Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

The AI Arms Race: Attacks, Exploits & Defenses
Stories
🗞️ Google Detects First AI-Generated Zero-Day Exploit in the Wild — Google’s GTIG confirmed the first zero-day exploit developed with LLM assistance, a sophisticated 2FA bypass, with “AI signatures” like educational annotations and a hallucinated CVSS score embedded in the code.
🗞️ The Dawn of Agentic AI-Driven Intrusion Campaigns — Trend Micro uncovered campaigns SHADOW-AETHER-040 and -064, the first confirmed instances of AI agents autonomously executing intrusion steps against government and financial targets in Latin America, generating bespoke fileless malware on the fly. 🔎 Threat Hunting Package
🗞️ OpenAI’s Daybreak Signals a New Era of Agentic Cybersecurity — OpenAI launched Daybreak, a GPT-5.5-powered platform to automate vulnerability discovery and patch validation, positioning AI as a critical component of defensive operations as the traditional 90-day disclosure window collapses.
Recommendations
☑️ Shift your SOC to AI-powered tooling capable of triaging alerts and analyzing suspicious code at machine speed. Human-only review can no longer keep pace with AI-assisted offensive operations.
☑️ Move beyond legacy 2FA to phishing-resistant FIDO2 hardware security keys and place all system administration tools behind ZTNA, directly mitigating the class of bypass exploit demonstrated in the wild.
☑️ Transition from signature-based detection to behavior-based MDR AI-generated scripts are fileless and bespoke, making them invisible to tools that rely on known file hashes.
☑️ Harden Zero Trust policies to include deep inspection of SSH and ProxyChains tunnel traffic, the primary conduit these agentic campaigns use to grant AI agents access to internal assets.
☑️ Embed autonomous security agents into your CI/CD pipeline and audit AI model guardrails to prevent persona-driven jailbreaking, where attackers trick AI into acting as a malicious expert security auditor.
Supply Chain & Open Source Ecosystem Poisoning
Stories
🗞️ Official Checkmarx Jenkins Plugin Compromised — Attackers hijacked Checkmarx’s legitimate distribution credentials to inject credential-stealing code into the official Jenkins plugin, silently harvesting CI/CD secrets from security-conscious organizations using a tool they fully trusted.
🗞️ Mini “Shai-Hulud” Hits TanStack & Open Source Ecosystem — A sophisticated campaign compromised 84 TanStack npm packages alongside Mistral AI and OpenSearch libraries, using GitHub Actions cache poisoning and “Pwn Request” patterns to publish malicious artifacts with valid Sigstore provenance badges.
🗞️ Shai-Hulud Malware Goes Open Source — TeamPCP leaked the full Shai-Hulud source code and a deployment manual to GitHub, triggering a wave of copycat variants within hours and democratising supply chain attack capability across the threat actor ecosystem.
🗞️ High-Level Abuse of RubyGems for Covert Data Exfiltration — The GemStuffer campaign abused the RubyGems registry as a storage layer rather than a malware distribution channel, using hardcoded API keys to disguise harvested data from UK government portals as legitimate .gem archives.
Recommendations
☑️ Immediately audit and rotate all CI/CD secrets (npm tokens, GitHub PATs, AWS keys, and API keys) and enforce hardware-based MFA on all package publishing accounts, treating any exposure during the affected windows as a confirmed compromise.
☑️ Harden GitHub Actions globally by defaulting permissions: id-token: none and pinning all third-party actions to specific commit SHAs. The Shai-Hulud worm exploits OIDC trusted-publisher workflows to generate valid SLSA Build Level 3 provenance for malicious code.
☑️ Implement strict egress filtering on all build runners and transition to short-lived, dynamically generated OIDC credentials to minimize the blast radius of any future credential theft.
☑️ Scan your CI/CD environments and lockfiles for known IOCs (e.g. router_init.js, strings like “Shai-Hulud: Here We Go Again”) and implement runtime alerting for anomalous environment variable mutations such as HOME overrides to /tmp paths.
Exploiting Trust: Platform, Website & AI Ecosystem Abuse
Stories
🗞️ Official JDownloader Website Links Hijacked to Spread Malware — Attackers compromised JDownloader’s CMS to redirect the “Alternative Installer” and Linux shell download buttons to malicious files, demonstrating that a trusted brand can be weaponized simply by altering download destinations without touching the core software.
🗞️ Malicious Google Ads Abuse Claude.ai to Deliver Malware — Cybercriminals hosted malicious artifacts directly on Claude.ai and promoted them via Google Ads, exploiting the trust chain from a legitimate ad to an official AI platform domain to bypass security filters entirely.
🗞️ Malware Found Hiding in Trending Hugging Face Repository — Researchers uncovered malware embedded in pickle files within a trending Hugging Face repository, exploiting social proof and the inherent insecurity of the pickle format to achieve RCE on AI researchers’ systems without running a traditional script. 🔎 Threat Hunting Package
Recommendations
☑️ Never click sponsored search links or execute commands from shared AI artifacts or trending repositories. Always navigate directly to official vendor domains and treat any “convenient” one-click installer with heightened suspicion.
☑️ Verify digital signatures on all downloaded installers and use automated scanners like modelscan to inspect AI/ML model files before loading them into your environment. The pickle format enables RCE with no script execution required.
☑️ Implement content integrity monitoring to verify that external-facing download links match known-good hashes, and enforce hardware-based MFA on all web CMS management platforms to prevent unauthorized content manipulation.
☑️ Run all AI model development and inference inside sandboxed containers with restricted network egress, and migrate long-term workflows from pickle to the safetensors format, which is non-executable by design.
Critical Vulnerabilities: Patch Now
Stories
🗞️ Dirty Frag Vulnerability Grants Root Access — A deterministic logic bug chain in the Linux networking stack — not a race condition — allows local attackers to gain full root privileges with near-perfect reliability across Ubuntu, RHEL, Fedora, and openSUSE, with a public PoC already available.
🗞️ NGINX Rift: Critical 18-Year-Old RCE Vulnerability Discovered — CVE-2026-42945, a heap overflow in the ngx_http_rewrite_module affecting NGINX versions back to 2008, allows unauthenticated RCE via common URL rewrite configurations, with attackers able to brute-force exploitation due to predictable worker process respawn behavior.
🗞️ New BitLocker Zero-Day Bypass: “YellowKey” PoC Now Public — A functional, publicly released exploit abuses NTFS transaction logs in the Windows Recovery Environment to bypass BitLocker on Windows 11 and Server 2022/2025 systems using default TPM-only configurations, disclosed as a zero-day after researcher frustration with Microsoft’s response process.
Recommendations
☑️ Apply patches immediately: CVE-2026-43284/43500 for Dirty Frag via your distribution’s security advisories, and NGINX Open Source 1.31.0 or 1.30.1 (Plus: R36 P4 / R32 P6) for NGINX Rift. Prioritize any internet-facing NGINX instance using rewrite directives.
☑️ Where immediate patching is not possible, apply interim mitigations: disable the esp4, esp6, and rxrpc kernel modules (Dirty Frag); replace unnamed PCRE captures ($1, $2) with named captures in nginx.conf; and disable WinRE (reagentc /disable) on high-risk portable assets until Microsoft issues a BitLocker patch.
☑️ Layer defense-in-depth controls across all three: enforce strict SELinux or AppArmor policies to restrict memory-write primitives, enable BitLocker TPM+PIN with a strong BIOS/UEFI password to block the YellowKey auto-unlock path, and implement alerting on frequent NGINX worker process restarts as an indicator of active exploitation attempts.
Persistence, Detection Failures & Major Breaches
Stories
🗞️ Hackers Lurked in UK Water Utility for Two Years Undetected — Cl0p ransomware operators spent nearly two years inside South Staffordshire Water’s network after a single phishing email, moving laterally via a domain administrator account while the company’s SOC monitored only 5% of the IT environment, ultimately exfiltrating 4.1TB of data on 633,887 individuals.
🗞️ US Government Demands Answers on Massive Canvas Breach — ShinyHunters exploited “Free-For-Teacher” accounts as an entry point into Instructure’s Canvas LMS, exposing data for approximately 275 million users across 9,000 educational institutions and triggering federal oversight as the government moves to treat EdTech as critical infrastructure.
🗞️ TrickMo C Evolves into a Decentralized Mobile Threat Platform — The latest TrickMo variant uses the TON blockchain for C2, making it nearly impossible to block via DNS filtering, and adds SOCKS5/SSH tunneling to pivot directly from compromised Android devices into victims’ internal corporate networks. 🔎 Threat Hunting Package
Recommendations
☑️ Enforce the Principle of Least Privilege (PoLP) and mandate MFA for all lateral movement (particularly Domain Admin accounts) and conduct an immediate audit of all freemium, trial-tier, and shadow IT accounts to ensure they are brought under centralized SSO/MFA or prohibited entirely.
☑️ Shift from partial or sampled monitoring to a comprehensive MDR strategy delivering 100% visibility across all critical infrastructure assets. The South Staffordshire case is a direct consequence of an active SOC with a 95% blind spot.
☑️ Transition your organization’s MFA strategy from SMS and app-based OTPs to FIDO2 hardware security keys. TrickMo is specifically engineered to intercept, suppress, and overlay software-based authentication methods.
☑️ Update ZTNA policies to detect and alert on anomalous SOCKS5/SSH proxy traffic originating from mobile endpoints, and audit Android devices for any third-party apps holding Accessibility Services permissions, revoking access for all non-essential or unverified software.
Feature Video
Want to customize your MISP instance to suit your cyber threat intelligence work?
Part 2 of my zero-to-production MISP series on YouTube dropped on Monday. In this second installment, we covered:
✅ Themes, UI customization, and Org settings
✅ Custom tags and taxonomies
✅ Custom galaxies
✅The new MISP workflows
✅ Decay models
Whether you’re new to MISP or just need a structured walkthrough, this series takes you from zero to a production-grade deployment – step by step.
CTI practitioners, detection engineers, and threat analysts, this one’s for you!
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



