Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Theme 1: Identity Under Siege — Device Code Phishing, Vishing & MFA Bypass
Stories
🗞️ Inside the ARToken Phishing Panel Targeting Microsoft 365 (Cisco Talos) — A PhaaS panel that weaponizes Microsoft’s own OAuth 2.0 Device Authorization Grant to bypass MFA entirely, hidden behind a seven-layer client-side anti-analysis engine that blinds scanners and sandboxes. 🔎 Threat Hunting Package
🗞️ Sponsored Hackers Weaponize Microsoft Device Code Flow Using GraphSpy (ZeroBEC) — Russian state actor Storm-2372 captures tokens through the legitimate Microsoft login page, then uses GraphSpy to map infrastructure, register rogue devices, and inject backup MFA methods — no fake domains needed. 🔎 Threat Hunting Package
🗞️ Helix Data Extortion Group Bypasses MFA via Vishing and Device Code Phishing (ReliaQuest) — Helix spoofs a victim’s direct manager over the phone to trick them into authorizing a device code, captures the session token, and exfiltrates SharePoint data to fuel ransom demands. 🔎 Threat Hunting Package
🗞️ Sophisticated Phishing Kits Impersonate Big Brands to Hijack Google Ecosystems (Will Thomas) — Recruitment-themed “Google Careers” kits use HTML-splitting — breaking “Google” into individual <label> tags — plus a spoofed Turnstile and dynamic C2 to evade signature detection and steal Workspace credentials. 🔎 Threat Hunting Package
🗞️ Fake IT Support Campaign Abuses Microsoft Teams to Deploy EtherRAT (Palo Alto Unit 42) — Attackers impersonate IT support via Teams vishing to deploy EtherRAT, which pulls live C2 addresses from Ethereum smart contracts — making its infrastructure highly resilient and hard to disrupt. 🔎 Threat Hunting Package
Recommendations
☑️ Block or disable the Device Code Flow (deviceCode) in Microsoft Entra ID via Conditional Access, allowing narrow audited exceptions only for input-constrained systems like meeting-room devices.
☑️ Migrate to phishing-resistant MFA (FIDO2 keys / Authenticator passkeys) with Conditional Access enforcing managed-device compliance and automated token revocation on high-risk signals.
☑️ Hunt in your SIEM / Sentinel for device-code and auth anomalies — IP mismatches across auth legs, logins from residential proxy pools, and post-compromise bulk Graph API mailbox reads or new inbox-forwarding rules.
☑️ Restrict external Microsoft Teams interactions, train staff to distrust “External and unknown” callers, and require independent verification of any IT-support request before granting screen share or installing software.
☑️ Harden email defenses with text-normalization / OCR to defeat HTML-splitting, and block or alert on newly registered lookalike hiring and vendor domains.
☑️ Block execution of unauthorized RMM tools (HopToDesk, AnyDesk) and silent Node.js installs via curl.exe associated with EtherRAT.
Theme 2: AI Coding Agents Under Attack
Stories
🗞️ The SKILLCLOAK Technique and the Looming Threat to AI Coding Agents (HKUST) — Malicious “skills” for AI coding assistants evade static scanners over 90% of the time by hiding self-extracting payloads in ignored directories (.git/, build/) that unpack at runtime into the agent’s privileged terminal.
🗞️ GitLost Vulnerability Exposes Private GitHub Repositories via AI Agents (Noma) — An indirect prompt injection in GitHub Agentic Workflows lets an unauthenticated attacker leak private-repo data via a crafted public issue; the single keyword “Additionally” was enough to bypass built-in guardrails.
🗞️ GitHub Copilot Generates Banned Malicious Content via Code Workflow Exploits (Kumar & Maple) — “Workflow-level jailbreaks” exploit an agent’s drive to complete tasks, hitting a 100% success rate across 816 runs to silently write malicious payloads into source files without ever tripping chat-level refusals.
🗞️ How a Simple Symlink Exploit Tricks AI Coding Assistants Into Overwriting Sensitive System Files (Wiz) — “GhostApproval” abuses the human-in-the-loop model: a benign filename shown for approval hides a malicious symlink that redirects the write to critical host files.
🗞️ Hijacking Defensive AI Agents for Remote Code Execution (AI Now Institute) — Prompt injections embedded in third-party repos trick autonomous agents (Claude Code, Codex) into executing obfuscated binaries under the guise of a security review — no plugins or special config required.
Recommendations
☑️ Kill autonomous execution — disable auto-mode / auto-review and enforce human-in-the-loop authorization for every shell command and file write an agent generates.
☑️ Sandbox all agentic work — run codebase analysis and supply-chain audits in disposable containers / VMs (DevContainers) with no access to host files, saved credentials, or elevated terminals.
☑️ Treat the context window as an active attack surface — sanitize and isolate user-generated content from system instructions, and model prompt injection as a systemic, SQLi-class risk rather than trusting model guardrails.
☑️ Shift from static / signature scanning to runtime behavioral monitoring — watch for high-entropy blobs in ignored folders, abnormal file padding, symlink anomalies, and startup network pulls.
☑️ Mandate independent human review plus SAST on all AI-generated source regardless of whether the chat panel looked compliant, and tightly scope agent permissions (no broad cross-repo access, no posting to public untrusted threads).
Theme 3: Supply Chain & the Developer Ecosystem
Stories
🗞️ North Korea-Linked ‘PolinRider’ Campaign Spreads Across Open-Source Repositories (Socket) — The DPRK PolinRider campaign expands from npm into Go, Packagist, and Chrome extensions, using Git history rewriting (force pushes, anti-dated commits) and .vscode/tasks.json “folderOpen” triggers to auto-run hidden loaders.
🗞️ npm v12 Disables Automatic Install Scripts by Default (GitHub) — npm shifts from “trust by default” to explicit approval, blocking implicit preinstall/install/postinstall hooks, remote URLs, and node-gyp triggers, and deprecating 2FA-bypassing tokens.
🗞️ Blunting the Edge of Coordinated GitHub API Enumeration (Datadog) — Attackers spread GitHub API enumeration across residential proxies to stay under volume-based rate limits while scraping repos and hunting secrets; detection has to pivot to behavioral correlation.
Recommendations
☑️ Audit repos and dev workstations for supply-chain tradecraft — VS Code tasks with “runOn”: “folderOpen”, Node.js executing static assets like .woff2, force-pushes / anti-dated commits, and synchronized batch changes across unrelated repos.
☑️ Update to npm 11.16.0+ / v12, run npm approve-scripts to allowlist only trusted native-compilation packages, commit the results so headless CI/CD doesn’t break, and retire Granular Access Tokens before the August 2026 deadline.
☑️ Enforce phishing-resistant MFA for all maintainers and rotate any exposed secrets from a clean host if an affected package version was ever installed.
☑️ Ingest GitHub Audit Logs (repo.access, oauth_application, token-generation events) into a SIEM and correlate distributed anomalies — synchronized queries, uniform User-Agents, rapid token use.
☑️ Enforce secret scanning and strict least-privilege on OAuth apps and PATs, with fine-grained scopes and short expiration windows.
Theme 4: Residential Proxies, Botnets & ORB Networks
Stories
🗞️ Google, FBI, and Partners Dismantle 2-Million-Device NetNut Proxy Botnet (Google GTIG) — A 2-million-node residential proxy botnet, grown by embedding proxy SDKs in consumer software and linking with Badbox 2.0, ran a white-label reseller program quietly fueling other proxy brands across the underground economy.
🗞️ The Massive Malicious Scheme Turning Everyday Devices into Proxy Ware (Infoblox) — “Lurking Lizard” uses 230+ lookalike domains and “drop-catching” of long-misquoted domains (e.g. 7zip[.]com) to push trojanized installers that silently enroll victims as residential proxy exit nodes.
🗞️ UAT-7810 Rapidly Expanding ORB Networks with New Custom Malware Arsenal (Cisco Talos) — China-nexus UAT-7810 deploys LONGLEASH / DOGLEASH / JARLEASH on unpatched Ruckus and ASUS edge routers to build ORB relay infrastructure leased to other state-sponsored actors. 🔎 Threat Hunting Package
Recommendations
☑️ Stop relying on IP reputation — move to Zero Trust / Conditional Access keyed on device-health certificates and continuous session evaluation, and flag distributed low-and-slow logins masked behind domestic ISP networks.
☑️ Deploy Protective DNS and application allowlisting to block typosquatting / drop-caught installer domains and prevent execution of unvetted installers; alert on outbound proxyware or tunneling traffic patterns.
☑️ Educate remote staff against “get paid to share your bandwidth / unused data” apps — a primary route to becoming a proxy exit node.
☑️ Patch edge gear now — Ruckus (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS (CVE-2025-2492) — deploy the Talos SNORT / ClamAV signatures, block listed C2 IPs, and monitor edge / IoT devices for unknown tunnels, open ports, and rogue shell scripts.
Theme 5: Critical Vulnerabilities — Patch Now
Stories
🗞️ 16-Year-Old ‘Januscape’ Flaw Enables Universal Guest-to-Host VM Escapes (Hyunwoo Kim) — CVE-2026-53359, a use-after-free in Linux KVM’s legacy shadow MMU emulation code, allows guest-to-host escape and root-level code execution on Intel and AMD x86 platforms.
🗞️ Ubiquiti Issues Urgent Patch for Max-Severity UniFi OS Flaw (Ubiquiti) — CVE-2026-50746 (CVSS 10.0) enables command injection via the UniFi Connect app; 100,000+ internet-facing UniFi OS instances are exposed, with six more low-complexity, zero-interaction flaws also disclosed.
🗞️ How Browser Personalization Opened the Door to Zero-Click Universal XSLeaks and DoS (zhero_web_security) — An Opera GX mod-framework flaw auto-installs configs when a user simply visits a malicious site, enabling zero-click DoS and universal CSS-injection data harvesting with no JavaScript.
Recommendations
☑️ Patch immediately — deploy the fixed Linux kernel for CVE-2026-53359, update UniFi Connect to 3.4.20+ and UniFi OS to 5.1.19+, and force Opera / Opera GX to the latest vendor build.
☑️ Reduce exposure — remove UniFi management interfaces from public internet visibility via firewall rules and segmentation, and isolate high-risk / multi-tenant KVM guests using hardened micro-VMs, moving off legacy shadow paging where hardware-assisted virtualization is available.
☑️ Watch for exploitation — unexplained host-kernel crashes or hypervisor restarts (Januscape), and anomalous browser behavior like .crx downloads from static iframes or non-JavaScript exfiltration (Opera GX).
☑️ Enforce centralized browser management to block unauthorized add-ons and automatic layout/theme modifications.
Feature Livestream
Most MISP deployments never make it past “it works on my laptop.”
❌ The problem: people set it up once, it’s fragile, and nobody trusts it enough to put real data through it.
Part 6 of our MISP series is the fix — we build a production-ready MISP on AWS using Kubernetes (EKS), the same way you’d actually want it running at your org.
What’s inside this episode:
🔧 Terraform — so the infrastructure is repeatable and version-controlled, not a pile of manual clicks
☸️ AWS EKS — MISP running properly on Kubernetes, not duct-taped to a single VM
☁️ The supporting AWS services that separate “demo” from “production”
Whether this is your first MISP deployment or you’re already running one and want to see what’s actually happening under the hood — this episode is built for you!
🔗 Check out our MISP production readiness checklist and deployment code here.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development.
- TCM Academy: A comprehensive suite of courses with a hands-on, practical approach to training that equips students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your own custom cyber threat intelligence web-scraping tool!



