Home / Companies / Stream.Security / Blog / November 2025

November 2025 Summaries

4 posts from Stream.Security

Filter
Month: Year:
Post Summaries Back to Blog
The Shai-Hulud 2.0 malware campaign, also known as "Sha1-Hulud: The Second Coming," has swiftly compromised numerous npm packages and GitHub repositories, exfiltrating sensitive data from thousands of developer environments. This self-propagating malware has backdoored over 700 npm packages and created more than 25,000 malicious GitHub repositories, impacting several prominent organizations. The attack is notable for its combination of credential harvesting, cross-victim exfiltration, and a destructive "dead-man's switch" that can wipe a user's home directory if certain conditions are not met. Stream's security platform provides real-time threat detection and analysis across various cloud and SaaS platforms, helping enterprises prepare and respond effectively to such incidents by automating detection, investigation, and response processes. The malware's methodology involves initial infection via npm preinstall scripts, credential harvesting, data exfiltration to public GitHub repositories, self-propagation using npm tokens, and the creation of a remote code execution backdoor through GitHub Actions. If the malware fails to propagate, it can execute a destructive mechanism that wipes user data, transforming the attack from espionage to sabotage. This campaign presents a significant escalation in supply-chain attacks, combining elements of ransomware and botnet infrastructure, emphasizing the need for adaptive, real-time security measures over static detection systems.
Nov 27, 2025 1,277 words in the original blog post.
Stream's red-team tests reveal that AI triage processes can be manipulated through cloud metadata injection, highlighting a new form of social engineering that targets AI systems rather than using them as tools. Attackers can inject misleading metadata, such as plausible business justifications or altered configuration tags, to trick AI into categorizing malicious activities as benign, thereby bypassing initial security defenses. This manipulation exploits the AI's reliance on structured decision-making logic and data inputs, which can be compromised through techniques like tag manipulation and social engineering. As AI becomes a standard part of security operations, it offers expanded detection coverage but inherits human-like vulnerabilities, such as susceptibility to believable context. Stream's AI Triage Agent, part of their Cloud Detection & Response offering, is designed to counteract these tactics by actively questioning metadata and ensuring decisions are based on accurate, real-time data. Stream's platform aims to reduce alert volume significantly while maintaining focus on genuine threats, thus enhancing the resilience of AI-driven security systems against evolving attack strategies.
Nov 24, 2025 1,371 words in the original blog post.
Stream has integrated its security platform with Microsoft 365 to enhance threat detection across various services such as Entra ID, DLP, SharePoint, Teams, Outlook, and OneDrive, providing real-time visibility into identity, chat, files, and mail to detect issues like token abuse and malicious OAuth apps. This integration is crucial as Microsoft 365, powering modern work environments, is increasingly targeted by attackers exploiting its interconnected ecosystem. Notable campaigns, such as those by Storm-1811 and Octo Tempest, have demonstrated how attackers use simple techniques like Teams chats to facilitate ransomware attacks. Traditional detection methods struggle to keep up, necessitating a cross-service, identity-aware approach that Stream now offers by integrating with Microsoft 365 Audit Logs. This integration includes behavior-driven detection, threat intelligence enrichment, and pre-built detection rules to identify and mitigate threats more effectively. The AI-powered triage and investigation feature further enhances security by correlating signals across multiple services and reducing noise, enabling faster, more confident threat response. Stream's solution aims to close visibility gaps in Microsoft 365, ensuring that collaboration doesn't compromise security.
Nov 10, 2025 506 words in the original blog post.
AI Security Operations Center (SOC) agents are gaining attention for their potential to help security teams manage the overwhelming volume of alerts, especially in cloud environments, by automating tasks like alert triage and investigation enrichment using AI and large language models (LLMs). These agents are designed to augment rather than replace human analysts, offering speed in processing alerts and recommending actions. However, the effectiveness of AI SOC tools heavily depends on the quality and connectivity of the data they use, as fragmented or incomplete data can lead to incorrect inferences. The challenge is exacerbated in cloud environments, where visibility is spread across various layers and formats, making it difficult for AI to fully understand the context and impact of alerts. The article suggests that for AI SOC tools to truly enhance security operations, a reliable and integrated data foundation is essential, enabling not just faster but more accurate decision-making. The series promises to further explore how improved data visibility can enhance AI's role in security operations.
Nov 03, 2025 600 words in the original blog post.