft Graph API to Evade Detection
New Go-based malware, GoGra, targets Linux systems and uses the Microsoft Graph API for C2 communications. By blending in with legitimate Microsoft cloud traffic, it evades detection from traditional network security tools.
Key takeaways
🎯 Target: Linux-based infrastructure, primarily within government agencies, telecommunications, and high-tech sectors.
💡 Insight: GoGra exploits the inherent trust in Microsoft’s global infrastructure; by using the Graph API, it ensures that its C2 traffic is encrypted and blends seamlessly with routine HTTPS traffic to legitimate Microsoft endpoints.
☑️ Recommendation 1: Audit your Microsoft 365/Azure environment for unauthorized OAuth applications. Ensure that only verified applications have the permissions required to interact with the Microsoft Graph API from your production Linux servers.
☑️ Recommendation 2: Implement robust Endpoint Detection and Response (EDR) for Linux. Since network-level filtering may miss API-based C2, focus on detecting unusual process behaviors, such as unexpected Go-based binaries initiating outbound connections to cloud services.
☑️ Recommendation 3: Enforce strict egress filtering and “Zero Trust” network policies. Limit the ability of critical servers to reach external APIs unless there is a validated and documented business necessity, and use TLS inspection to gain visibility into encrypted traffic patterns.
Kyber Ransomware Experiments With Post-Quantum Encryption
Rapid7 research details the Kyber ransomware group targeting VMware ESXi hypervisors and Windows file servers with a combination of cross-platform payloads and “post-quantum” encryption marketing for total operational paralysis across enterprise environments.
Key takeaways
🎯 Target: Mission-critical virtualization infrastructure (VMware ESXi and Hyper-V) and core Windows file servers, specifically within high-value enterprise networks.
💡 Insight: Kyber uses “post-quantum” encryption as marketing; the Windows variant implements a hybrid Kyber-ChaCha20 scheme, while the ESXi version merely advertises it while relying on RSA-4096.
☑️ Recommendation 1: (Short-term) Actively monitor VMware management files, such as /etc/motd and /usr/lib/vmware/hostd/docroot/index.html, for unauthorized modifications or defacement, which are primary indicators of a Kyber ESXi breach.
☑️ Recommendation 2: (Short-term) Implement strict egress filtering and alerting for data exfiltration tools like rclone and unauthorized outbound connections to AWS S3 buckets, as these are the group’s preferred methods for double extortion.
☑️ Recommendation 3: (Long-term) Harden virtualization hosts by disabling SSH unless strictly required, and transition to immutable, air-gapped backups to ensure that even a full hypervisor compromise does not result in irreversible data loss or total management lockout.
GopherWhisper APT Hiding in Plain Sight via Slack, Discord, and Outlook
GopherWhisper, a China-linked actor, uses a Go-based toolkit to turn enterprise tools like Slack and Outlook into covert C2 channels, bypassing defenses to maintain persistence.
Key takeaways
🎯 Target: Primarily government entities and financial institutions, with a significant concentration of activity observed in Mongolia and across various global sectors.
💡 Insight: This campaign uses “Living-off-Trusted-Services” (LoTS) tactics, in which malicious traffic is disguised as routine business activity, such as modifying “Draft” emails in Outlook or sending API requests to Slack, making it nearly indistinguishable from legitimate corporate communications.
☑️ Recommendation 1: (Short-term) Conduct a retroactive audit of Microsoft Graph API logs for unusual “Draft” folder activity or unauthorized API integrations that do not align with established business workflows.
☑️ Recommendation 2: (Short-term) Update EDR/XDR signatures to detect the “LaxGopher” and “RatGopher” malware families and monitor for Go-compiled binaries executing unauthorized network connections to cloud service endpoints.
☑️ Recommendation 3: (Long-term) Implement a strict “Zero Trust” model for application-to-cloud communication, utilizing deep packet inspection (DPI) to validate that traffic to services like Discord or GitHub is tied to a verified business process.
Chinese “Covert Networks” Hijacking SOHO Devices to Mask State-Backed Attacks
A joint advisory reveals China-nexus actors are hijacking consumer routers and IoT devices to create “covert networks.” By using these “Living-off-the-Network” tactics, groups like Volt Typhoon blend malicious traffic with legitimate residential activity to bypass perimeter defenses.
Key takeaways
🎯 Target: Critical national infrastructure, government agencies, defense industrial bases, and educational institutions worldwide, primarily for credential theft and long-term espionage.
💡 Insight: These massive botnets (like “Raptor Train,” which infected 260,000 devices) are often maintained by private Chinese companies to serve as a global proxy layer, rendering traditional geographically based blocking and static IP blacklists virtually obsolete.
☑️ Recommendation 1: (Short-term) Immediately audit and map all network edge devices (routers, firewalls, and NAS) to identify and decommission end-of-life (EoL) hardware that no longer receives security updates.
☑️ Recommendation 2: (Short-term) Enforce robust Multi-Factor Authentication (MFA) on all remote access points and administrative interfaces to mitigate the risk of credential-based entry via these residential proxies.
☑️ Recommendation 3: (Long-term) Transition to a zero-trust architecture and leverage dynamic threat feeds that include known covert network indicators, rather than relying on static IP reputation lists.
National Cyber Security Centre (NCSC-UK)
Checkmarx KICS Tools Poisoned in Stealthy Credential-Theft Campaign
Checkmarx KICS Docker images and VS Code extensions were compromised by “TeamPCP” to steal developer credentials and GitHub tokens. This supply chain attack injects malicious workflows into enterprise repositories to facilitate further propagation.
Key takeaways
🎯 Target: DevOps engineers and developers utilizing Checkmarx KICS for infrastructure-as-code (IaC) scanning and associated VS Code extensions.
💡 Insight: The malware establishes persistence by injecting a rogue workflow (format-check.yml) into any repository it can reach and exfiltrates data to public GitHub repositories using Dune-themed naming conventions like “Shai-Hulud.”
☑️ Recommendation 1: (Immediate) Revert to known-safe versions of Checkmarx KICS and VS Code extensions, and immediately rotate all environment secrets, including GitHub tokens, npm credentials, and cloud API keys.
☑️ Recommendation 2: (Short-term) Conduct a forensic audit of GitHub Action logs for unauthorized workflow executions or unexpected artifact creations that may indicate an active compromise.
☑️ Recommendation 3: (Long-term) Implement “Pinning by Digest” for all CI/CD dependencies; pull Docker images and GitHub Actions by their immutable SHA-256 hashes rather than mutable tags like :latest.
Bitwarden CLI Hijacked on npm to Steal Developer Secrets
Researchers found a hijacked @bitwarden/cli (v2026.4.0) on npm that deploys a credential-stealer. Linked to “TeamPCP,” it targets cloud, GitHub, and AI configs across workstations and CI/CD pipelines.
Key takeaways
🎯 Target: Developers, DevOps engineers, and automated pipelines utilizing the Bitwarden CLI for secret management and automation.
💡 Insight: The malware is unusually comprehensive, hunting for not just standard cloud keys (AWS/Azure/GCP), but also SSH material, shell histories, and modern AI/MCP configuration files (like Claude and Kiro settings) to maximize its reach across high-value developer assets.
☑️ Recommendation 1: (Immediate) Check your global npm installations for @bitwarden/cli version 2026.4.0. If found, uninstall it immediately and rotate ALL secrets on that machine, including GitHub PATs, npm tokens, AWS keys, and SSH identities.
☑️ Recommendation 2: (Short-term) Enforce the use of npm config set ignore-scripts true in CI environments to prevent malicious preinstall hooks from executing unauthorized scripts during package installation.
☑️ Recommendation 3: (Long-term) Implement software composition analysis (SCA) tools and internal package curation to block unverified updates to critical CLI dependencies and ensure only cryptographically signed packages are used in production.
Feature Video
Investigating hundreds of IOCs manually across multiple tools creates a “context gap,” leading to analyst burnout. This video explains how Model Context Protocol (MCP) servers automate this workflow while introducing new attack surfaces.
Key Takeaways:
🧩 MCP acts as a universal standard for AI to pull live intelligence from multiple sources simultaneously.
🛠️ Purpose-built servers deliver scored attribution and mapping directly into security platforms.
⚠️ New risks include trojanized servers and prompt injection; popularity doesn’t equate to security.
🔐 Defend with scoped tokens, isolation, and logging to monitor for anomalous patterns.
📈 AI handles triage, allowing analysts to focus on strategic and geopolitical intelligence.
Success belongs to those who build and govern these automated workflows.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



