Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Theme 1: The Human is the Perimeter — Social Engineering & Identity Abuse
Stories
🗞️ UNC6692 SNOW (Teams) — Microsoft Teams social engineering deploying modular malware against IT staff in critical infrastructure, with a “double-entry” password trick that ensures data accuracy while reinforcing false legitimacy. 🔎 Threat Hunting Package
🗞️ BlackFile Gang — Vishing-led attacks on retail and hospitality that skip custom malware entirely, abusing Microsoft Graph and Salesforce APIs under the cover of legitimate SSO-authenticated sessions. 🔎 Threat Hunting Package
🗞️ IRSF / Keitaro Fake CAPTCHA — A “ClickFix” scam exploiting the muscle memory of clicking “Verify,” which secretly triggers a hidden tel: URI that auto-dials premium-rate international numbers for instant fraud revenue. 🔎 Threat Hunting Package
🗞️ Robinhood notification abuse — An unsanitized “Device Name” field at sign-up allows attackers to embed raw HTML in legitimate “unrecognized login” emails that pass every SPF, DKIM, and DMARC check.
🗞️ BlueKit phishing platform — An AI-powered phishing-as-a-service kit with 40+ templates that goes beyond credentials, performing live session monitoring and browser-storage dumps to keep access even after password changes.
🗞️ FBI cargo theft surge — A 60% rise in cyber-enabled cargo theft, where criminals alter official FMCSA registration and insurance records, making impersonation invisible until the shipment is long gone.
Recommendations
☑️ Move to phishing-resistant MFA (FIDO2 keys) — neutralizes credential harvesters and session-cookie replay across all six stories.
☑️ Mandate out-of-band verification for sensitive actions: IT helpdesk requests, freight release, broker changes, MFA device enrolment.
☑️ Audit and tighten SaaS API scopes (Graph, Salesforce) and configure IAM alerts for new device enrollments originating from residential proxies or anti-detect browsers.
☑️ Refresh awareness training to cover ClickFix, vishing/IT impersonation, and trusted-domain template injection — three patterns staff have not historically been trained on.
☑️ Adopt continuous Zero Trust session validation to prevent stolen cookies from being replayed on unmanaged devices.
Theme 2: Supply Chain Sabotage — The Developer Ecosystem Under Siege
Stories
🗞️ 73 Malicious VS Code Extensions — Sleeper plugins on the Open VSX Registry that worked normally for extended periods to build a reputation and bypass automated scanners before activating their payloads. 🔎 Threat Hunting Package
🗞️ elementary-data PyPI compromise — Attackers bypassed branch protections via a GitHub Actions issue-comment script injection, forging a signed orphan commit that triggered the official release pipeline.
🗞️ Quick Page/Post Redirect WordPress plugin — An “inside job” where the plugin author personally committed malicious code to v5.2.3, weaponizing the official update channel to sail past third-party tampering filters.
🗞️ PyTorch Lightning (”Mini Shai-Hulud”) — A self-spreading worm in versions 2.6.2 / 2.6.3 that impersonates Claude Code in Git commits, making malicious changes look like legitimate AI-generated fixes.
🗞️ PromptMink — North Korean Famous Chollima crafting “AI-friendly” documentation specifically to trick LLM coding assistants into recommending malicious npm and PyPI packages — a new tactic dubbed LLM Optimization (LLMO) abuse. 🔎Threat Hunting Package
Recommendations
☑️ Audit and remove the named compromised packages immediately; rotate every secret, cloud token, SSH key, and CI/CD credential in any environment that touched them.
☑️ Move CI/CD to Trusted Publishers / OIDC and add runner-level network filtering for outbound C2.
☑️ Implement file-integrity monitoring against official checksums and SBOM scanning (version numbers alone are no longer trustworthy).
☑️ Apply zero-trust scrutiny to AI-recommended dependencies (reputation, age, publisher history) before merging them.
☑️ Audit Git history for unusual commits, especially anything impersonating [email protected] or similar AI-assistant identities.
Theme 3: AI as Both Weapon and Target
Stories
🗞️ Hugging Face LeRobot RCE (CVE-2026-25874) — Despite Hugging Face inventing Safetensors to replace pickle, their own gRPC networking code used # nosec comments to silence scanners flagging dangerous pickle.loads() calls on unauthenticated channels.
🗞️ LiteLLM SQL injection (CVE-2026-42208) — Exploited within 36 hours of disclosure; a single SQLi harvests admin keys for OpenAI, Anthropic, AWS Bedrock, and more, making the AI gateway a “keys to the kingdom” target.
🗞️ AI on the offensive side (PromptMink) — Attackers are now tuning malware package documentation for LLM consumption, deliberately weaponizing the trust developers place in AI coding assistants. 🔎 Threat Hunting Package
🗞️ AI on the defensive side (Pack2TheRoot &GitHub RCE) — Both bugs were surfaced via AI-assisted research, with the GitHub flaw representing one of the first critical vulnerabilities ever found in closed-source binaries using LLMs.
Recommendations
☑️ Treat AI gateways (LiteLLM and similar) as Tier-0 systems — they centralize credentials for all downstream providers.
☑️ After any AI-stack disclosure, patch immediately and rotate all keys the gateway manages; assume compromise during the exposure window.
☑️ Eliminate pickle deserialization on untrusted inputs across ML codebases and require TLS/mTLS on inference gRPC channels.
☑️ Hunt for # nosec, # noqa, and similar suppressions in security-sensitive paths. They are a reliable pattern for finding overlooked risk.
☑️ Build internal capability for AI-assisted vulnerability research and code review; the asymmetric advantage is now real on both sides.
Theme 4: Foundational Cracks — Privilege Escalation & Network Edge
Stories
🗞️ Firestarter (Cisco) — A state-sponsored backdoor on Firepower / ASA / FTD that achieves “unkillable” persistence by manipulating Cisco’s CSP_MOUNT_LIST, surviving firmware updates and reboots, and defeating software-only remediation.
🗞️ Pack2TheRoot (CVE-2026-41651) — A TOCTOU race condition in the PackageKit daemon that hid across major Linux distros for over a decade surfaced this month through AI-assisted research with Claude Opus.
🗞️ Copy Fail (CVE-2026-31431) — A 100% reliable Linux kernel logic bug (no race) that corrupts only the in-memory page cache, leaving on-disk hashes valid and the exploit invisible to standard file integrity monitoring.
🗞️ cPanel / WHM 2FA bypass — A flaw in security token validation that effectively nullifies multi-factor authentication, letting attackers walk into high-privilege WHM accounts even with 2FA enabled.
🗞️ GitHub RCE (CVE-2026-3854) — A delimiter-injection flaw in git push options across microservices written in different languages (Go, Ruby, C++); another landmark AI-assisted discovery in closed-source code.
Recommendations
☑️ Patch immediately: Cisco ASA/FTD per AR26-113A; PackageKit ≥ 1.3.5; latest kernel for CVE-2026-31431; cPanel 11.110.0.1+; and GHES per the advisory range.
☑️ Where patching is delayed, apply the documented mitigations: mask packagekit.service, blacklist algif_aead, and tighten GHES write access.
☑️ Baseline and integrity-monitor boot-level configurations and kernel modules. Modern persistence lives below the file system.
☑️ Review cross-service protocols for delimiter/injection risks, especially at language boundaries in microservice architectures.
☑️ For perimeter devices, adopt a “clean rebuild from trusted media” policy. Assume a software reload is insufficient to defend against boot-level implants.
Theme 5: When Attacks Land — Mass Breaches and Destructive Outcomes
Stories
🗞️ ShinyHunters / Pitney Bowes — 8.2M records leaked as one node in a relentless “scalping” campaign also hitting Rockstar Games and Carnival Cruises, reportedly via misconfigurations in SaaS platforms like Salesforce.
🗞️ VECT 2.0 ransomware-turned-wiper — A polished RaaS with a slick affiliate panel that contains an amateurish coding error: it generates four decryption nonces and discards three, permanently destroying any file over 128KB and making ransom payment pointless. 🔎 Threat Hunting Package
Recommendations
☑️ For SaaS-heavy estates: audit Salesforce, SharePoint, and Snowflake permissions for public access and overprivileged API keys — these are the active intrusion paths.
☑️ Adopt a firm no-payment stance against VECT 2.0; the operators technically cannot decrypt large files even if they wanted to.
☑️ Prioritize 3-2-1 backups with immutable/offline copies physically or logically isolated. The only viable recovery against modern wipers and exfiltration extortion.
☑️ Monitor for force-safemode registry modifications and disable SSH on ESXi to limit ransomware movement through the virtualization layer.
☑️ Treat any breached org’s PII as fuel for downstream credential stuffing and spear-phishing. Proactive credential rotation and MFA enforcement matter even if you weren’t the original victim.
Feature Livestream
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



