Triaging the Week 125

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

🤖 AI Agents & MCP Targeted

Stories
🗞️ High-Severity Amazon Q Developer Flaw Enables Cloud Credential Theft via MCP Auto-Execution (Wiz) — CVE-2026-12957 in the Amazon Q VS Code extension auto-executes MCP server configs from workspace files (.amazonq/mcp.json) with no user consent. Because the spawned shell inherits the developer’s environment, opening a malicious repo hands attackers live AWS tokens.
🗞️ How Attackers “Game” Agentic Browsers to Escape Security Guardrails (LayerX) — “BioShocking” traps agentic browsers (Atlas, Comet, Claude Chrome) in a gamified context where logic is subverted (e.g., accepting 2+2=5), so the agent stops applying real-world safety restrictions and blindly exfiltrates data from authenticated sessions.
🗞️ Universal Shell Injection Vulnerability in Open-Source AI Coding Agents (Adversa AI) — “GuardFall” defeats regex safety filters with shell-quoting tricks (r''m -rf) that bash collapses back into destructive commands after the check passes. Hits opencode, goose, cline, Roo-Code, OpenHands, SWE-agent and more.
🗞️ Shielding AI Agents Against MCP Tool Description Poisoning (Microsoft) — Malicious instructions hidden in natural-language MCP tool descriptions are treated as legitimate owner commands. A poisoned third-party tool update silently harvests data while returning a flawless answer to the user.
🗞️ The Emergence of Autonomous AI-Driven Agentic Ransomware (Sysdig) — JADEPUFFER is the first end-to-end ransomware campaign fully orchestrated by an AI agent, using LLMs to generate self-narrating payloads that autonomously fix failed exploit steps in real time. Targets exposed Langflow, Nacos, and MySQL.

Recommendations
☑️ Kill unattended auto-execution: reload/patch to AWS Language Server 1.65.0+, drop --auto-exec/--auto-yes flags in high-privilege environments, and enforce centralized workspace-trust so IDEs don’t run tasks or MCP configs from untrusted directories.
☑️ Lock down MCP: turn off “Allow all,” scope agents to explicit named tools, mandate human-in-the-loop sign-off for high-risk actions, and freeze/flag any tool whose metadata changes — treat a description update like a system-prompt change.
☑️ Isolate the agent’s blast radius: segregate authenticated enterprise sessions from untrusted tabs, unmount real $HOME/SSH keys/cloud creds when running local agents, and require explicit user prompts before data leaves an authenticated environment.
☑️ Harden the infrastructure agents touch: patch Langflow (CVE-2025-3248), rotate default credentials/token secrets, pull admin DB accounts off the public internet, and vault API keys in scoped secret managers rather than plaintext.

🌊 Riding the AI Hype Wave

Stories
🗞️ Attackers Abuse OpenAI Invitations to Launch “Poisoned Tenant” Attacks (Push Security) — Fake OpenAI orgs send legitimate invites via OpenAI’s own infrastructure, inherently passing SPF/DKIM/DMARC. Accepting drops the victim into an attacker-controlled workspace that harvests every prompt; stolen cards fund it to dodge billing alerts.
🗞️ Malicious Chromium Extension Exploits AI Hype to Intercept Real-Time Search Data (Microsoft) — A Perplexity-branded MV3 extension hijacks the default search provider and exfiltrates every Omnibox keystroke to perplexity-ai[.]online via a rigged suggest_url.
🗞️ Inside “Phantom Squatting” — How Threat Actors Weaponize AI-Hallucinated Domains (Unit 42) — Adversaries map the brand-specific domains LLMs predictably hallucinate and pre-register them. Zero prior reputation = clean past blocklists; in “Montana Empire,” attackers registered the exact phantom domain an LLM predicted 23 days earlier.
🗞️ In-Browser Ransomware Emerges via LLM Offensive Code Synthesis (Check Point) — DeepSeek-linked technique runs entirely in-browser with no native payload, tricking victims (via AI image-upscaler lures) into granting folder access through the legitimate File System Access API (showDirectoryPicker()) to encrypt local data.

Recommendations
☑️ Treat trusted-platform emails as untrusted entry points: scrutinize inviter domains on SaaS/AI org alerts, and update awareness training so staff know OpenAI/GitHub/Atlassian domains can still front attacker infrastructure.
☑️ Gain SaaS visibility: deploy IdP logging, browser telemetry, or SaaS monitoring to see which external workspaces staff are joining, and watch for “LLMjacking” signals like a single key firing thousands of calls across regions.
☑️ Control the AI supply of URLs and domains: restrict execution of unverified external URLs inside AI-integrated workflows, probe LLMs to map your brand’s own “hallucination surface,” and pre-register or WHOIS-monitor high-value phantom variants.
☑️ Constrain browser file/API power: educate users to treat folder-access prompts like running an unknown binary, and gate/disable showDirectoryPicker/showOpenFilePicker for non-admin units on low-reputation domains.

👨‍💻 Developers & Researchers Under Siege

Stories
🗞️ Hijacked npm Packages Weaponize VSCode Autorun and Blockchain Dead Drops (JFrog) — html-to-gutenberg and fetch-page-assets hide executable code in a fake font file (fa-solid-400.woff2) that fires when a VS Code folder opens, pulling C2 instructions from public blockchain transactions. 🔎 Threat Hunting Package
🗞️ Trojanized Exploits Target Vulnerability Researchers with New “ChocoPoC” RAT (Sekoia) — A Python RAT hidden in backdoored PoC repos uses dependency confusion via malicious PyPI packages in requirements.txt, dropping an obfuscated payload that beacons to Mapbox for stealthy C2. 🔎 Threat Hunting Package
🗞️ Malicious CVE Exploits Target Vulnerability Researchers (YesWeHack) — The companion ChocoPoC investigation: the RAT executes automatically during pip install via obfuscated native extensions (”extension shadowing”), bypassing source-code skims to steal browser creds, session tokens, and shell histories.
🗞️ 282 iOS Apps Found Leaking LLM API Keys and Proxy Access (Wake Forest University) — Two-thirds of tested iOS AI chatbot apps leak API keys, open proxies, or replayable tokens in plaintext network traffic; three months post-disclosure only 28% patched, and some tokens were hardcoded to expire in 2125.

Recommendations
☑️ Never trust community PoC code on your primary box: detonate unfamiliar exploits only in disposable, network-isolated VMs/containers, and stop running installer requirements outside ephemeral sandboxes.
☑️ Audit the dependency and task layer: review requirements.txt/setup.py and .vscode/tasks.json for typosquatting (e.g. “frint,” “skytext”) and auto-run parameters, uninstall compromised packages, and mirror dependencies through private artifact repos.
☑️ Watch for the tell-tale behaviors: anomalous package-install activity and unauthorized outbound calls to hidden Mapbox resolvers or unknown C2, and disregard cosmetic trust signals (stars, forks, account age).
☑️ Fix client-side AI credential leakage: strip LLM API keys out of app code, route model calls through an authenticated backend, and set short token expirations with rotation plus usage-anomaly monitoring.

🕵️ Nation-State Espionage & Targeted Intrusions

Stories
🗞️ Russian Hackers Evolve Tactics to Target Signal Backup Recovery Keys (FBI/CISA) — Rather than break Signal’s encryption, UNC5792/UNC4221 exploit the human layer with a fake “security sync issue” to trick high-value targets into creating a backup and revealing the 30-digit recovery key.
🗞️ Evasive “Photo ZIP” Campaign Targets Hospitality Industry with Resilient Node.js Implant (Microsoft) — Attackers bypass filters via Calendly “authentication laundering” and deploy a Node.js implant using Run/RunOnce keys to survive disinfection and re-download payloads. 🔎 Threat Hunting Package
🗞️ Cyber Espionage Campaign Targets India’s Government and Energy Infrastructure (Acronis) — China-aligned Mustang Panda repurposes Zoho WorkDrive — a trusted platform in India’s public sector — as C2, hiding exfiltration inside routine enterprise cloud traffic. 🔎 Threat Hunting Package
🗞️ ToddyCat APT Deploys “Umbrij” Tool for Covert OAuth Token Theft via Headless Browsers (Kaspersky) — Umbrij side-loads via trusted binaries and uses a headless Chromium browser to automate consent clicks, siphoning OAuth 2.0 tokens from live Gmail/Workspace sessions (”Shadow Token via Remote Debug”) without tripping EDR. 🔎 Threat Hunting Package

Recommendations
☑️ Treat recovery keys and OAuth grants as crown jewels: guard Signal Backup Recovery Keys like a master password, and audit/revoke unverified third-party OAuth token grants in the Google Workspace admin portal.
☑️ Hunt trusted-cloud abuse as C2: trace anomalous automated data operations to Zoho WorkDrive and similar services, and tune EDR to flag unauthorized background handshakes with reputable cloud infrastructure regardless of domain reputation.
☑️ Detect the browser-debugging and side-loading tells: flag Chromium processes spawned with –remote-debugging-port, disable remote debugging/dev tools via GPO for non-developer profiles, and restrict folder write permissions to blunt DLL side-loading.
☑️ Behavior over IOCs and awareness for the human layer: build detections for the full chain (LNK → obfuscated PowerShell → csc.exe → Node.js from non-standard profiles), purge RunOnce/Run persistence fully, and train high-risk staff on in-app phishing and fake booking/image lures.

🌐 The Browser & Identity Battleground

Stories
🗞️ Deconstructing a Massive 2.6M Install Malicious Browser Extension Campaign (Microsoft) — “StegoAd” used 119 extensions to hit 2.6M users, hiding payloads in PNG icons, WebP, and WOFF2 fonts with a 3–5 day dormancy gate and DevTools detection to dodge sandboxes, harvesting Google/WordPress admin creds. 🔎 Threat Hunting Package
🗞️ Millions of Password Spray Attacks Exploit Azure CLI to Bypass MFA (Huntress) — Over 81M login attempts abused the deprecated OAuth ROPC flow via Azure CLI to hit the /token endpoint directly, bypassing MFA that was scoped to specific portals/groups rather than all cloud apps.
🗞️ Opera Pioneers Native Browser Protections with “Paste Protect” (Opera) — A default-on browser feature countering ClickFix clipboard hijacking, with Hijack protection (blocks data swapping on copy) and Injection protection (blocks rogue command-line scripts) before they reach the terminal.

Recommendations
☑️ Govern extensions tightly: audit installed extensions against known IOCs (e.g., StegoAd, Perplexity ID flkebkiofojicogddingbdmcmkpbplcd), restrict installs to verified/allow-listed publishers by group policy, and enforce least-privilege extension permissions.
☑️ Close identity blind spots: restrict Azure CLI for non-admins, enforce userStrongAuthClientAuthNRequired to block ROPC, and build unconditional Conditional Access requiring modern MFA for All Users / All Cloud Apps / All Client App types.
☑️ Kill the clipboard-to-terminal path: keep browsers on latest builds with Paste Protect on, forbid pasting web-copied text into PowerShell/Bash/CMD, and mandate FIDO2 hardware MFA to neutralize any intercepted credentials or sessions.


Feature Video

Most people trying to break into CTI think they have a skills problem. They don’t. They have a signal problem… the job market can’t see what they actually know. 👀

Here’s what separates the analysts who get hired from the ones stuck submitting application #47:

🎯 CTI is a synthesis discipline, not an entry-level one. There’s a canonical 4-tier path (SOC → Threat Hunting → CTI Analyst → Senior/Lead), and most people try to skip Tier 2 and stall out for years.

🧠 A good analyst finds the IOC. A great analyst tells you what the adversary does next. The difference between data enrichment and finished intelligence is asking, “What does this tell me about capability, intent, and second-order effects?”

📁 Your employer’s threat intel is NOT your portfolio. It’s locked behind an NDA. Build 3 public projects instead — APT TTP mapping, a Sigma/KQL threat hunting playbook, and a Python IOC enrichment script — and your CV stops being a list of jobs and starts being proof of competency.

🤝 The hard truth nobody posts about: most senior CTI roles are never publicly listed. They’re filled through referrals inside trust networks. Conferences, ISACs, and public writing matter more than 50 cold LinkedIn connection requests.

💡 One habit beats every certification combined: add a “so what” section to every report you write, translating technical findings into business impact. That’s the line between an analyst who blocks an IP and one who builds an entire detection capability around it.

Whether you’re trying to land your first CTI role or break through to a senior/lead role, this video gives you the map and the exact next steps to take.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools