Triaging the Week 127

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Theme 1: The Agentic Attack Surface (and AI as the Attacker)

Stories

🗞️ From WhatsApp Message to Host Takeover (Chinmohan Nayak) — Three high-severity flaws in the open-source OpenClaw framework let a plain WhatsApp/Slack/Teams message run arbitrary code on the host. Root cause: no separation between the natural-language layer and the execution layer, so payloads slip past variable filters and escape the sandbox — even against safety-aligned models.

🗞️ GhostCommit: Prompt Injections Hidden in Images (ASSET Research Group) — AI code reviewers treat images as benign binary blobs, but downstream multimodal coding agents read the instructions printed inside them and dump live .env secrets as raw number arrays that sail past secret scanners.

🗞️ MemGhost: Persistent False Memories in AI Assistants (WhisperBench) — A single crafted email tricks a memory-enabled agent (OpenClaw, Claude Code SDK) into writing false “facts” straight into its MEMORY.md — no password needed — and hides the action from the chat UI.

🗞️ Claude for Chrome Flaw Unlocks Silent Email Reading (Manifold Security) — The “ClaudeBleed” bug lets a low-privilege extension hijack the assistant with ~6 lines of JavaScript (no event.isTrusted check on synthetic clicks) to silently read Gmail, Docs, and Calendar. Still unpatched in v1.0.80. (Note: this appeared twice in the issue — dedupe before airing.)

🗞️ Threat Actor Migrates Live Botnet in Six Minutes with AI (Trend Micro) — “bandcampro” used Gemini CLI to architect, code, and deploy C2 infrastructure by typing plain Russian intents — doing only 11% of the work. The whole C&C op fits in 5KB of plaintext, making it trivially replicable. 🔎 Threat Hunting Package

Recommendations

☑️ Stop treating LLM safety alignment as a security boundary — enforce code-level, zero-trust sandbox isolation that separates language interpretation from execution permissions. 

☑️ Lock down agent inputs: strip exec/shell from external-facing tool allowlists, gate durable-memory writes behind explicit user confirmation, and route untrusted email/DMs through an isolated reader agent with no file, shell, or memory access. 

☑️ Patch and harden deployments now (OpenClaw ≥ 2026.6.6; disable “Act without asking” in Claude for Chrome) and rotate credentials for any agent that was publicly reachable. 

☑️ Shift detection from static access gates to runtime behavior monitoring — traditional EDR won’t log model-level compromises. Watch for PowerShell beaconing from temp dirs and anomalous agent tool use.

Theme 2: The MFA Bypass Era — Phishing, Vishing & Social Engineering

Stories

🗞️ Vishing Campaigns Target Entra Passkey Enrollment (Okta) — Operator-controlled PHP panels let attackers adapt to live MFA prompts (TOTP, push-matching, SMS OTP) over the phone and walk M365 victims through enrolling an attacker-owned passkey. Hitting food & beverage, healthcare, aviation, and more.

🗞️ AI-Powered Phishing Surge & the “Jalisco” Toolkit (ReliaQuest) — PhaaS kits like Jalisco use a real-time lure-generation API to mint fresh OAuth device codes on the fly, defeating Microsoft’s 15-minute TTL, then enroll rogue devices for a Primary Refresh Token that survives password resets. 🔎 Threat Hunting Package

🗞️ TELEPUZ MaaS Rides the “ClickFix” Trap (Elastic Security Labs) — Fake “verification” pages trick users into pasting malicious PowerShell. TELEPUZ then uses NTDLL unhooking, AMSI/ETW patching, and indirect syscalls, with a Telegram profile as fallback C2. 🔎 Threat Hunting Package

Recommendations

☑️ Push targeted awareness comms now: legit IT never calls to rush passkey enrollment on an external domain, and users must never paste PowerShell/scripts from a “verification” page. 

☑️ Constrain identity in Entra ID — block device-code auth via Conditional Access, restrict passkey and new-device registration to managed corporate networks, and audit for rogue enrollments (generic microsoft-* / WINDOWS-* device names). 

☑️ Hunt newly registered passkey-themed domains and block known TELEPUZ infra (e.g. hurgadatour[.]shop + Telegram fallbacks). 

☑️ Rebuild IR playbooks for token compromise: revoking rogue devices and active sessions is now mandatory — a password reset alone won’t evict an OAuth/PRT-based intruder.

Theme 3: Poisoned Supply Chains & Fake Repos

Stories

🗞️ Hidden Exfiltration in 900k-User “ModHeader” Chrome Extension (Stripe OLT) — A trusted, reputable extension quietly generated unique IDs, monitored browsing, and beaconed to external infra. Google pulled it July 10, but existing installs remain live. 🔎 Threat Hunting Package

🗞️ Supply Chain Attack Hits AsyncAPI NPM Packages (OX Security) — A 91,000-line dropper embedded directly in main JS files (2M+ weekly downloads) acts as an info-stealer, crypto-stealer, and RAT — using IPFS for payload storage and torrent URLs for backup C2, and self-terminating on Russian locale, VMs, or EDR.

🗞️ 290+ Fake GitHub Repos Deliver BoryptGrab Infostealer (Arctic Wolf) — Repos impersonating trusted brands use hidden redirects to spoofed download pages; a trojanized libcurl.dll side-loads and runs 11 modules to steal browser creds, wallets, and messaging tokens. 🔎 Threat Hunting Package

🗞️ OkoBot Framework Hijacks Crypto Wallets via Fake GitHub Repos (Kaspersky) — “ClickFix” + fake tools (e.g. spoofed SSMS) deploy SSH bots that disable Defender, enable RDP, replace termsrv.dll, and inject hidden malicious browser extensions. 🔎 Threat Hunting Package

Recommendations

☑️ Mandate software acquisition only from validated vendor domains — not links inside GitHub repos — and train teams to spot repos hijacking popular tool names. 

☑️ Audit and allow-list browser extensions; force-remove ModHeader everywhere and review historical logs for what it exfiltrated. 

☑️ Rotate all NPM/PyPI/Cargo tokens on suspect machines and audit recent commits for injected payloads in main JS files (this class bypasses post-install script restrictions). 

☑️ Alert on DLL side-loading from Downloads/Temp, anomalous children of utilities like gup.exe, unauthorized outbound SSH / inbound RDP, and connections to IPFS gateways or BitTorrent bootstrap nodes.

Theme 4: Stealers, Ransomware & the macOS Frontier

Stories

🗞️ Apple-Notarized “CrashStealer” Bypasses macOS Gatekeeper (Jamf) — A notarized dropper (“Werkbit Setup”) delivers a native-C++ stealer with multi-layer anti-debugging, control-flow flattening, and a dscl-based password check — harvesting browsers, wallets, and the keychain on Intel and Apple Silicon. 🔎 Threat Hunting Package

🗞️ ClickLock Stealer Forces macOS Into Lockdowns (Group-IB) — Fake ClickFix/Cloudflare pages get users to run Terminal commands; a “kill loop” repeatedly terminates Finder, Dock, and browsers for hours until the victim surrenders their password. 100+ victims across 33 countries. 🔎 Threat Hunting Package

🗞️ New “Spirals” Ransomware — Sub-24-Hour Double Extortion (Symantec & Carbon Black) — A Rust-based crew breached an internet-facing IIS server and, in under 24 hours, dumped credentials, disabled EDR, and exfiltrated data before encrypting. 🔎 Threat Hunting Package

Recommendations

☑️ Kill the “notarized/verified = safe” assumption — deploy behavioral EDR/MDM that flags post-execution recon, not just signature checks. 

☑️ Retrain users to never paste Terminal/bash commands from a website; if a Mac starts force-killing apps and demanding a password, hard shut down and boot to Safe Mode rather than entering credentials. 

☑️ Secure internet-facing servers (esp. IIS) — hunt ASP.NET web shells and rogue scheduled tasks — and enforce least privilege to blunt PsExec/WMI lateral movement. 

☑️ Enable tamper protection on Defender/EDR with instant alerts when real-time scanning is disabled, and keep isolated offline backups to defang extortion. Hunt CrashStealer IoCs (/Volumes/Werkbit Setup, dev.golove.velto, unauthorized dscl lookups).

Theme 5: Infrastructure, Privacy & Critical Patches

Stories

🗞️ Russian State Hackers Exploiting Vulnerable Routers (IC3 / joint advisory) — FSB Center 16 (“Berserk Bear”) scans for weak/default SNMP strings and exploits Cisco Smart Install to seize network devices and exfiltrate configs across energy, comms, healthcare, defense, and government.

🗞️ Is Your Free VPN Spying On You? (MVPNalyzer study) — Of 281 free Android VPNs (2.4B+ installs), 61 send data in plaintext, 29 leak traffic outside the tunnel, and 80%+ contact ad trackers — data-harvesting tools dressed up as privacy apps.

🗞️ Privacy Flaw in 85 Popular Crypto Wallet Extensions (DistriNet) — Wallets used by 35M+ people leak addresses and enable cross-site tracking by default; failing to terminate connections on “log out” lets invisible iframes link pseudonymous profiles to real identities — no hack required.

🗞️ Critical 9.8 Account-Takeover Flaw in Zoom for Windows (Zoom) — CVE-2026-53412 (CVSS 9.8): improper input validation lets an unauthenticated remote attacker take over sessions over the network; no local access or privileges needed.

Recommendations

☑️ Patch/harden infrastructure now: upgrade Zoom for Windows (Workplace ≥ 7.0.0; VDI 7.0.10 / 6.6.15 / 6.5.18), move to SNMPv3, disable Cisco Smart Install, block TFTP/SNMP at the edge, and replace end-of-life network gear. 

☑️ Cross-reference mobile fleets against the MVPNalyzer flagged list, uninstall offending free VPNs, and stop trusting “verified” badges or “no-logs” marketing over independent audits. 

☑️ For crypto users: regularly audit and revoke “Connected Sites,” use dedicated browser profiles and throwaway wallets, and push vendors to block iframe address exposure and enforce true session termination. 

☑️ Enforce phishing-resistant MFA + SSO on collaboration tools and stand up automated third-party patch management so critical fixes don’t wait on manual user action.


Feature Video

I spent years building CTI programs that impressed exactly nobody.

Dark web monitoring. Infrastructure hunting. Automation. Then AI, obviously.

All of it was fun to build. None of it moved the needle for the business.

What actually moved the needle was one boring slide for the CISO: here is our threat model, here is what we can defend against, here is what we can’t, here is the gap and what it costs to close it.

That’s the whole premise behind the CTI-CMM, the community-built maturity model for threat intelligence. It’s free, it’s on GitHub, and it doesn’t ask how many reports you published. It asks whether anyone made a different decision because of them.

This video takes a deep dive into the 11 domains, 4 levels maturity levels, and a 60-day sprint to turn your CTI program around 💪

Get started using this fantastic, community-driven model today!

✍️ Accompanying blog article

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools