<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Vulnerable U</title>
    <description>Infosec&#39;s favorite weekly newsletter for news, tools, and tips with 34,000+ CISOs, founders, change-makers, and straight up hackers.</description>
    
    <link>https://www.vulnu.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/lSfumbrEGk.xml" rel="self"/>
    
    <lastBuildDate>Mon, 20 Jul 2026 03:32:54 +0000</lastBuildDate>
    <pubDate>Fri, 17 Jul 2026 12:43:00 +0000</pubDate>
    <atom:published>2026-07-17T12:43:00Z</atom:published>
    <atom:updated>2026-07-20T03:32:54Z</atom:updated>
    
      <category>Mental Health</category>
      <category>News</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, Vulnerable U</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/71c1f7f0-15e9-4f22-932a-e61c0932a9e2/Newsletter_Thumbnail_2026_Bunny_Only.png</url>
      <title>Vulnerable U</title>
      <link>https://www.vulnu.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>🎓️ Vulnerable U | #177</title>
  <description>Record breaking patch tuesday, AI 0days, Hacker perp walks, job interviews that get you hacked, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-177</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-177</guid>
  <pubDate>Fri, 17 Jul 2026 12:43:00 +0000</pubDate>
  <atom:published>2026-07-17T12:43:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>5 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e986518e-4995-461b-8d7e-319104bd16de/Newsletter_Header.png?t=1784218552"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">It was one of those weeks that I think it would be easier to count the amount of hours I wasn’t on camera yapping. Recorded an absurd amount of content. Felt good to be back in studio in between a bunch of traveling banging it all out though!</p><p class="paragraph" style="text-align:left;">Really excited about how the new podcast with Low Level is shaping out. We’ll be putting these out weekly so make sure to subscribe to either the new YouTube channel or wherever you listen to podcasts. (<a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Apple</a>, <a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?si=f5f6ac02a4834a1b&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Spotify</a>, etc.)</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/iAfUQdKoTsU" width="100%"></iframe><p class="paragraph" style="text-align:left;">And as always a special shoutout to <a class="link" href="https://mazehq.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Maze</a> who not only is doing awesome things in AI Security land, they also must be geniuses since they wanted to be our Launch partner on The Low Down.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Just opt out of us siphoning all of your data out of your home directory to our cloud storage! <a class="link" href="https://x.com/mattjay/status/2076713394766275028?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Honestly it’s your fault.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This <a class="link" href="https://www.youtube.com/watch?v=F8tRi1RYf7c&t=5s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">awesome panel</a> we did at PlanetScale HQ</p><p class="paragraph" style="text-align:left;">🎤 Something I said: How I cooked <a class="link" href="https://www.youtube.com/watch?v=D7prSk5wsy0&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">prompt injection</a> with this open source tool</p><p class="paragraph" style="text-align:left;">🔖 Something I read: This great interview between <a class="link" href="https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Kim Zetter and Allison Nixon</a> on tracking The Com (Scattered Spider) - and did you see the <a class="link" href="https://x.com/NCA_UK/status/2077728550505922936?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">perp walk?</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="microsoft-patches-a-record-570-secu"><a class="link" href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches a Record 570 Security Flaws</a></h3><p class="paragraph" style="text-align:left;">570 patches in a single Patch Tuesday. Welcome to Mythos baby!!! Microsoft is, of course, attributing exploding patch number to AI-assisted vulnerability discovery. The most pressing items this month are three zero-days, two of which are already being exploited in the wild, both allowing privilege escalation. There&#39;s also a fun 9.6 CVSS RCE in Microsoft Copilot that lets attackers execute code via a malicious website that tricks Edge on Android into sending crafted prompts.<br><br>Microsoft&#39;s exploitability index is basically becoming useless in an AI world. Anthropic&#39;s Mythos model was able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that Microsoft had rated &quot;Exploitation Less Likely.&quot; The SharePoint zero-day this month was rated the same way before showing up on CISA&#39;s KEV list. Adobe is moving to twice-monthly patches, and Google pushed over 900 fixes in June alone. Patch management is having its DevOps moment, gotta do more and more faster! (<a class="link" href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"></p><h3 class="heading" style="text-align:left;" id="are-pentests-obsolete-in-the-ai-era"><a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Are pentests obsolete in the AI era?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d5d04c20-ad4e-4fb8-871b-344e958c424c/Vuln_U_x_Intruder_July_2026.png?t=1784132905"/></div><p class="paragraph" style="text-align:left;">AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.</p><p class="paragraph" style="text-align:left;">This <a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Intruder blog </a>explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (<a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="contagious-interview-infostealer-ca"><a class="link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Contagious Interview Infostealer Campaign Continues Targeting Developers</a></h3><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/y3cVL78-9HE?si=-tdWEeYhOMSncETM&start=1608" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><div class="image"><a class="image__link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e69a9466-9d85-4bcc-902d-a7dd711a73f3/Screenshot_2026-07-15_at_7.41.23_PM.png?t=1784158889"/></a><div class="image__source"><a class="image__source_link" href="https://gist.github.com/soolidsnake/9e937530a49bc51a5e2e56d86137561b?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" rel="noopener" target="_blank"><span class="image__source_text"><p><a class="link" href="https://gist.github.com/soolidsnake/9e937530a49bc51a5e2e56d86137561b?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Full thread here.</a></p></span></a></div></div><p class="paragraph" style="text-align:left;">Love when people who get popped are super transparent about their experience so we all get a chance to learn from it. This blockchain dev got a recruiting message on LinkedIn. They even said they were expecting a suspicious link or some malware that never came. They got all the way to the interview, it all felt super legit, and then the team asked them to clone a GitHub repo to work on a coding assessment live on the call. Doing what anyone would do during a job interview, they got to work - but the github repo contained malware heading in an auth.js file a few folders deep. By the time the victim knew what happened, a bunch of their crypto wallets were drained.</p><p class="paragraph" style="text-align:left;">This campaign has been very prevalent and successful out of North Korea. They specifically target blockchain/crypto/web3 devs as it fits SUPER nicely in with their lure to get code on their machine for a technical interview. They are also a perfect target because since North Korea is basically sanctioned out of the western economy they fund much of their government efforts with stolen crypto. Billions per year. (read more <a class="link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="legacy-hive-bone-shattering-zero-da"><a class="link" href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>LegacyHive: “Bone-Shattering” Zero-Day from Microsoft&#39;s Serial Tormentor Not the Haymaker That Was Promised</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/071e4cb8-db0e-4f96-af59-74200156967e/Screenshot_2026-07-16_at_6.57.02_PM.png?t=1784246242"/></div><p class="paragraph" style="text-align:left;">The day Nightmare Eclipse promised finally arrived. If you&#39;ve been following the saga, Nightmare Eclipse is the security researcher who&#39;s been carrying out a very public feud with Microsoft over what they describe as a broken vulnerability disclosure process. Back in June, the researcher hinted that July 14 would be significant, and sure enough, a new zero-day dubbed &quot;LegacyHive&quot; landed on GitHub. </p><p class="paragraph" style="text-align:left;">It&#39;s a local privilege escalation in the Windows User Profile Service that lets a regular user mount and get read-write access to other users&#39; registry hives, including admins. Useful post-compromise tool, but experts are calling out the gap between the &quot;bone-shattering&quot; hype and what the released PoC actually delivers.</p><p class="paragraph" style="text-align:left;">Interestingly, NightmareEclipse stripped back the public PoC this time around - likely due to Microsoft&#39;s legal threats - requiring additional credentials and limiting it to the usrclass.dat hive. The full version apparently doesn&#39;t have those limitations, but you&#39;d need to do some work to get there. Given that previous drops like BlueHammer and RedSun went from PoC to active ransomware exploitation within days, security teams shouldn&#39;t treat the incomplete PoC as a reason to relax. No patch yet, no CVE, and Microsoft just shipped 622 fixes this month so don&#39;t hold your breath for an out-of-band fix. (<a class="link" href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="telegrams-shortlink-domain-is-back-"><a class="link" href="https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-after-day-long-suspension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Telegram’s shortlink domain is back online after day-long suspension</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/221f5892-3d54-4646-b4e7-8c43ff3de181/Screenshot_2026-07-16_at_7.03.19_PM.png?t=1784246604"/></div><p class="paragraph" style="text-align:left;">Telegram had a rough Monday when their t[.]me shortlink domain went dark, and the reason turned out to be a pretty embarrassing clerical blunder. The Montenegro-based registrar DomainME accidentally suspended Telegram&#39;s entire t[.]me domain while trying to comply with new OFAC sanctions - the sanctions that were actually targeting a VPN provider called First VPN. The problem? The Treasury&#39;s sanctions listing for First VPN happened to contain a t[.]me link to the VPN&#39;s Telegram group, and rather than just blocking that specific URL, DomainME nuked the whole domain to stay on the right side of U.S. sanctions law. (<a class="link" href="https://home.treasury.gov/news/press-releases/sb0559?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grok-build-uploaded-entire-git-repo"><a class="link" href="https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read</b></a></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DavT8sQNTXM/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><p class="paragraph" style="text-align:left;">If you&#39;ve been using xAI&#39;s Grok Build coding CLI, it&#39;s time to rotate your credentials. A researcher found that Grok Build was uploading entire Git repositories - full commit history included - to an xAI-controlled Google Cloud Storage bucket. Some examples showed a 27,800x gap between what the model actually needed and what left the machine. Turning off &quot;Improve the model&quot; in settings did absolutely nothing to stop the uploads - that toggle only governs training data, not what actually hits the wire.</p><p class="paragraph" style="text-align:left;">Any file Grok read during a task, including .env files, went out unredacted. And since full commit history was bundled up, that includes secrets you committed and deleted ages ago. xAI quietly flipped a server-side switch to stop the uploads on July 13th and Elon promised everything would be &quot;completely and utterly deleted,&quot; but they still haven&#39;t explained why full repos were being uploaded by default, for how long, or how many users were affected. The upload code is still sitting in the latest binary, just held back by a server flag. Rotate anything that could have touched this tool. If you were running this in a corporate environment, this is a data residency and regulatory nightmare. (<a class="link" href="https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="cursor-0-day-when-full-disclosure-b"><a class="link" href="https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Cursor 0day: When Full Disclosure Becomes the Only Protection Left</a></h3><p class="paragraph" style="text-align:left;">This isn’t the craziest vuln, but it is worth talking about this story because I trust the author is legit and this disclosure process is not alright for a company of their size and reputation. Mindgard dropped a full disclosure on Cursor today after seven months of trying to get the AI code editor to patch a painfully simple vulnerability. The bug itself is almost embarrassingly basic - drop a malicious git.exe in your repo root, and Cursor will execute it automatically when someone opens the project. No clicks or prompts. It just runs. The proof of concept was literally just Windows Calculator renamed to git.exe popping up over and over.</p><p class="paragraph" style="text-align:left;">Mindgard did everything right - responsible disclosure, HackerOne, direct CISO outreach - and got ghosted for seven months while Cursor shipped 197+ new versions. If you&#39;re running Cursor on Windows, either sandbox your untrusted repos or have your admins set up AppLocker rules blocking execution from workspace directories until a patch drops. This one&#39;s worth paying attention to given how much access these AI IDEs have to your code, credentials, and environment. (<a class="link" href="https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="last-pass-bitwarden-users-targeted-"><a class="link" href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>LastPass, Bitwarden Users Targeted With Fake Security Alerts</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/072a9e00-a0a8-460e-950c-040fcb6fe57c/image.png?t=1784247244"/></div><p class="paragraph" style="text-align:left;">One thing I always like putting in the newsletter is phishing campaigns like this because they are active and a good pulse on what to look out for. In this case, LastPass and Bitwarden weren&#39;t compromised at all. The attackers simply registered domains that looked legitimate and sent convincing emails warning users about, of all things, ongoing phishing campaigns and recent security incidents. The phishing email is literally warning you about phishing. It talks about enhanced security measures, updated policies, and protecting your account. Then it adds a little urgency: you have 14 business days to review and accept new terms or risk losing access to your account. &quot;We&#39;re here to protect you, but you need to act right now.&quot;</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59b4a71a-2166-4352-9792-f885f265c4d6/image.png?t=1784247253"/></div><p class="paragraph" style="text-align:left;">The design is clean. The spelling and grammar are solid. The domains are convincing. Clicking the link takes victims to a DocuSign clone hosted on domains like &quot;lastpasscompliance[.]com,&quot; complete with a chatbot and realistic branding. Eventually you get prompted to download software, which is where the malware comes in and the divergence from anything resembling real DocuSign happens. Those of us in security immediately see the red flags: urgency, account restrictions, DocuSign requests, software downloads. But for a normal user, nothing really screams &quot;fake&quot; here. Guards up! (<a class="link" href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="white-house-details-gold-eagle-clea"><a class="link" href="https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">White House details ‘Gold Eagle’ clearinghouse for AI cyber threats</a></h3><p class="paragraph" style="text-align:left;">The White House has put some meat on the bones of last month&#39;s AI executive order, unveiling &quot;Gold Eagle&quot; - a new federal clearinghouse for sharing AI-discovered cyber threat intelligence between government and private sector. Treasury&#39;s running point on this one, with CISA, DHS, and DoD all contributing. The idea is straightforward enough - use AI to find vulnerabilities before the bad guys do, then coordinate patching across government and critical infrastructure. They&#39;ve even built a new platform called VINTS (Vulnerability Information and Coordination Environment) with Carnegie Mellon&#39;s Software Engineering Institute to receive and prioritize those reports, and apparently it&#39;s already collecting intel.</p><p class="paragraph" style="text-align:left;">They&#39;re specifically planning to use frontier models including Anthropic&#39;s Mythos for vulnerability discovery. Which I find funny as they’ve also recently deemed Anthropic a supply chain risk and banned the government from using it, and then also a risk worthy of an export control to now allow the general public to use Mythos either. I also don’t get why gut CISA as much as we have and then recreate this program and hand it to the Treasury, but I’ll let more .gov wonks explain that one.</p><p class="paragraph" style="text-align:left;">I’m not confident in anything this admin puts forward, so I’d look closer to Glasswing or the “Patch the Planet” initiative out of OpenAI/Trail of Bits to be more successful that whatever the hell this is. Even the press release reads like a political rally, which is signal to me that this is more sizzle than steak. (<a class="link" href="https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="us-unseals-indictment-against-alleg"><a class="link" href="https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">US unseals indictment against alleged operators of Russian bulletproof hosting service</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6da255b9-ee66-4133-a684-8e6d64184511/image.png?t=1784249541"/></div><p class="paragraph" style="text-align:left;">The DOJ just unsealed an indictment against three Russians running Media Land, a St. Petersburg-based bulletproof hosting shop that was essentially a one-stop-infrastructure provider for some heavy hitter hackers. LockBit, BlackSuit, Play ransomware groups, plus a laundry list of stolen credit card marketplaces like BriansClub and Bidencash. The three defendants - Volosovik, Pankova, and Zatolokin - are looking at charges covering computer fraud, wire fraud, and money laundering, with 44 victims and $62 million in documented losses tied to their operation.</p><p class="paragraph" style="text-align:left;">The indictment itself was actually filed back in December 2024, so this unsealing feels more like a public pressure move than an imminent arrest situation - these folks are in St. Petersburg with no extradition possible. The $10 million Rewards for Justice bounty is interesting though, specifically asking for info on foreign government links to their operations. (<a class="link" href="https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/db673283-9f3a-4d1b-acb7-a02bb72448ec/image.png?t=1784252688"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5a471921-3763-4010-863b-9b0d3294a199/Screenshot_2026-07-16_at_8.45.31_PM.png?t=1784252745"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ec58ff6b-3fcd-4f46-8b6d-d13e6cc35b80/Screenshot_2026-07-16_at_8.47.53_PM.png?t=1784252883"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #176</title>
  <description>Microsoft ID used to track hackers in court case, Vidar infostealer intel breakdown, Zero days to watch out for, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-176</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-176</guid>
  <pubDate>Fri, 10 Jul 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-07-10T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>10 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0f6d1d40-6bc8-4dc2-905b-74589b3846df/Newsletter_Header.png?t=1783537908"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/00e18321-b9d7-4797-8a33-050a4581b45b/Newsletter_Sponsor_Logo.png?t=1783538131"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">The BlackHat and DEFCON calendar invites have begun. I’m sure there won’t be 7 things I try to show up in the same 3 hour block on Tuesday. Who’s all going? Should I get the cabana by the pool again for us to do a meetup?</p><p class="paragraph" style="text-align:left;">Did you see my big announcement this week? Me and <a class="link" href="https://www.youtube.com/@LowLevelTV?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Low Level</a> started a podcast. We’ll be shipping weekly episodes and occasional guest interviews. We do film it for YouTube but you can find it on all your favorite podcast apps.</p><p class="paragraph" style="text-align:left;">Check it out! Subscribe to help us get it off the ground on the new channels.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/@lowdownpod?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">YouTube</a><br><a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Spotify</a><br><a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Apple</a></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d8a4eb1-88b3-4eb2-9b3e-b06f75daf420/The_Low_Down_Logo__1_.png?t=1783635055"/></div><p class="paragraph" style="text-align:left;">Thanks Maze for being an awesome launch partner on this new venture. 🤘 </p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=5pgvSbh8L_0&t=27s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">The Low Down!</a> We recorded this one at PlanetScale HQ out in SF where we were hosting a panel.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: I <a class="link" href="https://www.youtube.com/watch?v=CqKxGBNbCPU&t=1s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">interviewed HD Moore</a> about how hacking feels like its in the 90s again thanks to AI.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Early signs of <a class="link" href="https://www.linkedin.com/posts/irregular-com_we-ran-preliminary-evaluations-of-glm-52-activity-7478448392139010048-YyBG/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABZnM8BKlIB11WOhwpTnKR2wSH7AzwPTpg" target="_blank" rel="noopener noreferrer nofollow">frontier cyber capabilities</a> in Open-Weight models</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="alleged-member-of-criminal-cyber-ha"><a class="link" href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to United States</a></h3><p class="paragraph" style="text-align:left;">One of the more interesting debates that came out of the recent Scattered Spider arrest wasn&#39;t actually about the alleged cybercrime itself. It was about how the suspect got caught. A lot of people latched onto the court documents discussing Microsoft&#39;s GDID identifier and immediately jumped to the conclusion that Microsoft has some secret tracking mechanism baked into Windows. </p><div class="image"><a class="image__link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2130b43-b543-4897-9f51-b57e8dfbd9b1/Screenshot_2026-07-08_at_1.48.21_PM.png?t=1783542284"/></a><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Click here for full court document</a></p></span></div></div><p class="paragraph" style="text-align:left;">But when digging into what security researchers were saying, the reaction was almost the opposite. Several people who spend their lives tracking threat actors were basically saying, &quot;Wait, you&#39;re surprised by this?&quot; One of the strongest reactions came from Allison Nixon, who has spent years helping identify and track cybercriminal groups. Her argument: anonymity isn&#39;t something you have. It&#39;s something you maintain until you don&#39;t.</p><div class="image"><a class="image__link" href="https://www.linkedin.com/feed/update/urn:li:activity:7479987731037569024/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fdc57479-67d0-4cf6-8932-69cc4b45a5ac/Screenshot_2026-07-08_at_1.42.04_PM.png?t=1783542544"/></a></div><p class="paragraph" style="text-align:left;">Nixon&#39;s comments were honestly some of the most fire takes I&#39;ve seen on this story. She pointed out that the suspect allegedly sent her death threats years ago, which immediately put him on her radar. From there, she did what she does: shared intelligence with providers, incident responders, security teams, and investigators. Her broader point was that threat actors often have a completely unrealistic view of anonymity. They think they&#39;re invisible because they use a VPN, a burner account, or some OPSEC tricks. Meanwhile, the people tracking them are collecting evidence, building profiles, connecting dots, and watching patterns over the course of years. As she put it, saying you&#39;re anonymous is like saying you&#39;ve won a marathon you haven&#39;t finished. The game doesn&#39;t end until your opponents either lose interest or catch you.</p><div class="image"><a class="image__link" href="https://x.com/vxunderground/status/2073427396535963967?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6fd0afe6-1e35-42e1-b8ac-457acbede3d3/Screenshot_2026-07-08_at_1.36.14_PM.png?t=1783542661"/></a><div class="image__source"><span class="image__source_text"><p>From my live stream here: <a class="link" href="https://www.youtube.com/live/5QmVWzh3JUs?si=h0SlCGJ8ERx08E3d&t=6260&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">https://www.youtube.com/live/5QmVWzh3JUs?si=h0SlCGJ8ERx08E3d&t=6260</a></p></span></div></div><p class="paragraph" style="text-align:left;">The technical details around the GDID itself turned out to be less dramatic than some headlines suggested. Researchers such as Massgrave pointed out that the identifier is closely related to Microsoft&#39;s long-documented Passport User ID system. In other words, this wasn&#39;t some secret spyware identifier that suddenly surfaced. It was part of the ecosystem Microsoft uses to tie together accounts, devices, activation services, and telemetry. The browsing-history angle that got everyone excited also appears to have involved optional Microsoft Edge telemetry rather than some universal logging feature affecting every Windows user. The bigger story isn&#39;t that Microsoft can identify a device, but how many different systems, services, accounts, and telemetry sources can be correlated once investigators start looking. (read more <a class="link" href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7479987731037569024/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://x.com/vxunderground/status/2073427396535963967?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="new-ctf-alert-help-pixel-stop-the-b"><a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">New CTF Alert: Help Pixel Stop the Breach at the Beach!</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/096f7040-dc18-4d64-8bd6-5f08e080c713/Blog_VTL-BreachattheBeach_202606_FNL.png?t=1783614720"/></div><p class="paragraph" style="text-align:left;">Looking for a fast, free way to level up your resume and data security skills? </p><p class="paragraph" style="text-align:left;">Varonis Threat Labs created <a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Breach at the Beach</a>, a new CTF that drops you into a live identity breach unfolding across Entra ID and M365. As the storm rolls in, you help Pixel the cat trace an AI threat actor who is quietly abusing legitimate features to move through the environment. You&#39;ll dig through real logs and audit trails to track them down the same way threat hunters do in the field, so you can save the day and bring the sunshine back. </p><p class="paragraph" style="text-align:left;">The best part? It&#39;s free to play, browser-based, and each stage you complete earns you a CPE credit. Finish all four stages by August 6 for a shot at a $2,000 Marriott Gift Card. </p><p class="paragraph" style="text-align:left;">Pixel&#39;s counting on you. Grab your sunglasses and <b><a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">play now</a></b>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="footage-shows-cop-stalking-woman-he"><a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Footage Shows Cop Stalking Woman He Met on a TV Set After Surveilling Her With a License Plate Reader</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/86f0332b-7a3a-4429-a39b-12fc34899669/Screenshot_2026-07-08_at_12.22.32_PM.png?t=1783543378"/><div class="image__source"><span class="image__source_text"><p>from my live stream here: <a class="link" href="https://www.youtube.com/live/5QmVWzh3JUs?si=7FRqGGnOIKjq4YLh&t=1872&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">https://www.youtube.com/live/5QmVWzh3JUs?si=7FRqGGnOIKjq4YLh&t=1872</a></p></span></div></div><p class="paragraph" style="text-align:left;">I had to cover this one because it&#39;s such a perfect example of the privacy and surveillance conversations we keep having in cybersecurity. A Florida police officer is under investigation after allegedly using law enforcement databases and AI-powered license plate reader systems to stalk a woman he met while working security on the set of the Apple TV+ show <i>Bad Monkey</i>. According to reporting from 404 Media, he spent weeks harassing her, asking for her name and Instagram information, then used Florida&#39;s law-enforcement-only DMV database, called DAVID, to pull her vehicle information. From there, he allegedly added her license plate to a surveillance hot list so he would receive real-time notifications whenever AI-powered cameras spotted her vehicle. She wasn&#39;t suspected of a crime.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0452aa40-a66e-4f94-bdf3-d0040b157398/Screenshot_2026-07-08_at_4.43.59_PM.png?t=1783543463"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Click to see video</a></p></span></div></div><p class="paragraph" style="text-align:left;">According to court records, he allegedly used government databases, automated license plate readers, surveillance alerts, and other law enforcement tools to track her movements and ultimately chase her down. At one point he allegedly told her, &quot;I told you I&#39;d find you and pull you over.&quot; That&#39;s an insane abuse of power. It&#39;s exactly why I roll my eyes whenever someone says we should be comfortable giving governments or corporations more surveillance capabilities because they&#39;ll only be used by the good guys. The “good guys” doing some heavy lifting here. (<a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="felons-fraudsters-flog-offensive-cy"><a class="link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow"><b>Felons, Fraudsters Flog Offensive Cybersecurity Startup</b></a></h3><p class="paragraph" style="text-align:left;">Krebs has a knack for finding stories that make you stop and say, &quot;Wait, what?&quot; This week&#39;s example is Iris C2, a self-described offensive security company that claims to sell cyber capabilities and phone-hacking services to government customers. Krebs dug into the company&#39;s background and found connections to Jacob Wohl and Jack Burkman, two political operatives better known for a long history of failed ventures, misinformation campaigns, lawsuits, and criminal convictions than cybersecurity research. Iris C2 emerged from a penetration-testing business before pivoting toward zero day peddling, with related corporate records pointing back to Burkman&#39;s lobbying operation.</p><div class="image"><a class="image__link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bea4b96b-ac7d-4f92-9541-6faa39c139e9/Screenshot_2026-07-08_at_5.15.51_PM.png?t=1783545372"/></a></div><p class="paragraph" style="text-align:left;">One of the quotes Krebs highlighted was Wohl describing himself as highly technical and capable of building &quot;spectacularly exquisite capabilities,&quot; despite acknowledging he has no formal education or training in computer science or information security. Maybe there&#39;s a legitimate business here. Maybe there isn&#39;t. But if you&#39;re a security researcher frustrated with bug bounty programs or looking for someone to buy your zero-days, I&#39;d be asking a lot of questions before handing them over to a company whose founders are better known for political grift and felonies than cybersecurity. (<a class="link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="vidar-stealer-unmasked-code-signing"><a class="link" href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f32ab5c-c69f-4f11-a5af-725cf0a9329f/image.png?t=1783634055"/></div><p class="paragraph" style="text-align:left;">Unit 42 with a great breakdown of Vidar stealer campaign they spotted spiking in April 2026. It uses malvertising which is always one of a delivery mechanism that makes my ears perk up. Pushing fake cracked software downloads - but the evasion tricks are worth noting. The loader binaries are inflated with null bytes up to 491MB (the actual malicious content is only 2.3MB) specifically to skip automated sandbox analysis, paired with a fake JustWatch code-signing certificate and an in-memory AMSI bypass. The whole thing is built on a MaaS framework called Factory-v3 that generates unique hashes per build, making hash-based detection pretty useless.</p><p class="paragraph" style="text-align:left;">The payload is a two-fer: Vidar steals your browser creds and crypto wallets while XMRig mines Monero in the background using your CPU cycles. The operator gets a Telegram ping labeled &quot;X3D MINER • NEW LOG&quot; for every fresh infection. A second variant showed up April 24th swapping the fake JustWatch cert for one impersonating BleacherReport - same infrastructure, just iterating on the certificate approach. IOCs are in the full report if you want to go hunting, and defenders should prioritize stripping null byte padding before applying file size limits or you&#39;ll miss this one entirely. (<a class="link" href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="your-access-reviews-have-a-99-appro"><a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Your access reviews have a 99% approval rate. That&#39;s the problem.</a>*</h3><p class="paragraph" style="text-align:left;">If every reviewer clicks approve, the review didn&#39;t happen. Attestation fatigue is real: reviewers see 200 identical rows with no context and do the only reasonable thing. Opal&#39;s Paladin triages the queue before they ever open it — automating the routine 90% with a full audit trail, surfacing the 10% that needs a human call. <a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Watch the on-demand demo</a>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="ubiquiti-patches-critical-uni-fi-fl"><a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS</a></h3><p class="paragraph" style="text-align:left;">If you&#39;re running Ubiquiti gear, patch now. Ubiquiti just dropped fixes for seven critical vulns in UniFi OS, headlined by CVE-2026-50746, a max severity command injection flaw in the UniFi Connect Application. Anyone with network access could exploit it to run commands on the host device - no user interaction required. The fix is version 3.4.20, go get it.</p><p class="paragraph" style="text-align:left;">The other six CVEs hit a wide range of Ubiquiti products - UniFi Talk, Access, Protect, their OS Server, and a bunch of routers, gateways, NAS and surveillance systems. With Censys tracking over 100,000 UniFi OS instances exposed to the internet (nearly half of them in the US), the blast radius here is significant. Worth noting that Ubiquiti gear has been a favorite target for state-sponsored groups before - Russia&#39;s GRU was caught using hijacked Ubiquiti routers as recently as 2024 to proxy espionage traffic. No confirmed exploitation in the wild yet, but given the history and the exposure numbers, that window probably won&#39;t stay open long. (<a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="only-fans-models-are-accidentally-m"><a class="link" href="https://www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear</a></h3><p class="paragraph" style="text-align:left;">This one&#39;s a fun unintended consequence story. Scammers have been hijacking .gov and .edu websites - over 2,000 of them across 80 countries - to host fake &quot;leaked OnlyFans&quot; pages that redirect victims to malware and scam sites. Gold mine since they can use the Google authority score from the old legit site. Plot twist! OnlyFans creators filing DMCA takedown requests are acting as a free threat detection service, with over 384,000 takedown requests helping surface compromised government sites they probably didn&#39;t even know were hacked.</p><p class="paragraph" style="text-align:left;">UpGuard&#39;s research suggests that monitoring for adult content keywords on your .gov or .edu domain could serve as a solid early warning system for SEO injection attacks. What a weird and funny canary. One researcher noted that getting Google to remove the search results is surprisingly effective since these pages have virtually no visibility outside of search. The bulk of the DMCA requests are being fired off by one Estonian company called Rulta, which is raising some eyebrows about whether carpet-bombing compromised government sites with copyright notices is really the right approach - but hey, at least someone&#39;s finding these breaches. (<a class="link" href="https://www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="injective-sdk-on-npm-infected-with-"><a class="link" href="https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Injective SDK on npm infected with cryptocurrency wallet stealer</a></h3><p class="paragraph" style="text-align:left;">Supply chain attacks on npm and days that end in y. This one&#39;s nasty because it targeted the Injective Labs SDK - a package with 50,000 weekly downloads used by developers building crypto wallets, trading bots, and DeFi apps. As per usual, an attacker compromised a legitimate contributor&#39;s GitHub account, snuck in malicious code on June 8, and published version 1.20.21 before anyone noticed. The good news is the real account owner caught it within minutes and pushed a clean release. The bad news is 310 downloads happened in that window, and the malicious GitHub artifacts are still sitting there.</p><p class="paragraph" style="text-align:left;">The malware itself doesn&#39;t trigger on install, it waits until developers actually use wallet key generation or import functions, then quietly grabs the full mnemonic seed phrase and private key, bundles them up, and ships them out via HTTP POST to a legitimate-looking Injective Labs endpoint. Sneaky. If you&#39;re a developer who pulled that package, assume you&#39;re compromised - move your crypto to new wallets and rotate everything in your environment immediately.(<a class="link" href="https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="metas-new-ai-image-tool-lets-others"><a class="link" href="https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Meta&#39;s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ccaf90e6-c20a-42e8-a3dc-48b98f4ed004/image.png?t=1783632921"/></div><p class="paragraph" style="text-align:left;">Meta&#39;s spent a gazillion dollars on being a frontier AI lab and nobody is using their models. So why not just bake their new one into Instagram to force usage. Their new AI image model called Muse Image, and …wait for it… it&#39;s using your public Instagram photos by default to generate AI content - including letting other users @-mention your account to remix your photos into new images without notifying you. The opt-out is buried several menus deep in your settings, and here&#39;s the annoying part - anything already created with your photos before you disable it stays up. If you&#39;ve got a public Instagram account, it&#39;s worth taking the two minutes to go turn that off now.</p><p class="paragraph" style="text-align:left;">This is part of a broader trend of big tech companies quietly flipping AI training features to opt-out rather than opt-in. Google&#39;s doing the same thing with a new Search Services History setting that stores your images, audio, and video to train their models. Neither company is doing anything technically illegal here, but it’s concerning they didn’t have to. (<a class="link" href="https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="google-pays-250-k-for-linux-vulnera"><a class="link" href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Google pays $250K for Linux vulnerability allowing guest VM escapes</a></h3><p class="paragraph" style="text-align:left;">Two spicy Linux kernel vulnerabilities this week, and Google&#39;s bug bounty program had to write some big ol’ checks. The bigger one, dubbed &quot;Januscape&quot; (CVE-2026-53359), is a guest VM escape in KVM that sat undetected for 16 years. The short version: if you&#39;re renting a single cloud instance and have root on your guest VM, you can potentially take down or fully compromise the host machine and every other tenant on it. That&#39;s a bad day for any cloud provider. Google paid $250K for this one.</p><p class="paragraph" style="text-align:left;">The second bug, &quot;GhostLock&quot; (CVE-2026-43499), is a use-after-free in the kernel&#39;s futex priority-inheritance code that&#39;s been hiding since 2011 and lets low-privileged users escalate to root. That one netted $92K from Google&#39;s kernelCTF program. Both are patched in the kernel now, so go check your distro and make sure those fixes have actually landed on your systems. (<a class="link" href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-exploit-roundcube-flaw-to-s"><a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Hackers exploit Roundcube flaw to spy on academic researchers</a></h3><p class="paragraph" style="text-align:left;">China-linked hackers have been hitting Roundcube webmail servers at U.S. and Canadian universities since May, specifically targeting physics and engineering departments plus anyone touching astrophysics, particle physics, or national security research. Since May 2026, they&#39;ve been chaining together n-day Roundcube vulnerabilities to steal credentials and drop either a webshell or VShell backdoor into server memory. The attack only requires the email to be opened in the webmail client, so the specific recipients may have been less important than the fact that those departments were running vulnerable Roundcube versions - suggesting prior recon.</p><p class="paragraph" style="text-align:left;">Their custom JavaScript stealer (dubbed IceCube by Proofpoint) escapes iFrames, steals creds and 2FA material, then pivots to server-side exploitation via a deserialization vuln to plant a webshell. If that fails, there&#39;s a fallback that pulls down SNOWLIGHT and ultimately VShell. The tooling is verbose, well-commented, and likely LLM-assisted. (<a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="git-lost-how-git-hubs-ai-agent-was-"><a class="link" href="http://GitLost: How GitHub’s AI Agent Was Tricked Into Leaking Private Repository" target="_blank" rel="noopener noreferrer nofollow">GitLost: How GitHub’s AI Agent Was Tricked Into Leaking Private Repos</a></h3><p id="researchers-demonstrated-a-techniqu" class="paragraph" style="text-align:left;">Researchers demonstrated a technique they call &quot;GitLost,&quot; showing how an attacker could abuse GitHub&#39;s AI-powered issue-handling capabilities to retrieve information from private repositories. The attack starts with a public GitHub issue. Because the AI agent automatically reads issue titles and descriptions as part of its workflow, an attacker can embed instructions that look like legitimate questions but are actually prompts designed to manipulate the agent&#39;s behavior. In the proof of concept, the researchers simply asked the agent to retrieve information from both a public repository and a related private repository that the agent had access to. (<a class="link" href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d15d6139-9711-4b02-864c-b079690dd99f/Screenshot_2026-07-09_at_4.57.16_PM.png?t=1783634239"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b33113fa-379d-4895-8c95-39c99e49541e/Screenshot_2026-07-09_at_4.56.14_PM.png?t=1783634178"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6807f3e9-4b3f-4fd5-be49-fb67f485ff66/Screenshot_2026-07-09_at_5.24.02_PM.png?t=1783635879"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #175</title>
  <description>Free Fable! Fortibleed updates, New Citrix and Oracle active attacks, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-175</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-175</guid>
  <pubDate>Fri, 03 Jul 2026 12:28:00 +0000</pubDate>
  <atom:published>2026-07-03T12:28:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c4cfdfb1-8314-4550-855c-4ea6cf24fcea/Newsletter_Header.png?t=1783008291"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ab23d817-9f8e-4ddc-8ec3-0ad8e3a92be5/Newsletter_Sponsor_Logo.png?t=1783023326"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Finally back at home. Feels good to be writing this from my own office again. Just got back from SF the other night and had a great time talking AI and security at PlanetScale HQ. Have you been to SF recently? It is like a whole other world just by reading the billboards and bus stop ads. I swear there is a whole ecosystem of companies that only exist there.</p><p class="paragraph" style="text-align:left;">I love the city but it sure is dystopian to see someone sleeping at a bus stop where the ad is saying “Never hire another human again!” for some AI sales rep thing.</p><p class="paragraph" style="text-align:left;">But mission escape Texas heat for a few weeks was a success. Now its time to sweat again. Speaking of sweat, Vegas summer camp plans are in full swing. Calendar is already filling up, and me and Low Level have something fun planned for you guys to come to. More details soon, eyes peeled if you’re headed to BlackHat/DEFCON.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Michael Roytman and Ed Bellis are 2 data nerds who have thought about <a class="link" href="https://www.youtube.com/watch?v=AZSfRAfQ9UA&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">vulnerabilities and exploitation</a> longer than most anybody.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: This event at PlanetScale was awesome. <a class="link" href="https://www.youtube.com/live/F8tRi1RYf7c?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Really good live discussion</a> worth watching.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Mike Privette’s <a class="link" href="https://www.returnonsecurity.com/p/quantum-security-is-a-one-company-market?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Quantum Security Is a One-Company Market</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="us-lifting-export-control-restricti"><a class="link" href="https://cyberscoop.com/us-lifting-export-control-restrictions-anthropic-mythos-fable/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">US lifting export control restrictions on Anthropic’s Mythos, Fable</a></h3><p class="paragraph" style="text-align:left;">Well finding security vulnerabilities is possible again! (Right? Mythos is the only thing that could do that, right?) After a few weeks of back-and-forth, Anthropic and the Commerce Department have kissed and made up over Fable 5 and Mythos 5. The models are back online for U.S. users and export controls have been lifted, after the Trump administration briefly panicked over an Amazon threat intel report claiming they&#39;d jailbroken Fable&#39;s cybersecurity capabilities. The fix is new safety classifiers that Anthropic says will block the problematic behaviors 99.9% of the time, stress-tested by the federal Center for AI Standards and Innovation. Guardraily-er Guardrails!</p><p class="paragraph" style="text-align:left;">Anthropic&#39;s own testing found that ChatGPT 5.5, Claude Opus 4.8, and several other existing models could do the same things that freaked everyone out about Fable in the first place. So the export controls were essentially targeting capabilities that are already widely available. Former Bush-era Commerce official Christopher Padilla summed it up pretty well, calling the administration&#39;s AI policy approach &quot;chaotic and unpredictable&quot; - which is a bit rich given they&#39;re simultaneously loosening export controls on advanced AI chips to China. Defensive security folks should also note that the new classifiers will likely make Fable 5 even more restrictive for routine security work than it already was. Aka not useful. (<a class="link" href="https://cyberscoop.com/us-lifting-export-control-restrictions-anthropic-mythos-fable/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="open-source-runtime-security-harnes"><a class="link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Open-Source Runtime Security Harness for AI Agents (Two-line install)</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/41a1c696-b073-4aa4-95ed-daf77630119e/Screenshot_20260703_091423.png?t=1783070078"/></div><p class="paragraph" style="text-align:left;">Adrian is the open-source runtime security harness for AI agents. Five minutes from install to a continuous, independent security system monitoring your agents. While other tools watch what your agent does, Adrian also watches what it thinks and plans, blocking misalignment, prompt injection and tool abuse before they happen. </p><p class="paragraph" style="text-align:left;">Uses a technique theorised by OpenAI and Google DeepMind, and proven to catch 4x more malicious actions than activity monitoring alone. Built by Secure Agentics, a London-based AI security startup founded by former red teamers. </p><p class="paragraph" style="text-align:left;">Self-hosted and free, forever. (<a class="link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="forti-bleed-credentialtheft-campaig"><a class="link" href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">FortiBleed credential-theft campaign linked to Lynx ransomware</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/17209d6f-854d-47bc-99cd-d059d607b6ad/fortibleed-credential-stuffing.jpg?t=1783034602"/></div><p class="paragraph" style="text-align:left;">Turns out FortiBleed wasn&#39;t just opportunistic data hoarding. SOCRadar has now tied the whole operation directly to the INC and Lynx ransomware groups, and the scale is way bigger than originally thought. 430,000 FortiGate firewalls targeted, ~19,000 devices with actual traffic sniffers deployed, around 20 operators with defined roles, and roughly 500 servers running the operation. The smoking gun was finding browser sessions on FortiBleed infrastructure actively accessing both ransomware negotiation panels.</p><p class="paragraph" style="text-align:left;">The technical details are pretty gnarly too - they deployed a custom tool called &quot;FortiGate Sniffer&quot; to intercept VPN credentials directly from network traffic, left persistent backdoor accounts under the username &quot;adminin,&quot; and may have exploited an undisclosed Nextcloud zero-day for lateral movement. If you&#39;re running FortiGate devices, hunting for that &quot;adminin&quot; account is a good place to start. (<a class="link" href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="teen-suspect-in-scattered-spider-ha"><a class="link" href="https://therecord.media/teen-suspect-in-scattered-spider-hacks-extradited-to-us?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Teen suspect in Scattered Spider hacks is extradited to US</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/23ece5e1-d6e7-423f-bfc0-163f24153786/Screenshot_2026-07-02_at_6.25.54_PM.png?t=1783034757"/></div><p class="paragraph" style="text-align:left;">Another Scattered Spider member is facing the music - Peter Stokes, a 19-year-old dual U.S.-Estonian citizen, got extradited from Finland to Chicago this week. The centerpiece of the DOJ&#39;s case is a pretty textbook Scattered Spider playbook: call the IT help desk with Google Voice numbers, social engineer a password and MFA reset, compromise three accounts in under three hours, then drop an $8 million ransom demand on a luxury jewelry retailer. They also threw in ngrok for persistent access, which is becoming a bit of a calling card for this group.</p><p class="paragraph" style="text-align:left;">The company didn&#39;t pay the ransom, but still ate roughly $2 million in disruption and remediation costs. Stokes was originally picked up by Finnish authorities back in April following an Interpol Red Notice. This is part of a broader crackdown on Scattered Spider, a group the DOJ estimates has hit over 100 networks and collected more than $100 million in ransom payments. The arrests are starting to stack up for them. (<a class="link" href="https://therecord.media/teen-suspect-in-scattered-spider-hacks-extradited-to-us?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="pam-stealer-a-rustbased-mac-os-info"><a class="link" href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">PamStealer: a Rust-based macOS infostealer that validates credentials through PAM</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/329aa1f7-1723-4d30-840c-542dd14f30be/image.png?t=1783035659"/></div><p class="paragraph" style="text-align:left;">New macOS infostealer just dropped and this one&#39;s got some interesting tricks up its sleeve. PamStealer poses as Maccy, a legit clipboard manager, and uses a combo of AppleScript and JavaScript for Automation to drop its Rust payload. It validates stolen passwords locally through macOS&#39;s own PAM interface rather than phoning home with unverified creds - meaning it&#39;s making less noise than your typical commodity stealer. It also holds off on triggering the Full Disk Access prompt for up to 40 minutes after launch so nothing looks suspicious right out of the gate.<br><br>The social engineering piece is solid too - it tricks users into pressing Command-R which both executes the malicious code AND bypasses macOS&#39;s quarantine attribute that normally warns you about downloaded executables. Once it grabs your password, it throws up a fake &quot;file is damaged&quot; error so you just shrug and move on, none the wiser. Mac defenders should be watching for processes masquerading as Finder or Software Update, especially anything running under com[.]apple.finder.core or com[.]apple[.]security.daemon. The Jamf writeup is worth a read if you want the full technical breakdown. (<a class="link" href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fbi-seizes-net-nut-proxy-platform-p"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">FBI Seizes NetNut Proxy Platform, Popa Botnet</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/36b100b5-1721-490d-9936-57e25f41cf07/image.png?t=1783035992"/></div><p class="paragraph" style="text-align:left;">The FBI just took down NetNut, a residential proxy service run by publicly-traded Israeli company Alarum Technologies. If that name doesn&#39;t ring a bell, you might know it better as the Popa botnet - a network of over 2 million compromised devices, mostly cheap TV streaming boxes and smart TVs, rented out to cybercriminals for ad fraud, account takeovers, and traffic scraping. Google&#39;s threat intel team noted 316 distinct threat actor clusters using NetNut exit nodes in a single week, including both cybercriminal and espionage groups.</p><p class="paragraph" style="text-align:left;">NetNut had actually grown significantly after the FBI took down its biggest competitor IPIDEA earlier this year, so experts are hopeful this puts a real dent in the ecosystem. The practical takeaway here is worth repeating - those cheap no-name Android TV boxes flooding Amazon and AliExpress are essentially malware delivery devices. Spur found that 42% of LG webOS apps and over 25% of Samsung Tizen apps contain proxy SDKs that silently enroll your TV into these networks. Stick to name brands and verify your device supports Google&#39;s official Play Protect certification. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a> and <a class="link" href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">krebs here</a>)</p><h3 class="heading" style="text-align:left;" id="when-ai-invents-the-attack-browser-"><a class="link" href="https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">When AI Invents the Attack: Browser-Native Ransomware</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e8ec0acf-57ad-4c98-9f17-d69020f79e4a/Screenshot_2026-07-02_at_7.05.44_PM.png?t=1783037341"/></div><p class="paragraph" style="text-align:left;">Researchers found something genuinely concerning - while sifting through nearly 3,000 DeepSeek-attributed malware samples, they found one where the AI independently figured out that the browser&#39;s native <code>showDirectoryPicker()</code> API could be weaponized for ransomware. No exploit or installation required - just a permission prompt that, as ClickFix shows us, a ton of users would click. The attacker who prompted it probably had no idea this API even existed, which is nuts. DeepSeek connected the dots between a vague malicious goal and a real browser capability on its own.</p><p class="paragraph" style="text-align:left;">The PoC in the research is a fake AI photo tool that asks you to select a folder, encrypts your images during the fake &quot;processing&quot; step, and calls it a day. Worth noting this works on Android Chrome (since v132 added full File System Access support), and your DCIM folder - years of photos, banking screenshots, recovery codes - is fair game. iOS Safari doesn&#39;t expose the same API so iPhone users are in the clear here. No active campaigns have been spotted yet, but the barrier to operationalizing this is low enough that it warrants attention. Treat browser folder-access prompts like any other permission request, and maybe don&#39;t point random websites at your main photo library. (<a class="link" href="https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="researchers-spot-exploitation-of-an"><a class="link" href="https://cyberscoop.com/oracle-ebs-critical-vulnerability-exploited/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Researchers spot exploitation of another critical Oracle defect</a></h3><p class="paragraph" style="text-align:left;">New CVE to keep on your radar - CVE-2026-46817, a 9.8 severity hit on Oracle E-Business Suite&#39;s payments processing feature. Threat intel firm Defused caught six exploitation attempts on their honeypots over a two-hour window Saturday, all from a single IP, and this was happening before any public proof-of-concepts were even available. Shadowserver&#39;s scans show about 950 potentially vulnerable instances exposed to the internet, with more than half sitting in the US.</p><p class="paragraph" style="text-align:left;">If this sounds familiar, it should - Clop ransomware had a field day with Oracle E-Business Suite last year, and ShinyHunters just got done tearing through PeopleSoft hitting over 100 organizations. The current activity looks more like someone testing their weaponization than an active campaign, but given the history here, patch your Oracle deployments before this gets interesting. (<a class="link" href="https://cyberscoop.com/oracle-ebs-critical-vulnerability-exploited/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ongoing-password-spray-campaign-abu"><a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175#new_tab" target="_blank" rel="noopener noreferrer nofollow">Ongoing password spray campaign abuses Azure CLI legacy auth flow to bypass MFA and compromise Microsoft 365 accounts.</a></h3><p class="paragraph" style="text-align:left;">Huntress caught a massive password spray campaign hitting Microsoft 365 that&#39;s bypassing MFA through a legacy auth flow most people forgot exists. Attackers are using old breached credentials and validating them through Azure CLI&#39;s OAuth 2.0 ROPC flow—which completely skips interactive MFA prompts because it sends creds directly to the token endpoint. Dozens of orgs thought they had MFA enforced everywhere, but their Conditional Access Policies weren&#39;t scoped to cover this flow. Tens of millions of login attempts and dozens of confirmed compromises.</p><p class="paragraph" style="text-align:left;">The fix is pretty straightforward but requires tightening up your CAP scope. You need to enforce MFA for <i>all</i> users, <i>all</i> cloud apps, and <i>all</i> client types. Microsoft has a setting specifically to block ROPC sign-ins (userStrongAuthClientAuthNRequired), and you should probably restrict Azure CLI access to admins only. Also worth noting: the attacks are coming primarily from an IPv6 range tied to LSHIY LLC (AS32167), so watch your sign-in logs for ROPC attempts and weird geo patterns. If you&#39;ve been relying on &quot;trusted location&quot; exceptions or report-only policies, those are getting exploited too.<br>(<a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175#new_tab" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="new-citrix-bleed-vulnerability-expl"><a class="link" href="https://www.securityweek.com/new-citrixbleed-vulnerability-exploited-immediately-after-public-disclosure/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure</a></h3><p class="paragraph" style="text-align:left;">New CitrixBleed-adjacent vuln just dropped for NetScaler, and threat actors were already hammering it within 24 hours of public disclosure - basically the moment watchTowr published their technical writeup and detection artifact generator. CVE-2026-8451 is an out-of-bounds read in NetScaler&#39;s XML parser that leaks memory contents back in the NSC_TASS cookie, no auth required. The catch is the appliance needs to be configured as SAML IDP, but that&#39;s not exactly a rare configuration in enterprise environments.</p><p class="paragraph" style="text-align:left;">Lupovis caught at least two separate threat actors probing their sensors, one from Frankfurt infrastructure and another from Koapu Cloud HK, both using the same playbook - probe for the right endpoint, get a 200 OK, immediately drop the payload. If you&#39;re running NetScaler as SAML IDP, patch now, and if you can&#39;t patch, disable SAML IDP until you can. Either way, go check your /saml/login traffic and NSC_TASS cookie values for anything weird - if you&#39;re already hit, you&#39;ll want to know sooner rather than later. (<a class="link" href="https://www.securityweek.com/new-citrixbleed-vulnerability-exploited-immediately-after-public-disclosure/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5c8d045e-6c29-4cb4-98e3-12e4ec7fed0e/Screenshot_2026-07-02_at_7.16.48_PM.png?t=1783037811"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/63e438bc-b3ac-45e5-99f6-b1a3e2582bdd/Screenshot_2026-07-02_at_7.19.25_PM.png?t=1783037969"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cef78d1c-af43-4293-aa66-d961cdd5437f/Screenshot_2026-07-02_at_7.23.33_PM.png?t=1783038218"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #174</title>
  <description>Fortibleed is a bigger nightmare than we thought, Scattered Spider members go to jail, LastPass has another breach this time via Salesforce, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-174</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-174</guid>
  <pubDate>Fri, 26 Jun 2026 12:38:00 +0000</pubDate>
  <atom:published>2026-06-26T12:38:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9ecd64fd-7bd0-41a8-9e85-89b6a6fa66d5/Newsletter_Header.png?t=1782445933"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.tines.com/platform/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9f65c037-0ece-4aff-82ff-883daf0129f4/Newsletter_Sponsor_Logo.png?t=1782445946"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing from rural Nevada outside Lake Tahoe. Sorry for all of you who hang out in my live streams, it’s been hard to find good internet connection in a quiet spot out here. I did stream a few times from the basement of a museum and a closed book store. You have to get creative to keep making content on the road!</p><p class="paragraph" style="text-align:left;">I’ve also apparently fallen into this new hobby of scuba diving since my keynote at Descent Cyber and decided to bring my gear and dive in the very cold Lake Tahoe. I was very jealous of the other guy on the boat who was in a dry suit with a heater in it.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b6ec7a95-c154-4786-ad89-fed949e6148f/IMG_8153.png?t=1782410001"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ad37701a-05f7-47f7-9ba5-ecf387c25e6f/Screenshot_2026-06-25_at_12.50.30_PM.png?t=1782409931"/></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: I heard I’ll be <a class="link" href="https://luma.com/ow1f82nb?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">speaking on a panel</a> with Low Level, Clint Gibler, and Daniel Miessler @ PlanetScale HQ during the AI Engineer World’s Fair on Monday</p><p class="paragraph" style="text-align:left;">🎤 Something I said: GitHub is <a class="link" href="https://youtu.be/8MqOtYAw9dw?si=-zgZGUWgLWnm6QXz&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">not OK</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: An <a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Open Letter</a> On Transparent AI Cyber Protections</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="russian-initial-access-broker-behin"><a class="link" href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Russian Initial Access Broker Behind FortiBleed Campaign</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fbcbd874-963b-4670-8c01-265c570226fa/Screenshot_2026-06-25_at_10.36.55_PM.png?t=1782445024"/></div><p class="paragraph" style="text-align:left;">A Russian initial access broker has been running a credential harvesting operation called FortiBleed, targeting over 430,000 FortiGate firewalls since at least February. The attacker uses a custom Golang tool called FortigateSniffer that abuses legitimate FortiOS diagnostic commands to passively sniff authentication traffic across 24 protocols. They&#39;re SSH brute-forcing their way into exposed firewalls, capturing cleartext credentials and password hashes, then cracking and selling that access. SOCRadar estimates over 110 million credentials have been compromised through 650+ harvesting pipelines.</p><p class="paragraph" style="text-align:left;">They&#39;re heavily focused on SMBs under 200 employees, and the operation isn&#39;t even Fortinet-exclusive despite the name. The threat actor is also hitting Sophos SSL-VPNs, RDWeb portals, MSSQL, Citrix, and grabbing RADIUS, NTLM, and Kerberos data. They successfully cracked Kerberos hashes and exfiltrated DFS backup data from a NATO-aligned defense contractor in June. SOCRadar suspects this Russian-speaking IAB might be providing access to state-sponsored groups or ransomware gangs, illustrating how initial access brokers fuel the broader cybercrime ecosystem. (<a class="link" href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read this</a>)</p><h3 class="heading" style="text-align:left;" id="the-hidden-operational-costs-slowin"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">The Hidden Operational Costs Slowing Down Network Teams</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0788bfa9-d1ab-43a1-bebb-c90b41aad678/Newsletter_ad_640x480__1_.png?t=1782375045"/></div><p class="paragraph" style="text-align:left;">Modern network operations are more complex than ever, but the work behind them is still too manual. Security teams are stuck chasing context across tools. IT teams are slowed down by repetitive operational work. The result is slower response, more friction, and duplicated effort.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">Tines’ new guide</a> explores how IT and security teams can move faster with fewer manual steps, clearer audit trails, and better operational visibility. Inside, you’ll learn practical ways to streamline incident response, change management, network troubleshooting, and more. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">Get the guide</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="password-manager-maker-last-pass-sa"><a class="link" href="https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Password manager maker LastPass says hackers stole customer support case data during Klue breach</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/xPen2H_HRdE" width="100%"></iframe><p class="paragraph" style="text-align:left;">LastPass with another breach, though this time it&#39;s not directly their fault. A market research firm called Klue got hit by an extortion group named Icarus, and since LastPass uses them via their Salesforce integration, customer names, phone numbers, email addresses, physical addresses, and support ticket data all got swept up in the theft. No password vaults were touched this time, which is an important bit.</p><p class="paragraph" style="text-align:left;">That said, support ticket data is nothing to brush off - those records tend to contain sensitive fragments like account recovery info and billing details. And given LastPass&#39;s 2022 breach where entire encrypted vaults were stolen and later cracked, their customers are understandably a little jumpy. Klue seems to have a big blast radius with HackerOne, Recorded Future, and Tanium are also in the affected list. Icarus is threatening to release the data if ransom isn&#39;t paid, so this one&#39;s still developing. (<a class="link" href="https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Read more</a>)</p><h3 class="heading" style="text-align:left;" id="from-langflow-to-monero-inside-cve-"><a class="link" href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">From Langflow to Monero: Inside CVE-2026-33017 Cryptominer</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/217030f8-5b45-4692-b2d7-45070cf2ad2b/Screenshot_2026-06-25_at_11.58.45_AM.png?t=1782403134"/></div><p class="paragraph" style="text-align:left;">Trend Micro dropped a pretty detailed writeup on a cryptomining campaign targeting Langflow, the AI workflow builder. CVE-2026-33017 is an unauthenticated RCE in Langflow&#39;s API that lets attackers just POST a Python payload to a public endpoint - no auth required. From there, a shell script drops a Go-based miner called lambsys that goes full scorched earth: kills rival miners, disables AppArmor, SELinux, and UFW. It then spreads laterally via SSH key reuse to every host the victim can reach. If you&#39;re running Langflow exposed to the internet, especially as root on infra with broad SSH access, you&#39;ve had a bad time.</p><p class="paragraph" style="text-align:left;">The malware traces back to a 2019 KORKERDS dropper called is[.]sh, and this one&#39;s named isp[.]sh - same SSH worm pattern, same userdel commands for rival miner accounts. The operator has been quietly iterating this toolchain since at least May 2024 with near-zero public visibility. The fix is straightforward - update Langflow to 1.9.0 and stop exposing it to the public internet. (<a class="link" href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="scattered-spider-hackers-plead-guil"><a class="link" href="https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Scattered Spider Hackers Plead Guilty on Day 1 of Trial</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/14666989-73fa-4c42-ab40-d65257e6aa55/Screenshot_2026-06-25_at_11.49.49_AM.png?t=1782402602"/></div><p class="paragraph" style="text-align:left;">Two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), saved everyone a six-week trial by pleading guilty on day one in the UK. These two were behind the 2024 Transport for London attack, but that&#39;s almost the least interesting thing about them. Jubair co-ran a SIM-swapping Telegram channel called Star Chat, was allegedly behind the massive 2022 SMS phishing campaign that hit 130+ organizations including LastPass and Signal, and was selling fake emergency data requests to extract user data from tech companies - all starting at age 15. Flowers, meanwhile, is reportedly the guy who gave those anonymous media interviews bragging about the MGM and Caesars casino hits back in 2023.</p><p class="paragraph" style="text-align:left;">The Scattered Spider takedown is slowly but surely wrapping up. Noah Urban already got 10 years last August, Tyler Buchanan pleaded guilty in April and is awaiting sentencing, and three more members still have charges pending. Jubair is also staring down a separate New Jersey federal indictment covering 120 network intrusions across 47 US companies with $115 million in ransom payments. Sentencing for Jubair and Flowers is set for July 15th in London, but something tells me the US will want their turn after that. (<a class="link" href="https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="f-fmpeg-pixel-smash-flaw-allows-rce"><a class="link" href="https://www.runzero.com/try/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow">Is Your Attack Surface Ready for the AI-Attack Era?</a>*</h3><p class="paragraph" style="text-align:left;">AI-generated exploits don&#39;t need sophistication, just a gap you don&#39;t know exists.</p><p class="paragraph" style="text-align:left;"><b>runZero</b> knows every asset, finds every exposure, and maps every attack path across IT, OT, IoT, cloud, and mobile, then prioritizes the vulnerabilities most likely to be exploited and verifies they&#39;re remediated. No agents. No credentials.</p><p class="paragraph" style="text-align:left;">Defenders win by default. Even against AI. They also offer a <b>21-day free trial</b>, so go test it out. (<a class="link" href="https://www.runzero.com/try/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="f-fmpeg-pixel-smash-flaw-allows-rce"><a class="link" href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances</a></h3><p class="paragraph" style="text-align:left;">Nasty one dropped for FFmpeg - CVE-2026-8461, dubbed &quot;PixelSmash,&quot; is a heap out-of-bounds write in the MagicYUV decoder that allows RCE via crafted media files. Given that FFmpeg&#39;s libavcodec is basically everywhere - video players, media servers, NAS devices, cloud transcoding pipelines - the attack surface here is massive. JFrog confirmed successful exploitation against a pretty impressive list of targets including Jellyfin, Emby, Nextcloud, Immich, Kodi, OBS Studio and more.</p><p class="paragraph" style="text-align:left;">The delivery mechanism is a 50KB AVI, MKV, or MOV file that requires zero authentication to trigger. On the server side it fires when a file gets uploaded and auto-processed, and on desktop it can even trigger just by browsing to a folder containing the file if your file manager uses ffmpegthumbnailer for thumbnails. There&#39;s even a zero-click torrent attack path if the victim auto-downloads into a monitored media library. Patch to FFmpeg 8.1.2 now, but in reality you’re not the one that needs to upgrade it as its embeded in so much. Watch for patch notes …everywhere this week. (<a class="link" href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="whats-app-vb-script-campaign-uses-f"><a class="link" href="https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/63d7fe35-f201-43ad-b58f-58d64b18fa35/Screenshot_2026-06-25_at_12.07.02_PM.png?t=1782403632"/></div><p class="paragraph" style="text-align:left;">Kaspersky&#39;s flagging an active campaign spreading malicious VBScript files through WhatsApp, hitting users across Malaysia, Brazil, India, and several other countries. The attack is pretty straightforward social engineering - compromised WhatsApp accounts are being used to send contacts what look like business and financial documents (&quot;Financial Reports.vbs&quot;). Once opened, it kicks off a multi-stage infection chain that ends with ManageEngine RMM Central getting installed on the victim&#39;s machine, handing the attacker remote access. The campaign&#39;s got some interesting obfuscation techniques, with the VBScript files stuffed with fake Windows Update metadata and comments written in Chinese.</p><p class="paragraph" style="text-align:left;">Attribution is still up in the air, but Kaspersky found infrastructure overlaps with Gh0st RAT and ValleyRAT activity. The infection chain also behaves slightly differently depending on whether you&#39;re using WhatsApp Web vs the Desktop app - in the Desktop version, WhatsApp itself spawns the malicious WScript process, which is a neat trick. Standard advice applies here: if you weren&#39;t expecting a file attachment, even from a known contact, don&#39;t open it - especially anything ending in .vbs, .js, .ps1, or .bat. (<a class="link" href="https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="photo-zip-campaign-targeting-hospit"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/24218c6c-f046-4344-8c51-d3859655cfb8/image.png?t=1782444798"/></div><p class="paragraph" style="text-align:left;">Microsoft dropped a detailed threat intel report on an active campaign specifically targeting hotel and hospitality staff. Staff are getting phishing emails through Calendly&#39;s notification infrastructure (which neatly passes SPF/DKIM/DMARC checks) with lures like bedbug complaints and guest reviews, leading them to download what looks like a photo ZIP. Inside is a fake .png shortcut that kicks off an obfuscated PowerShell chain, ultimately dropping a Node.js implant for C2 persistence. The attacker has been actively evolving their PowerShell obfuscation through seven distinct phases since April 2026, which is a good sign they&#39;re watching for detections and adjusting.<br><br>What makes this one worth paying attention to is the dual persistence mechanism - they&#39;re using both HKCU\Run for the Node.js implant and a RunOnce loop for the PE payload that keeps repopulating itself. Microsoft confirmed that even after Defender blocked the PE payload on a compromised device, the Node.js persistence survived and resumed beaconing two days later. If you&#39;re in the Defender/Sentinel world, Microsoft dropped a full set of KQL hunting queries in the article worth grabbing. The campaign is dubbed TonRAT internally, and attribution is currently unknown. (<a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="mac-os-weaknesses-chained-to-silent"><a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">macOS Weaknesses Chained to Silently Disable Endpoint Security Agents</a></h3><div class="image"><a class="image__link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ba0d0099-82db-4e71-98b2-9bcdf36c9261/Screenshot_2026-06-25_at_12.13.34_PM.png?t=1782404023"/></a></div><p class="paragraph" style="text-align:left;">XM Cyber just showed how a regular macOS user — no admin rights needed — <a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">can silently kill enterprise security tools like EDR and MDM agents</a>. The attack chains together some older known primitives (abusing XPC connections and NIB file injection) with a clever new trick: exploiting how the kernel&#39;s code-signing trust cache sticks around after a legit signed app runs. Basically, you can inject malicious code that the system still trusts as if it&#39;s the real deal, then use it to call privileged functions that shut down security tools.</p><p class="paragraph" style="text-align:left;">They demo&#39;d this against CrowdStrike Falcon (completely unloaded it) and Kandji MDM (permanently killed it in two stages). CrowdStrike paid out a bounty and added detection, Kandji patched and got CVE-2026-39118, and a third unnamed EDR vendor is working on fixes. XM Cyber is dropping an open source tool called XPC Hunter at Black Hat 2026 that&#39;ll help find these exploitable XPC surfaces across all your installed apps, which should be fun for both sides of the aisle. (<a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="zero-day-exploitation-of-vulnerabil"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/049e793b-658b-47b1-88ac-3cff9848ddc9/Screenshot_2026-06-25_at_12.17.23_PM.png?t=1782404252"/><div class="image__source"><a class="image__source_link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" rel="noopener" target="_blank"><span class="image__source_text"><p><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Source: Mandiant</a></p></span></a></div></div><p class="paragraph" style="text-align:left;">Mandiant caught a threat actor exploiting a zero-day (CVE-2026-20245) in Cisco&#39;s SD-WAN Manager to escalate from admin to root access at a service provider. The attack chain started with rogue peering connections—possibly leveraging two other critical auth bypass vulns (CVE-2026-20127 and CVE-2026-20182) that weren&#39;t patched yet, or stolen certificates from an earlier compromise. Once in via SSH, the attacker toggled the default admin password back and forth to stay under the radar, then dropped a malicious CSV file called &quot;evil_tenant.csv&quot; through a file upload feature that didn&#39;t properly sanitize input. The CSV created a root-privileged account called &quot;troot&quot; by injecting entries into /etc/passwd and /etc/shadow.</p><p class="paragraph" style="text-align:left;">The attacker deleted artifacts, restored original configs, and ran a validation script to confirm all traces were scrubbed. They backed up files before modification so the device wouldn&#39;t throw alerts from broken configs. This is &quot;living off the edge&quot; tradecraft where network appliances become prime targets because they lack the logging depth for forensics while sitting at the perfect chokepoint for long-term intelligence collection. Cisco&#39;s pushed patches (20.9.9.2, 20.12.7.2, and newer versions), and if you&#39;re running SD-WAN infrastructure, now&#39;s the time to pull admin-tech logs and hunt for suspicious peering connections, rapid-fire password changes, or unexpected su commands to non-standard accounts. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="third-draft-kings-hacker-sentenced-"><a class="link" href="https://www.securityweek.com/third-draftkings-hacker-sentenced-to-18-months-in-prison/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow"><b>Third DraftKings Hacker Sentenced to 18 Months in Prison</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/ae_iPShA1VM" width="100%"></iframe><p class="paragraph" style="text-align:left;">The third and final defendant in the 2022 DraftKings credential-stuffing attack just got sentenced. Nathan Austad, aka &quot;Snoopy,&quot; is heading to prison for 18 months and has to fork over $1.8 million in restitution and forfeiture. The crew used credentials from other breaches to access 60,000+ accounts, then drained funds or sold the accounts off.</p><p class="paragraph" style="text-align:left;">They were apparently joking about the FBI investigation in their own messages while still committing the crimes. All three are now convicted: Garrison got 18 months back in 2024, Stokes got 30 months in April, and now Austad wraps it up. Turns out the FBI could, in fact, do something about it. (<a class="link" href="https://www.securityweek.com/third-draftkings-hacker-sentenced-to-18-months-in-prison/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7fd42934-898f-4491-bd89-0d27e425ff56/Screenshot_2026-06-25_at_10.38.01_PM.png?t=1782445087"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/48669de0-998f-46a7-b826-92105f4c4b1d/image.png?t=1782445289"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72a82693-a5d9-41fe-a43f-c9a20eceb69b/Screenshot_2026-06-25_at_10.40.09_PM.png?t=1782445217"/><div class="image__source"><span class="image__source_text"><p>I love this twitter account, but this might be it’s magnum opus</p></span></div></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #173</title>
  <description>Free Mythos! Fortinet having massive security issues, FIFA has a near miss on massive security vulnerability in the World Cup streams, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-173</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-173</guid>
  <pubDate>Fri, 19 Jun 2026 12:44:00 +0000</pubDate>
  <atom:published>2026-06-19T12:44:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/207af6a7-0e53-46b5-8e86-4a2a2ff99b4b/Newsletter_Header.png?t=1781841988"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://withpersona.com/?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6ba84c68-892a-4165-a0c9-6b041be410ce/Newsletter_Sponsor_Logo.png?t=1761833305"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Out west a few weeks - speaking at some events. One of the major topics people are asking about is of course the Mythos and Fable restrictions from dot gov. I had to get creative with my live streaming locations this week including the basement of a museum and a book store that was closed today. In search of good wifi and a quiet corner.</p><p class="paragraph" style="text-align:left;">As a native New Yorker it certainly has been hard to avoid getting caught up in the energy of the Knicks victory. Between that and the World Cup it is straight up emotional for me watching people come together in community like that. It’s something we all crave and I’m glad this time crowds chanting on the streets is for joy.</p><p class="paragraph" style="text-align:left;">I’ll be at AI Engineering World’s Fair next week and I’m looking forward to talking to the group there as it will largely be out of the infosec echo chamber. (I mean… not that AI engineering isn’t it’s own echo chamber, but at least it’s not MY echo chamber).</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: This will accelerate the open weight models reaching <a class="link" href="https://x.com/mattjay/status/2065652704383270944?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">“Mythos tier” capabilities.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=gDpuFDCLvBc&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">LowLevel’s take</a> on the Mythos/Fable situation</p><p class="paragraph" style="text-align:left;">🎤 Something I said: I talked to the hackers that found a <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">nation state 0day</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Absolute <a class="link" href="https://www.statesman.com/news/article/laredo-plane-crash-loop-20-austin-bound-22308875.php?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">tragedy for the Austin tech scene</a> - Josh, the founder/CEO of Capital Factory killed in a plane crash</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="an-open-letter-on-transparent-ai-cy"><a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">An Open Letter On Transparent AI Cyber Protections (and More Mythos Madness)</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/189bdbe5-f7ee-4e44-965f-d21ac5c7bf76/Screenshot_2026-06-17_at_4.26.42_PM.png?t=1781730265"/></div><p class="paragraph" style="text-align:left;">The Mythos conversation has gotten a little ridiculous. At this point, every cybersecurity discussion starts and ends with Mythos, Fable, Project Glasswing and the coming “AI vulnerability apocalypse”. </p><p class="paragraph" style="text-align:left;">I&#39;ve joked that people are treating Mythos like a skeleton key for the internet. I interviewed HD Moore about it, and that&#39;s essentially how he described the concern: a model that isn&#39;t just good at finding vulnerabilities but is also capable of reliably writing exploit code. That&#39;s the capability jump everyone is focused on, not vulnerability discovery by itself. AI has been helping find bugs for a while. The concern is what happens when exploit development becomes dramatically easier and more accessible.</p><p class="paragraph" style="text-align:left;">Anthropic&#39;s guardrails were so aggressive at launch that researchers were reporting they could barely discuss cybersecurity topics without triggering safety controls. That&#39;s what sparked the &quot;Free Mythos&quot; movement. If these models truly represent a step-function increase in capability, some people argue that locking them away behind a small group of approved users creates an unfair and potentially harmful asymmetry. <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Katie Moussouris</a> and others have gone further, arguing that concentrating access among a privileged few may actually create more risk than it reduces.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f881d1f0-d2a1-434f-89ab-a79ac448b099/Screenshot_2026-06-17_at_6.56.42_PM.png?t=1781737009"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Source: Luta Security</a></p></span></div></div><p class="paragraph" style="text-align:left;">Even if Anthropic, OpenAI, and others successfully gate frontier models today, it&#39;s hard to see how that remains sustainable. <a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAAznX8BNRuE7M9-TAcZRXWBU_xVm1GyipA" target="_blank" rel="noopener noreferrer nofollow">Alex Stamos</a> and others are pointing out that open-source models are advancing rapidly and could reach comparable capabilities in less than a year. If that&#39;s true, then much of the current debate becomes temporary by definition. All of the discussions about trusted access programs, Glasswing participants, and restricted model availability may ultimately be overtaken by open models that anyone can download and run. If the capability is coming regardless, the question shifts from containment to preparation.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f657a575-c9cd-42a0-8579-0b27e7d90ea5/Screenshot_2026-06-17_at_7.00.57_PM.png?t=1781737297"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAAznX8BNRuE7M9-TAcZRXWBU_xVm1GyipA" target="_blank" rel="noopener noreferrer nofollow">Source: Alex Stamos on LinkedIn</a></p></span></div></div><p class="paragraph" style="text-align:left;">That&#39;s why I keep coming back to the same conclusion. While everyone is debating Mythos, the security industry still has the same problems it had yesterday. We&#39;re still seeing supply chain compromises, credential theft, phishing campaigns, malicious browser extensions, and years-old security failures succeeding every day. The AI super hacker hasn&#39;t replaced those threats. Cybersecurity didn&#39;t suddenly become obsolete. If Mythos-class models eventually make exploitation easier, we&#39;ll adapt and deal with that too. But for now, defenders still have vulnerabilities to patch, identities to protect, and incidents to respond to. The vulnerability apocalypse may or may not arrive. In the meantime, cybersecurity still looks a lot like cybersecurity. (read more <a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="deepfake-attacks-surged-50-x-are-yo"><a class="link" href="https://withpersona.com/lp/wf-infosec?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" target="_blank" rel="noopener noreferrer nofollow">Deepfake attacks surged 50x. Are your security defenses ready?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a9846bff-0c7e-421f-963e-26873a9456c1/header_image_1200_800_vulnu.png?t=1781803238"/></div><p class="paragraph" style="text-align:left;">We’ve seen deepfake attacks surge 50x, yet 85% of CISOs say they lack GenAI-ready incident response plans. Workforce security is no longer about if you&#39;ll be targeted, but whether you&#39;re prepared.</p><p class="paragraph" style="text-align:left;"><b>Persona</b> verifies employees, contractors, and vendors in seconds — automating identity checks to eliminate manual work and stop impersonation attacks before they spread. Integrate Persona&#39;s Workforce IDV solution with your existing security tech stack to verify who’s actually behind every login, device, and network. (<a class="link" href="https://withpersona.com/lp/wf-infosec?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="accenture-shells-out-418-b-on-three"><a class="link" href="https://cyberscoop.com/accenture-industrial-cybersecurity-acquisition-dragos-netrise-runzero/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Accenture Shells Out $4.18B On Three Companies in Big Industrial Cybersecurity Push</b></a></h3><p class="paragraph" style="text-align:left;">This is one of those deals that makes the entire cybersecurity industry stand up and pay attention. Accenture is acquiring a majority stake in Dragos and bringing runZero and NetRise under the same umbrella, creating a combined OT and asset intelligence powerhouse. What makes this story fun for me personally is that these aren&#39;t random companies. runZero founder HD Moore is a longtime industry legend who was literally just on my YouTube channel. NetRise founder Tom Pace is someone I run into at the gym. These are companies built by people who have spent years grinding in the security community, and now they&#39;re part of a deal valued at roughly $4.2 billion. That&#39;s a massive validation not just for the companies involved, but for the broader cybersecurity startup ecosystem. (also both Austin founders!)</p><p class="paragraph" style="text-align:left;">I don’t normally cheerlead investment round raises or acquisitions but this one is too close to home and too good for the security community. The founder/creator of Metasploit winning is just a win for all of us. Way to go HD, Tom, Rob and all your teams. (<a class="link" href="https://cyberscoop.com/accenture-industrial-cybersecurity-acquisition-dragos-netrise-runzero/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="forti-bleed-leak-exposes-fortinet-v"><a class="link" href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/34de39c2-da2f-467f-8ae6-d8971d11564f/Screenshot_2026-06-17_at_4.33.10_PM.png?t=1781731714"/></div><p class="paragraph" style="text-align:left;">The latest Fortinet stories are a perfect example of why I struggle to get excited about AI-generated exploits, when the industry is still drowning in known vulnerabilities. Researchers uncovered what appears to be a massive credential dump affecting roughly 73,000 Fortinet VPN devices. </p><p class="paragraph" style="text-align:left;">The dataset reportedly contains usernames, email addresses, and plaintext passwords, along with organizational details that could help attackers prioritize targets. Some researchers who reviewed the data say they&#39;ve been able to verify at least some of the credentials as authentic. The most concerning detail is that the information appears to have come from exported FortiGate configurations, raising obvious questions about how attackers obtained them in the first place. Unclear by my money is on an 0day.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4cf0613e-9f11-4789-af1f-823ea05596ec/Screenshot_2026-06-17_at_5.32.34_PM.png?t=1781731964"/></div><p class="paragraph" style="text-align:left;">At the same time, Fortinet is once again dealing with <a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">active exploitation</a> of recently disclosed vulnerabilities. Researchers observed attackers exploiting critical FortiSandbox flaws shortly after patches became available, while older Fortinet vulnerabilities continue to be abused years after disclosure. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="google-exposes-china-espionage-grou"><a class="link" href="https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Google Exposes China Espionage Group That’s Been Lurking in Networks Undetected Since 2023</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d70c6ce2-c3a9-41d2-9328-6046b84dd34e/Screenshot_2026-06-17_at_4.41.04_PM.png?t=1781732087"/></div><p class="paragraph" style="text-align:left;">This is the kind of story that actually keeps me up at night, not because it&#39;s particularly novel, but because it reinforces something we&#39;ve been hearing for years from U.S. intelligence agencies and law enforcement. The FBI has repeatedly warned that Chinese threat actors are sitting inside critical infrastructure environments, maintaining access, and in many cases not doing anything immediately disruptive. Google&#39;s reporting traces activity back to at least September 2023, with attackers establishing persistence, deploying credential theft tools, upgrading malware, and maintaining access over long periods of time. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">What stands out in Google&#39;s report</a> is that the tradecraft itself isn&#39;t especially exotic. The malware capabilities look familiar: credential harvesting, backdoors, command-and-control infrastructure and data exfiltration. The operators clearly invested heavily in operational security, routing traffic through compromised routers, residential proxy networks, VPS infrastructure and U.S.-based systems to make attribution and detection more difficult.</p><div class="image"><a class="image__link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59787f71-377c-4718-ad85-c4fd27f57f36/Screenshot_2026-06-17_at_5.42.02_PM.png?t=1781732529"/></a></div><p class="paragraph" style="text-align:left;">The part that surprises me is the dwell time. If the earliest known compromises date back to 2023, how do organizations fail to notice activity for that long? Some of that is undoubtedly a testament to the attackers&#39; opsec. But some of it is also the reality that many critical infrastructure operators don&#39;t have massive security budgets, dedicated threat hunting teams, or twenty-four-hour security operations centers. These aren&#39;t always Fortune 100 companies with unlimited resources. They&#39;re often organizations running essential services while trying to manage increasingly complex threats with limited personnel and funding.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/24d0ba1a-85c8-4218-8e07-14f2a6611cfb/Screenshot_2026-06-18_at_1.12.59_PM.png?t=1781802826"/></div><p class="paragraph" style="text-align:left;">Chinese espionage groups aren&#39;t succeeding because they have some mythical capability that nobody else possesses. They&#39;re succeeding because they&#39;re patient, disciplined, and often operating against organizations that can&#39;t afford perfect security. (read more <a class="link" href="https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="threat-actors-abuse-claudeai-shared"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">80% of Organizations Are Sitting on Access They Forgot Existed</a>*</h3><p class="paragraph" style="text-align:left;">Every company has it. Former employees, old service accounts, permissions that were supposed to be temporary and never got cleaned up.</p><p class="paragraph" style="text-align:left;"><b>Opal Security</b> analysed provisioning data across thousands of systems and found that 80% were exposed through stale entitlements. As AI agents start requesting access to more systems, those forgotten permissions can turn into a much bigger problem.</p><p class="paragraph" style="text-align:left;">See what AI-ready security teams are doing differently in Opal&#39;s 2026 report. (<a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="threat-actors-abuse-claudeai-shared"><a class="link" href="https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/70302d08-b287-4241-abfa-5431df153f5e/Screenshot_2026-06-18_at_3.13.19_PM.png?t=1781810008"/></div><p class="paragraph" style="text-align:left;">This is one of the more clever ClickFix-style campaigns I&#39;ve seen lately because it abuses something people already trust: shared AI chats. Researchers found attackers buying ads that redirected victims to publicly shared Claude AI conversations. The victim thinks they&#39;re clicking on a helpful AI-generated guide, maybe instructions for installing software or fixing a common problem, but the shared chat has been crafted to display malicious commands. The user follows what appears to be legitimate AI advice, opens a terminal window, pastes the commands, and unknowingly downloads malware. (<a class="link" href="https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="texas-government-data-breach-allowe"><a class="link" href="https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Texas Government Data Breach Allowed Hackers to Steal 3 Million Driver’s Licenses and Passports</b></a></h3><p class="paragraph" style="text-align:left;">This Texas breach immediately gets my attention because of the type of data involved. A lot of breach disclosures talk about names, email addresses, phone numbers, and physical addresses being exposed, and honestly, I&#39;ve become a little numb to those at this point because so much of that information is already floating around online. Driver&#39;s licenses and passport data are different. That&#39;s identity theft gold. According to reports, attackers accessed data tied to roughly three million records through a Texas government system used to manage licenses and permits. When you start talking about government-issued identity documents, you&#39;re talking about the exact kind of information criminals need to convincingly impersonate someone in the real world.</p><p class="paragraph" style="text-align:left;">The reason this hits home for me is that I&#39;ve dealt with identity theft myself. In my case, someone created a physical copy of my driver&#39;s license with their photo attached and tried to finance a Corvette in my name. <i>(</i><a class="link" href="https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><i>read more</i></a><i>)</i></p><h3 class="heading" style="text-align:left;" id="i-couldve-rickrolled-the-entire-fif"><a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">I Could&#39;ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2ba9e0e0-ee72-497a-848d-f3c4b1149665/Screenshot_2026-06-18_at_10.44.38_PM.png?t=1781840686"/></div><p class="paragraph" style="text-align:left;">A researcher nearly became the most chaotic villain in sports history. By registering as a FIFA football agent - just uploading your ID to a public portal - you&#39;d get added to FIFA&#39;s Microsoft Entra tenant. From there, while the frontend apps dutifully showed &quot;access denied&quot; pages, the backend APIs didn&#39;t check anything. The Football Data Platform handed over live RTMP stream keys, camera feeds, and full broadcast controls for every World Cup match. They confirmed it was live by pulling a tactical camera feed into VLC. Every match. Every camera angle. One click from killing a live broadcast. (<a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="152-chrome-live-wallpaper-extension"><a class="link" href="http://152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic" target="_blank" rel="noopener noreferrer nofollow"><b>152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9b48041b-2b5f-4aad-a736-396b141c8fd7/Screenshot_2026-06-17_at_5.48.31_PM.png?t=1781732919"/></div><p class="paragraph" style="text-align:left;">Researchers at Socket uncovered a network of 152 Chrome extensions masquerading as anime-themed live wallpapers that collectively accumulated more than 105,000 installs. Under the hood, they were doing far more than changing your browser background. Built from a shared codebase and distributed across dozens of publisher accounts, the extensions generated fraudulent web traffic, manipulated search activity, performed ad fraud, and included anti-forensics techniques designed to make analysis more difficult.</p><p class="paragraph" style="text-align:left;">Chrome extensions are just a thing I’ll never be able to stop talking about. (<a class="link" href="https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="nintendo-third-party-program-hit-by"><b><a class="link" href="https://www.freep.com/story/news/local/michigan/2026/06/17/nintendo-cyberattack-ransom-tinypulse/90588561007/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Nintendo, Third-Party Program Hit By Cyberattack for $2M Ransom</a></b></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/62a254e1-873e-4d08-ba89-0f75549332a1/Screenshot_2026-06-17_at_5.53.14_PM.png?t=1781733202"/></div><p class="paragraph" style="text-align:left;">The interesting part of this story isn&#39;t really Nintendo, but the third-party risk angle. According to reports, a ransomware group is demanding $2 million after compromising TinyPulse, a service Nintendo used for internal employee surveys. The attackers claim to have stolen roughly 859 megabytes of data, including employee names, email addresses, survey responses, bank statements, and W-9 forms. Nintendo says its own systems were not compromised and that no customer financial data was accessed. Instead, the exposure appears limited to information held by the third-party provider, much of which Nintendo says is several years old. (<a class="link" href="https://www.freep.com/story/news/local/michigan/2026/06/17/nintendo-cyberattack-ransom-tinypulse/90588561007/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/248d005f-3f86-44ff-8549-c21ac0f82542/Screenshot_2026-06-18_at_10.40.07_PM.png?t=1781840413"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/841f7413-7ba6-414b-9b55-934fd12cba4b/Screenshot_2026-06-18_at_10.42.45_PM.png?t=1781840620"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/af1937f9-adc1-4cc1-ac43-2d8830833b2f/image.png?t=1781840609"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Vulnerable U | #172</title>
  <description>Mythos and Fable updates, AI agents falling for phishing emails, Iran hacked California water providers, ServiceNow breach, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-172</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-172</guid>
  <pubDate>Fri, 12 Jun 2026 12:48:00 +0000</pubDate>
  <atom:published>2026-06-12T12:48:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ff8ff971-b56b-40bb-9e47-76da04fa274e/vulnu-header-2026-06-12.png?t=1781236059"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Anyone else in full summer brain? Just me because I spent the weekend scuba diving? Let me say this about <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> - the organizers put on a masterclass in throwing an event that balanced great cybersecurity content, heavy hitters from our industry, and camaraderie through diving together. It was an extremely well thought out and planned event that I’ve already committed Vulnerable U to sponsor again next year. Do recommend for the divers or dive curious.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/420952a6-1442-468d-8435-b91fb959bbf8/Screenshot_2026-06-11_at_6.22.34_PM.png?t=1781220186"/><div class="image__source"><span class="image__source_text"><p>Opening Keynote</p></span></div></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc151014-47ab-4628-87f0-477922e7dcf4/Screenshot_2026-06-11_at_6.22.53_PM.png?t=1781220192"/><div class="image__source"><span class="image__source_text"><p>In a ship wreck 60ft below</p></span></div></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: MSRC couldn’t possibly do anything worse this week… oh. <a class="link" href="https://x.com/mattjay/status/2062592867202109747?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Oh ok.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Blink 182 dropping updates on <a class="link" href="https://myspace.com/blink182?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">MySpace</a> - as someone who was a Blink super fan and MySpace power user, it’s a big week for me. They’re teasing a 25 yr anniversary tour.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Meta Built <a class="link" href="https://www.youtube.com/watch?v=A-JKWpICSzE&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">the Dumbest Hack</a> in Instagram History</p><p class="paragraph" style="text-align:left;">🔖 Something I read: I’ve been quoting this blog every day since I read it. Cloudflare’s <a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: what Mythos showed us</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="anthropics-new-model-mythos-on-a-le"><a class="link" href="https://cyberscoop.com/anthropic-claude-fable-5-release-mythos-guardrails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Anthropic’s New Model: Mythos On A Leash</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/391ec7c1-8830-4ebb-bd38-d08a03782607/Screenshot_2026-06-10_at_9.11.21_AM.png?t=1781097100"/></div><p class="paragraph" style="text-align:left;">For all of you who hang out in my live streams, you know I was hitting that MYTHOSSSS (spoken like Star Trek KHANNNN) sound button a ton this week. That’s because it has escaped the lab! Well sort of. Anthropic has now broadly released Fable 5, its public-facing “Mythos-class” model, and the reaction I&#39;m seeing is a mix of excitement, confusion, and frustration. The marketing narrative is still very much that Mythos was so powerful it needed to be carefully contained before being released to the public. </p><p class="paragraph" style="text-align:left;">Meanwhile, the actual experience many people are having is running headfirst into guardrails. In some cases, users report that simply mentioning cybersecurity-related topics is enough to trigger restrictions, model downgrades, or redirects to safer behavior. If Mythos escaped the lab, it appears to have done so while wearing several layers of bubble wrap.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5565f889-7ff5-4246-9c76-ec27452d34f3/Screenshot_2026-06-11_at_10.24.19_PM.png?t=1781234668"/></div><p class="paragraph" style="text-align:left;">What&#39;s becoming clearer is that Anthropic is taking an unusually aggressive approach to controlling how Fable 5 is used. Beyond the cybersecurity restrictions, the company has confirmed that it will actively limit the model&#39;s usefulness for certain frontier AI development tasks. These interventions aren&#39;t always visible to users. Anthropic says it may modify outputs or reduce effectiveness for requests related to building competing frontier models, training infrastructure, or AI acceleration research. At the same time, the company expanded data retention policies around Fable usage, citing safety and compliance requirements. That&#39;s generating almost as much discussion as the model itself.</p><p class="paragraph" style="text-align:left;">My takeaway remains about the same as it was when Mythos launched. I believe the underlying capabilities are real because I&#39;ve talked directly with people involved in Project Glasswing who have seen the model find vulnerabilities and security issues that other tools missed. And exploit/PoC development are definitely boosted. (read more <a class="link" href="https://cyberscoop.com/anthropic-claude-fable-5-release-mythos-guardrails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-claude-fable-5-but-its-available-for-a-limited-time/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, here, here and here)</p><h3 class="heading" style="text-align:left;" id="timetoexploit-is-down-to-one-day-no"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Time-to-exploit is down to one day. Now what?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dfe53be7-5b81-4248-bfc0-ce84964997b9/ASM_report_header.png?t=1778780069"/></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Intruder</a> analyzed 3,000 organizations&#39; attack surfaces. Top finding: more teams should be asking &#39;does this actually need to be on the internet?’</p><p class="paragraph" style="text-align:left;">There’s no better time to ask it. AI can now find zero-days autonomously and time-to-exploit has shrunk to a single day. Anything on the internet that doesn&#39;t need to be is a target the moment a new CVE drops.</p><p class="paragraph" style="text-align:left;">In the report:</p><ul><li><p class="paragraph" style="text-align:left;">What are the most common attack surface exposures?</p></li><li><p class="paragraph" style="text-align:left;">How long are organizations taking to fix them?</p></li><li><p class="paragraph" style="text-align:left;">How does your industry compare?</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Get the report now.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="measuring-ll-ms-impact-on-n-day-exp"><a class="link" href="https://red.anthropic.com/2026/n-days/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Measuring LLMs’ Impact On N-Day Exploits</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b5790303-567c-4671-b3ee-25b672aa7528/Screenshot_2026-06-10_at_8.56.38_AM.png?t=1781096581"/></div><p class="paragraph" style="text-align:left;">Anthropic with some sobering research on how their latest Claude model can automatically weaponize patches. Their most capable model, Mythos Preview, turned 18 recent Firefox security patches into 8 working exploits, with the first one ready in under an hour. On the Windows side, it cranked out 8 full privilege escalation exploits from kernel patches, basically going from low-privilege user to full SYSTEM control for about $2,000 in API credits per exploit.</p><p class="paragraph" style="text-align:left;">This flips the traditional patch gap timeline on its head. Where it used to take expert reverse engineers weeks or months to develop N-day exploits, we&#39;re now looking at hours. WannaCry hit 59 days after the patch was available. Mythos Preview would have had working exploits ready before most organizations even started their patch rollouts. The implications for anything that patches slowly - IoT devices, industrial systems, medical equipment - are pretty grim. (<a class="link" href="https://red.anthropic.com/2026/n-days/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="mini-shai-hulud-miasma-and-hades-wo"><a class="link" href="https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud, Miasma and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/edb5432b-ddc7-4c77-b5e0-c972dbdb2e87/Screenshot_2026-06-10_at_8.07.38_AM.png?t=1781093265"/></div><p class="paragraph" style="text-align:left;">We&#39;ve officially lost the plot on supply-chain attack names. We now have Mini Shai-Hulud, Hades, Miasma, and whatever comes next. Underneath the increasingly ridiculous naming convention, though, there&#39;s a real evolution happening. Socket&#39;s threat research team caught the campaign evolving again, this time with 23 new malicious PyPI packages targeting bioinformatics and MCP developers. These attackers keep switching up their delivery methods - some packages now hide malicious code in compiled native extensions that execute at import time, while others use typosquats like &quot;rsquests&quot; and &quot;tlask&quot; to catch typos. The standout is langchain-core-mcp, which installs a loader that searches your entire sys.path for _index.js payloads, meaning the malicious code doesn&#39;t even need to be in the same package.</p><p class="paragraph" style="text-align:left;">These aren&#39;t just random packages either - they&#39;re targeting real scientific computing tools like embiggen, gpsea, and pyphetools that researchers actually use. Once executed, the JavaScript stealer grabs everything from GitHub tokens to cloud credentials, SSH keys, and Docker configs.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e74a47a5-edd7-4aae-99e0-40c07593da10/Screenshot_2026-06-10_at_8.08.35_AM.png?t=1781093325"/></div><p class="paragraph" style="text-align:left;">The funniest part of this entire report was that the malware includes fake system instructions and policy-triggering text embedded in comments that don&#39;t affect execution at all but appear designed specifically to confuse AI-powered security tools and analyst copilots. The runtime ignores it, but an AI scanner might not. (<a class="link" href="https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="handala-iran-claims-breach-of-calif"><a class="link" href="https://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Handala (Iran) Claims Breach of California Water Service</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0f122830-0447-4664-bdb0-1a1f72d7bba5/image.png?t=1781232388"/></div><p class="paragraph" style="text-align:left;">Handala just hit California Water Service pretty hard, dumping 5GB of customer data and internal credentials as their latest hack. The Iranian group managed to breach both the billing system (grabbing customer PII across multiple districts) and an internal RTKBase GPS correction network that field crews use for precision mapping. They got administrative credentials for the GPS network and essentially mapped out the entire infrastructure across seven service districts.</p><p class="paragraph" style="text-align:left;">This isn&#39;t just a data grab - Handala&#39;s known for escalating to destructive attacks after their initial claims, and they&#39;ve got custom wipers in their toolkit. Same group that hit Stryker medical and wiped everything they could.</p><p class="paragraph" style="text-align:left;">The RTKBase system probably served as their entry point, which makes sense since these GPS correction systems often run on basic hardware with weak authentication. Water utilities everywhere should be checking if their survey equipment is internet-exposed right about now, especially since this fits the pattern of Iranian groups specifically targeting US water infrastructure that we&#39;ve been warned about. (<a class="link" href="https://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="80-of-systems-are-exposed-through-s"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">80% of Systems Are Exposed Through Stale Access. Here&#39;s the Fix.</a>*</h3><p class="paragraph" style="text-align:left;">Stale entitlements create an open door. Opal analyzed real provisioning data across thousands of systems and found 80% exposed through access that was never revoked. When AI agents start requesting infrastructure access at scale, that surface compounds fast. Opal&#39;s 2026 report has the data on what AI-ready teams did differently.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">Read the report.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="shiny-hunters-targets-education-sec"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</a></h3><p class="paragraph" style="text-align:left;">ShinyHunters just pulled off a pretty impressive campaign targeting Oracle PeopleSoft systems with a zero-day exploit (CVE-2026-35273). Between late May and early June, they hit over 100 organizations - mostly universities and colleges - using a critical RCE (9.8 CVSS). They were exploiting this before Oracle even knew about it, making it a proper zero-day until the patch dropped on June 10th.</p><p class="paragraph" style="text-align:left;">These guys set up staging servers with MeshCentral agents disguised as Microsoft Azure services, complete with SSL certs for &quot;azurenetfiles[.]net&quot; to make it look legit. But here&#39;s where it gets sloppy - they left their staging directories wide open, exposing command histories, custom lateral movement scripts, and their bash history showing exactly how they mapped internal networks and exfiltrated data. Mandiant caught wind and started warning potential targets, but some organizations still got breached and had their data posted on the ShinyHunters leak site. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="service-now-customers-hit-by-unauth"><b><a class="link" href="https://thecybersecguru.com/news/servicenow-api-vulnerability-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">ServiceNow Customers Hit by Unauthorized API Access – And the Company Knew for Months</a></b></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/14f25f8d-3484-471e-825c-9e720b3e0696/Screenshot_2026-06-10_at_8.42.49_AM.png?t=1781095374"/></div><p class="paragraph" style="text-align:left;">After days of speculation driven by customer reports on Reddit, ServiceNow disclosed that attackers exploited a vulnerability that could allow an unauthenticated user, under certain circumstances, to gain greater access to customer instances than intended.</p><p class="paragraph" style="text-align:left;">Turns out they had an API endpoint sitting there configured with &#39;requires_authentication=false&#39;. The vulnerable endpoint &#39;/api/now/related_list_edit/create&#39; let unauthenticated users query customer instance data, which could include all sorts of juicy enterprise info like support tickets, employee records, and internal docs. They quietly patched it on June 5th, but not before attackers (or maybe bug bounty researchers) had some fun with it.</p><p class="paragraph" style="text-align:left;">ServiceNow received a confidential bug bounty submission about this exact issue back in April, but didn&#39;t bother fixing it until June when they spotted &quot;anomalous activity.” Now they&#39;re saying it was probably just researchers poking around rather than actual bad guys, but that&#39;s a pretty generous interpretation considering the two-month delay between disclosure and fix. If you&#39;re running ServiceNow, definitely check your logs for requests to that endpoint and maybe rotate any credentials that might&#39;ve been exposed in support tickets. (read more <a class="link" href="https://thecybersecguru.com/news/servicenow-api-vulnerability-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.reddit.com/r/servicenow/comments/1u0c45c/potential_servicenow_breach/?solution=d3a1aa8e1dbc9b98d3a1aa8e1dbc9b98&js_challenge=1&token=7afd7253fec22262ff1c52b1703fe9ec35c03480830a02783c2f761e78c25b82&jsc_orig_r=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="phishing-for-lobsters-how-varonis-t"><a class="link" href="https://www.varonis.com/blog/openclaw-phishing?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Phishing for Lobsters: How Varonis Tricked OpenClaw into Spilling Secrets</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c211d2c0-92a2-49dd-a379-f4282ecd7076/Screenshot_2026-06-10_at_2.35.14_PM.png?t=1781116531"/></div><p class="paragraph" style="text-align:left;">If anyone thought AI agents were going to be immune to phishing attacks, this research should put that idea to rest. The Varonis team connected an OpenClaw agent to Gmail, gave it access to Google Workspace, and told it to monitor and process incoming emails.</p><p class="paragraph" style="text-align:left;">The most brutal example was when a fake &quot;Dan&quot; emailed asking for staging credentials during a supposed production emergency. Pinchy (their agent) not only fell for it but helpfully forwarded AWS keys, database passwords, and SSH access to an external Gmail account. Even their &quot;strict&quot; security configuration failed because the agent prioritized being helpful over verifying who was actually asking. The researchers point out this flips the phishing game - low-effort technical attacks become less effective, but context-heavy spear phishing becomes way more dangerous since every inbox now has an autonomous system trained to retrieve information and act immediately. <i>(</i><a class="link" href="https://www.varonis.com/blog/openclaw-phishing?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow"><i>read more</i></a><i>)</i></p><h3 class="heading" style="text-align:left;" id="new-github-account-ms-nightmare-pos"><a class="link" href="https://github.com/MSNightmare/RoguePlanet?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">New Github Account MSNightmare Posts Windows Defender Exploit With PoC That Works on Windows 11 and 10.</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3c329250-282b-496d-baf2-40ccfd84854b/Screenshot_2026-06-10_at_8.43.46_AM.png?t=1781095863"/></div><p class="paragraph" style="text-align:left;">Another day, another Microsoft Defender zero-day from the prolific researcher &quot;Nightmare Eclipse.&quot; This latest one, dubbed &quot;RoguePlanet,&quot; is a race condition bug that can grant SYSTEM privileges on fully patched Windows 10 and 11 systems. It dropped just hours after Microsoft&#39;s June Patch Tuesday fixed two other flaws from the same researcher. ThreatLocker confirmed it works on the latest builds, though success rates vary depending on the machine.</p><p class="paragraph" style="text-align:left;">The backstory here is getting messy. Nightmare Eclipse originally developed this as a remote code execution exploit targeting Defender&#39;s handling of SMB shares, but Microsoft quietly hardened the system in May, forcing a rewrite down to just local privilege escalation. This is all part of an ongoing feud between the researcher and Microsoft over bug bounty practices and disclosure policies. Microsoft&#39;s been nuking their repositories on GitHub and GitLab, even threatened law enforcement action, so now they&#39;re hosting exploits on their own platform.</p><p class="paragraph" style="text-align:left;">I’m also hearing some chatter that Nightmare Eclipse is an ex-Microsoft insider, so the legal battle might be way more than the public knows. (read more <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://github.com/MSNightmare/RoguePlanet?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/mattjay/status/2064447936428151013?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="expanding-private-cloud-compute"><a class="link" href="https://security.apple.com/blog/expanding-pcc/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Expanding Private Cloud Compute</a></h3><p class="paragraph" style="text-align:left;"><b>Apple</b> announced important info about expanding their Private Cloud Compute beyond their own data centers. They&#39;re now partnering with Google Cloud and NVIDIA to run the more demanding Apple Intelligence workloads while supposedly maintaining their hardcore privacy commitments. The collaboration includes leveraging Google&#39;s Gemini tech to build the next-gen Apple Foundation Models, which is a fascinating shift from Apple&#39;s usual &quot;we do everything ourselves&quot; approach.</p><p class="paragraph" style="text-align:left;">What&#39;s particularly noteworthy is how they&#39;re trying to have their cake and eat it too - running AI workloads on third-party infrastructure while claiming the same security guarantees as their own silicon. They&#39;re using NVIDIA&#39;s Confidential Computing, Intel TDX, and Google&#39;s Titan chips as the foundation, but they&#39;re adamant that Apple retains complete control over the PCC software stack. The real test will be whether their transparency promises hold up - they say they&#39;ll publish binaries for public inspection and maintain their security research program. Color me curious to see how this plays out in practice. (<a class="link" href="https://security.apple.com/blog/expanding-pcc/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0377700f-9f33-4327-9934-0c5159a74398/Screenshot_2026-06-11_at_9.50.22_PM.png?t=1781232626"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6069714d-d7ef-42ad-88b5-19afc09c6a23/Screenshot_2026-06-11_at_9.51.08_PM.png?t=1781232672"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/201427aa-9bec-4530-9370-219381db2e12/Screenshot_2026-06-11_at_9.49.51_PM.png?t=1781232597"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Vulnerable U | #171</title>
  <description>Meta&#39;s AI disaster, Whitehouse executive order on AI security, more npm worms, and more publicly disclosed vulns from researchers</description>
  <link>https://www.vulnu.com/p/vulnerable-u-171</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-171</guid>
  <pubDate>Fri, 05 Jun 2026 12:33:00 +0000</pubDate>
  <atom:published>2026-06-05T12:33:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d74b9f20-dce4-4411-a531-3dfdf3d594e8/Newsletter_Header.png?t=1780588280"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59b46fed-5055-4701-8bb3-f5338a8bb0ab/Newsletter_Sponsor_Logo.png?t=1770828619"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing you from a balcony in Grand Cayman. What started as a little newsletter I made to get back into content creation after leaving my tour in big finance where it wasn’t allowed has really turned into something crazier than I anticipated. Vulnerable U was just a way for me to blog again and talk about current events and things I was passionate about like mental health, personal development, and helping security practitioners be the best they can be.</p><p class="paragraph" style="text-align:left;">Now I’m here giving a keynote at a <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">conference abroad</a> with our logo all over the place as one of the sponsors. Just really grateful in this moment that I can employ a team and support the industry all based on what started right here. Literally in this text box.</p><p class="paragraph" style="text-align:left;">The other lesson here is - you can just do things. I didn’t ask anyone’s permission to start this, nor did I wait for someone to tell me it was a good idea. I just started 171 weeks ago and haven’t stopped. What do you think if you did for 171 weeks straight would change in your life? I don’t want to be some bullshit lifestyle influencer, but it is hard to not have that reflection in this moment. Thanks for indulging the cringe and honestly we should all lean into a little cringe from time to time.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a8bc103d-8b10-4b44-8512-f63067c7d021/Screenshot_2026-06-04_at_11.17.59_AM.png?t=1780589913"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/110e96d0-2f6a-42c5-ad41-069ccb55110c/Screenshot_2026-06-04_at_11.18.19_AM.png?t=1780589922"/></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Been working hard for the last few weeks getting PADI <a class="link" href="https://x.com/mattjay/status/2061213603286466683?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">scuba certified.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Maybe we were <a class="link" href="https://www.youtube.com/watch?v=SUDrFXFV-6U&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">wrong</a> - Primeagen</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Microsoft is threatening <a class="link" href="https://www.youtube.com/watch?v=ySAhFmMU534&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">researchers</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Jen Easterly’s take on the <a class="link" href="https://www.nytimes.com/2026/06/04/opinion/trump-ai-executive-order-cybersecurity.html?unlocked_article_code=1.nlA.ytKq.Szq8bpMgzWwM&smid=nytcore-ios-share&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">AI executive order</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="hackers-used-metas-ai-support-bot-t"><a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/A-JKWpICSzE" width="100%"></iframe><p class="paragraph" style="text-align:left;">What could possibly go wrong when you give an AI help desk chatbot write access over everyone&#39;s account, including password reset functions? Apparently …everything! Over the last few days, Instagram was vulnerable to a remarkably simple attack where people could convince Meta&#39;s AI support assistant to send password reset information to a brand-new email address that wasn&#39;t associated with the account at all. This wasn&#39;t some advanced AI jailbreak or cutting-edge hacking technique. The AI was just being helpful in exactly the wrong way.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b1906b86-61c4-4884-a097-2af06bf99660/Screenshot_2026-06-03_at_2.43.33_PM.png?t=1780512220"/><div class="image__source"><span class="image__source_text"><p>Source: <a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">KrebsOnSecurity</a></p></span></div></div><p class="paragraph" style="text-align:left;">The attack itself was almost laughably simple. Attackers connected to a VPN in roughly the same geographic region as the account owner, opened a chat with the AI support system, claimed they had lost access to their account, and asked for verification information to be sent to a new email address. In many cases, the AI simply complied. Some attackers even used anonymous one-time email services and still received account recovery codes. Once they had access, they followed a well-rehearsed playbook: reset the password, terminate active sessions, delete backup codes, and take complete ownership of the account. (<a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ai-will-make-every-asset-a-potentia"><a class="link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow">AI will make every asset a potential zero-day target. Are you ready?</a>*</h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c9f16811-cb24-44be-8074-d0c42d168e64/em-header-cropped.png?t=1780434368"/></div><p class="paragraph" style="text-align:left;">The AI-attack era has arrived. Thousands of zero-days in the pipeline. Target-specific exploits generated in minutes. Unattributed, one-off attacks that bypass detection - while your dashboard stays green.</p><p class="paragraph" style="text-align:left;"><b>runZero</b> is built for this reality. Know every asset on your attack surface, uncover every exposure, map every attack path, and validate your segmentation - before the exploit drops. We deliver deep intelligence across IT, OT, IoT, cloud, and mobile, so defenders can win by default. Even against AI.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow">Try It Free Today</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="ai-agents-are-now-undoing-security-"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://www.youtube.com/shorts/5E4ef29yfM8?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">AI Agents Are Now Undoing Security Protections They Run Into That They Don’t Like</a></span></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/5E4ef29yfM8" width="100%"></iframe><p class="paragraph" style="text-align:left;">This AI agent found a security protection that was put in place to make sure that it didn&#39;t install malware and it turned it off. If you guys have seen any of my videos on all of the NPM worms, PyPy worms, all the giant malware that&#39;s going around right now in the software supply chain, one of the main recommendations for people is to set your minimum release age to seven days. Give all the packages that show up on npm a bit of time for the security community to find the malware. Then you download it a few days later to catch any updates for any security bugs that might be in the software.</p><p class="paragraph" style="text-align:left;">Well, this is a screenshot from Cursor, which is an AI coding IDE, which said, &#39;Hey, by the way, I noticed that your pnpm policy has got this minimum release age thing set to seven days, which is too slow in my personal AI agent expert opinion. You&#39;re missing super useful features at speed. So I went ahead and set that back to zero.” Uh, you did... What? </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a9a18f14-ee56-4c05-9153-4f6a39a3fa14/Screenshot_2026-06-03_at_2.02.47_PM.png?t=1780509820"/></div><h3 class="heading" style="text-align:left;" id="chinese-spies-are-using-linked-in-t"><a class="link" href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Chinese spies are using LinkedIn to lure Westerners into sharing sensitive information</a></h3><p class="paragraph" style="text-align:left;">Five Eyes intelligence agencies are sounding the alarm about a pretty slick Chinese recruitment operation that&#39;s been going after government and military personnel through fake job postings. Chinese military intelligence is basically running a catfish scheme on LinkedIn, Indeed, and Upwork - posing as HR reps from legit-looking consultancies and think tanks to lure people with security clearances. They&#39;re not just going after the obvious targets either; academics, journalists, and anyone with even peripheral access to government info are fair game.</p><p class="paragraph" style="text-align:left;">The playbook is methodical: start with a normal-looking job ad, conduct virtual interviews while probing for access levels, then gradually escalate from &quot;write us a harmless report on China&#39;s bilateral relations&quot; to &quot;hey, can you share some classified stuff?&quot; They&#39;re paying anywhere from hundreds to thousands per report through PayPal, crypto, and other platforms. What&#39;s particularly crafty is how they eventually move conversations to encrypted messaging apps once they&#39;ve got someone hooked. If you&#39;ve got a clearance and you&#39;re getting unsolicited job offers that seem too good to be true, they probably are. (<a class="link" href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="white-house-executive-order-promoti"><a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_campaign=unsupervised-learning-no-531&utm_medium=referral&utm_source=newsletter.danielmiessler.com" target="_blank" rel="noopener noreferrer nofollow">WhiteHouse: Executive Order - PROMOTING ADVANCED ARTIFICIAL INTELLIGENCE INNOVATION AND SECURITY</a></h3><p class="paragraph" style="text-align:left;">Trump dropped a new executive order on AI cybersecurity that&#39;s got some interesting moves. The big theme is &quot;America First&quot; AI dominance while ditching what he calls the &quot;bureaucratic constraints&quot; from the previous administration. Key highlights include setting up an AI cybersecurity clearinghouse run by Treasury, expanding the Tech Force hiring pipeline, and creating a voluntary framework where AI companies can get their frontier models assessed by NSA before release.<br><br>What&#39;s catching attention is the &quot;covered frontier models&quot; classification system - basically a way to flag advanced AI systems that could have serious cyber capabilities. Companies can voluntarily submit their models for a 30-day government review before release, but notably there&#39;s explicit language saying this isn&#39;t creating a mandatory licensing system. (<a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_campaign=unsupervised-learning-no-531&utm_medium=referral&utm_source=newsletter.danielmiessler.com" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="the-attackers-playbook-has-changed-"><a class="link" href="https://hubs.ly/Q04k14HH0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">The attacker&#39;s playbook has changed. Do we even stand a chance?</a>*</h3><p class="paragraph" style="text-align:left;">Data breaches don&#39;t start with malware, they start with trust. Varonis Threat Labs mapped how attackers are exploiting identity, AI, and cloud workflows at every stage of the kill chain, from Cookie-Bite MFA bypasses to AI copilots leaking sensitive data with a single prompt. If you&#39;re defending modern infrastructure, take a look to understand how threats are actually getting in. (<a class="link" href="https://hubs.ly/Q04k14HH0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="new-iron-worm-malware-hits-36-packa"><a class="link" href="https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">New IronWorm malware hits 36 packages in npm supply-chain attack</a></h3><p class="paragraph" style="text-align:left;">Another day, another npm supply-chain attack. This time it&#39;s IronWorm, a Rust-based infostealer that managed to hit 36 packages before getting squashed. The malware hides behind an eBPF rootkit, phones home over Tor, and targets things you’d expect, OpenAI keys, AWS creds, and SSH keys. It self-propagates by stealing npm publishing credentials and then pushing out trojanized versions of packages.</p><p class="paragraph" style="text-align:left;">The attack started from a compromised account called &#39;asteroiddao&#39; and has some similarities to the Shai Hulud malware we&#39;ve seen before. It uses GitHub Actions as a data exfiltration method - it disguises stolen secrets as innocent build artifacts that anyone with access can download. The good news is that security folks caught this one early before it could spread to more popular packages. (<a class="link" href="https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="como-do-s-exploiting-a-remote-kerne"><a class="link" href="https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security</a></h3><p class="paragraph" style="text-align:left;">Marcus Hutchins is also on the “responsible disclosure requires a responisble vendor” train and is releasing some zero day publicly after the report he submitted multiple times was ghosted.</p><p class="paragraph" style="text-align:left;">He found a remote kernel vulnerability that lets you crash any system running Comodo&#39;s firewall with a single IPv6 packet - and it works even if the firewall blocks everything because the bug happens during packet parsing, before any rules kick in.<br><br>The bug is an integer underflow in the IPv6 extension header parser that doesn&#39;t validate the payload length field. While there&#39;s potential for out-of-bounds read and write primitives, Marcus thinks RCE is unlikely due to various constraints. They have no bug bounty program, so here we are with a public zero-day because vendors gonna vendor. He&#39;s provided a PoC so people can test if they&#39;re vulnerable. (<a class="link" href="https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="gemini-voice-assistant-hijacked-via"><a class="link" href="https://www.securityweek.com/gemini-voice-assistant-hijacked-via-messaging-notifications/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Gemini Voice Assistant Hijacked via Messaging Notifications</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a25ddec1-e2b6-44de-87bf-24104371c0aa/image.png?t=1780627038"/></div><p class="paragraph" style="text-align:left;">Researchers managed to trick Google Gemini through everyday notifications. They figured out a way to inject malicious prompts through WhatsApp, Slack, SMS, and pretty much any messaging app that sends push notifications. They’re calling this technique &quot;Fake Context Alignment,” where they hide malicious instructions in foreign languages or muted hyperlinks, so when you think you&#39;re just saying &quot;yes&quot; to end a conversation, you&#39;re actually authorizing Gemini to open your smart home windows or start a Zoom call streaming your video.</p><p class="paragraph" style="text-align:left;">The researchers could fake messages from trusted contacts without even knowing their names beforehand - just grab whatever name pops up in your notifications and attribute their malicious message to them. They also managed to poison Gemini&#39;s long-term memory for persistent access across all your devices. Google&#39;s already patched these issues after the disclosure. But boy are us AppSec nerds loving everyone learning about untrusted input sources all over again as AI agents seem to just read prompts from anywhere. XSS who? (<a class="link" href="https://www.securityweek.com/gemini-voice-assistant-hijacked-via-messaging-notifications/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-spied-on-a-stock-exchange-e"><a class="link" href="https://www.security.com/threat-intelligence/stock-exchange-espionage?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Hackers Spied on a Stock Exchange Executive&#39;s Outlook Mailbox for Five Months</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/51876881-abda-41fd-a272-7338f9e8449d/image.png?t=1780627060"/></div><p class="paragraph" style="text-align:left;">Someone just spent five months methodically stealing a stock exchange executive&#39;s entire email history, and honestly, it&#39;s impressive how patient and disciplined they were. The attackers used a custom tool built around Aspose (a legitimate .NET library) to slice Outlook OST files into bite-sized chunks, then exfiltrated everything through Dropbox and OneDrive Personal to blend in with normal cloud traffic. They grabbed emails incrementally over two-to-four-week windows, making sure not to trigger any alarms with massive data transfers.</p><p class="paragraph" style="text-align:left;">The opsec was pretty solid too - they masqueraded their tools as Adobe and OneDrive services, used scheduled tasks that looked like Lenovo health checks, and even switched to hard-coded Microsoft IPs instead of hostnames to avoid DNS logging. Five months of dwell time is serious commitment for what was essentially a glorified email theft operation. No attribution yet since they stuck to public tools and legitimate cloud services, but for an exchange executive&#39;s mailbox full of market-moving intel, someone clearly thought it was worth the long game. (<a class="link" href="https://www.security.com/threat-intelligence/stock-exchange-espionage?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="researcher-publishes-git-hub-tokens"><a class="link" href="https://therecord.media/researcher-publishes-github-token-stealing-exploit-microsoft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process</a></h3><p class="paragraph" style="text-align:left;">Here we go again with Microsoft and security researchers butting heads. Ammar Askar just dropped a working VS Code exploit that can steal GitHub tokens with a single click, and he intentionally bypassed Microsoft&#39;s disclosure process to do it. His beef is that Microsoft apparently &quot;silently&quot; fixed a previous bug he reported without giving him credit and claimed it had no security impact. So now he&#39;s going full public disclosure on VS Code bugs.<br><br>The attack is to craft a malicious Jupyter notebook, victim clicks the link to open it in github.dev, and hidden code simulates keystrokes to install a rogue extension that exfiltrates their GitHub token. That token gives full read/write access to everything they can touch, private repos included.</p><p class="paragraph" style="text-align:left;">This is getting spicy because it&#39;s part of a bigger trend where researchers are fed up with Microsoft&#39;s vulnerability handling. The timing is interesting to me since this comes right after TeamPCP breached thousands of GitHub repos through a poisoned VS Code extension. Hard to blame them for getting frustrated with being ignored. (<a class="link" href="https://therecord.media/researcher-publishes-github-token-stealing-exploit-microsoft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="google-adds-android-protection-agai"><a class="link" href="https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Google adds Android protection against AI deepfake scam calls</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7c4f93d6-baef-49be-a9b9-d54670fbf469/Screenshot_2026-06-04_at_1.46.13_PM.png?t=1780598787"/></div><p class="paragraph" style="text-align:left;">Google&#39;s rolling out a solution to the growing deepfake voice scam problem. Their new &quot;fake call detection&quot; feature for Android 12+ devices works by having the caller&#39;s phone send a silent, encrypted confirmation signal to the recipient. If that signal doesn&#39;t show up, your phone automatically pings your actual contact to ask &quot;hey, are you calling me right now?&quot; If they say no, you get a warning to hang up immediately.</p><p class="paragraph" style="text-align:left;">Impersonation scams hit $2.95 billion in losses last year alone. The feature only works if both people are using Phone by Google with RCS enabled, so adoption might be the real challenge here. I like that instead of trying to detect if a voice sounds fake, they&#39;re just verifying the call is actually coming from where it claims to be. Smart move, especially as AI voice cloning gets cheaper and more convincing. (<a class="link" href="https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="kali-365-operator-expands-operation"><a class="link" href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Kali365 Operator Expands Operation</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/50b747fd-0a08-49e5-8f52-972722564cbb/image.png?t=1780599029"/></div><p class="paragraph" style="text-align:left;">What started as a Microsoft 365-focused credential stealer has now expanded to target AWS, Okta, Xerox DocuShare, and some interesting Russian platforms including MAX Messenger - a state-backed messaging service with 80 million users. The kit specializes in device code phishing, which is where they trick you into entering a legitimate OAuth code on a real login page, completely bypassing your MFA in the process.</p><p class="paragraph" style="text-align:left;">Arctic Wolf recently tracked down 126 active malicious hosts all serving the same Kali365 kit between early and late May. They&#39;re impersonating everything from Microsoft Outlook to German email providers to major Russian services like Mail[.]ru and Yandex. It&#39;s part of a bigger trend with at least 14 different device code phishing kits floating around now. (<a class="link" href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="anthropic-expanding-access-to-proje"><a class="link" href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Anthropic expanding access to Project Glasswing</a></h3><p class="paragraph" style="text-align:left;">Anthropic&#39;s Claude Mythos Preview model is absolutely tearing through codebases right now. Since launching Project Glasswing in April, this thing has surfaced over 10,000 high or critical software vulnerabilities. They&#39;re now expanding access to about 150 more organizations across critical infrastructure sectors - power, water, healthcare, the works. Cloudflare alone found 2,000 bugs using it, including 400 rated high or critical, with better accuracy than human testers.</p><p class="paragraph" style="text-align:left;">Now we’ve got a human bottleneck of actually fixing everything. Mozilla found 271 vulnerabilities in Firefox 150, which is 10x more than previous versions using earlier models. The broader concern is that we&#39;re heading into a world where AI can find bugs faster than defenders can patch them, potentially giving attackers the upper hand. Anthropic&#39;s keeping Mythos locked down for obvious reasons, but they did release a public version called Claude Security that&#39;s already helped patch over 2,100 vulnerabilities in three weeks. (<a class="link" href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="attackers-are-exploiting-palo-alto-"><a class="link" href="https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Attackers are exploiting Palo Alto Networks defect that initially flew under the radar</a></h3><p class="paragraph" style="text-align:left;">Here&#39;s a fun lesson in how vulnerability ratings can age like milk. Palo Alto Networks dropped CVE-2026-0257 as a &quot;medium&quot; severity bug on May 13, but by the time Rapid7 spotted active exploitation just four days later, it got the full critical upgrade treatment. CISA quickly tossed it onto the KEV.</p><p class="paragraph" style="text-align:left;">The exploit itself is simple - just forge an authentication cookie using the device&#39;s own TLS certificate and boom, you&#39;ve got VPN access with a single HTTP request. Multiple threat groups are already swarming this opportunity, with Rapid7 tracking waves of attacks hitting their customers. A quote from the Rapid7 research sums it up well:</p><p class="paragraph" style="text-align:left;">“The implication here is that anyone who knows the public key for the certificate used by the authentication override feature to encrypt and decrypt cookies, can successfully forge and encrypt an arbitrary authentication override cookie. The question then becomes, how does an attacker learn the correct public key to use in this attack?</p><p class="paragraph" style="text-align:left;">This brings us back to the vendor&#39;s advisory where they state “do not reuse the portal or gateway certificate, and do not share this certificate with other features or users”.</p><p class="paragraph" style="text-align:left;">If a GlobalProtect portal or gateway has reused the certificate for encrypting and decrypting cookies with another feature, such as the HTTPS service of the portal or gateway, then a remote unauthenticated attacker can discover the public key for that certificate.” (<a class="link" href="https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="preinstall-to-persistence-inside-th"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign</a></h3><p class="paragraph" style="text-align:left;">Microsoft with a good deep dive on &quot;Miasma,&quot; the latest npm supply chain attack that hit 32 Red Hat Cloud Services packages. The attackers compromised the upstream CI/CD pipeline and used legitimate GitHub Actions OIDC workflows to publish trojanized packages with authentic provenance signatures - making malware look officially blessed. The attack triggered automatically during npm install via preinstall hooks, then downloaded the Bun JavaScript runtime and executed a heavily obfuscated 4.29MB payload that could steal credentials from pretty much everywhere: GitHub, AWS, Azure, GCP, HashiCorp Vault, you name it.</p><p class="paragraph" style="text-align:left;">Once it steals your npm tokens, it republishes poisoned packages under your name with forged SLSA provenance to keep the cycle going. The malware even scrapes GitHub Actions runner memory directly to bypass secret masking and can escalate privileges using passwordless sudo. Oh, and there&#39;s a fun destructive tripwire: if you mess with their planted decoy token, it tries to nuke your home directory with <code>rm -rf ~/</code>. &quot;if we can&#39;t have it, nobody can.” (<a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9b4fc23b-f17b-41b4-af10-0abc27bbc20a/Screenshot_2026-06-04_at_9.44.17_PM.png?t=1780627467"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6904e902-1170-4932-b661-dcb02854a1e9/Screenshot_2026-06-04_at_9.42.39_PM.png?t=1780627367"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cc9348a5-3b34-4cb8-8ae5-0c47cb84c1c3/Screenshot_2026-06-04_at_9.50.06_PM.png?t=1780627815"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #170</title>
  <description>Microsoft kicked the hornets nest, Mythos be Mythosing, FBI warnings about in person social engineering, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-170</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-170</guid>
  <pubDate>Fri, 29 May 2026 12:34:00 +0000</pubDate>
  <atom:published>2026-05-29T12:34:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>5 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/027e7ef1-cc5b-48ba-9fd8-d539235b441a/Newsletter_Header.png?t=1780035437"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fb894d06-d0ac-4af7-9ffd-55fcff5d4c13/Newsletter_Sponsor_Logo.png?t=1780035445"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">What a week! Opus 4.8 dropped. Microsoft pissed off the entire security community. Malware keeps malware-ing. Mythos is out there hacking the planet. And here we are. Clocking in for our shift at the vuln mines.</p><p class="paragraph" style="text-align:left;">I’m giving that keynote in the Caymans next week, so let me know if you have any shady offshore finance stuff you need done.</p><p class="paragraph" style="text-align:left;">Lets get to it.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: <a class="link" href="https://x.com/mattjay/status/2059697237496565943?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Why I’m worried</a> about AI agents downloading malicious packages</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Whats that? <a class="link" href="https://www.youtube.com/watch?v=gJNsCRT8NQk&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">I started a podcast with LowLevel?</a> But of course we did. Now found in a podcast store near you.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: What the hell is going on <a class="link" href="https://www.youtube.com/watch?v=AUEB2GMU8t4&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">at CISA?</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: <a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Cloudflare’s Mythos write up</a> is a very solid read with good lessons learned.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="microsoft-calling-security-research"><a class="link" href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Microsoft calling security researchers criminals for public disclosure</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4fe50ea5-0bbb-4dfd-880a-b19c222d15d1/image.png?t=1780004821"/><div class="image__source"><span class="image__source_text"><p>source: <a class="link" href="https://x.com/vxunderground/status/2060036224245432506?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">https://x.com/vxunderground/status/2060036224245432506</a></p></span></div></div><p class="paragraph" style="text-align:left;">This got me riled up today on stream. I recorded a YouTube video about it, will be out soon. But Microsoft got a big nostalgic about the early 2000s and is now threatening legal action against security researchers again. The community has absolutely exploded with stories of their nightmare experiences trying to work through the “responsible” disclosure processes. The pattern is clear - they are slow, non communicative, and consistently downplay security vulnerabilities, not rewarding researchers, not crediting researchers, and then fixing the vulns anyway.</p><p class="paragraph" style="text-align:left;">Casey Ellis (founder of Bugcrowd) wrote recently about this on an unrelated public disclosure issue with Citrix, but he captures the whole thing we’re talking about this week beautifully. I consider this required reading: <a class="link" href="https://cje.io/2026/05/17/coordinated-until-it-isnt/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Coordinated, Until It Isn&#39;t</a></p><p class="paragraph" style="text-align:left;">As he states, the “responsible” disclosure social contract is that the vendor is also responsible/responsive. If the vendor isn’t holding up their end of the bargain, full disclosure is the agreed upon path. This is to keep the asymmetry of power and legal consequences a <i>bit</i> more balanced and holding vendors accountable. The real goal at the end of the day is a more secure internet, not for the vendor to have the cheapest and least embarassing vulnerability patching lifecycle possible. If you ostracize and threaten security research, we end up with a less secure internet as more talent will refuse to work with you.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58eca334-d0ea-4f36-b14f-5c840a4edd01/Screenshot_2026-05-28_at_4.52.28_PM.png?t=1780005151"/></div><p class="paragraph" style="text-align:left;">As their own CEO said. The answer is clear, Do security. Threatening researchers isn’t doing security. (<a class="link" href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="you-cant-secure-ai-if-you-cant-see-"><a class="link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">You can’t secure AI if you can’t see what’s running.</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/342000a5-989d-4613-9936-c3c27e0a4fb0/1200_x_670.png?t=1779904967"/></div><p class="paragraph" style="text-align:left;"><b>Oligo</b> ran the runtime telemetry on what&#39;s actually executing inside production AI stacks, not what&#39;s sitting in a requirements.txt. It&#39;s the most data-driven look at the AI runtime landscape I&#39;ve seen this year, and one number in it reframes a lot of the vendor noise from the last 18 months.</p><p class="paragraph" style="text-align:left;">No company in their dataset runs Anthropic without also running OpenAI. Not one. 36% have both installed. Zero go Anthropic-only.</p><p class="paragraph" style="text-align:left;">Every &quot;OpenAI killer&quot; take assumed companies would switch. What the runtime shows is that nobody switches. They add Anthropic as a secondary, usually for specific tasks (long context, code, certain reasoning jobs), while OpenAI stays as the default. The full dataset has more numbers like this one. Grab the full report now.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">Read the 2026 AI Runtime Report</a>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="hackers-are-trying-to-steal-signal-"><a class="link" href="https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Hackers are trying to steal Signal users’ backups in new wave of phishing attacks</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8e969cf0-b091-4276-8132-9e18347fc72b/image.png?t=1780006783"/><div class="image__source"><span class="image__source_text"><p>source: <a class="link" href="https://x.com/joshrogin/status/2059634806648930614?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">https://x.com/joshrogin/status/2059634806648930614</a></p></span></div></div><p class="paragraph" style="text-align:left;">Signal users are getting hit with a new phishing scam where hackers pose as Signal support claiming their backups are about to vanish due to a &quot;sync issue.&quot; The fake support messages ask users to hand over their recovery keys to &quot;save&quot; their chat history - which …is what you shouldn&#39;t do. Josh Rogin from the Washington Post flagged this after anti-CCP activists started getting targeted, though it looks like the campaign might be casting a wider net based on reports from Access Now&#39;s security folks.</p><p class="paragraph" style="text-align:left;">Interesting that this is going after Signal&#39;s relatively new Secure Backups feature, which lets you store encrypted chat history on Signal&#39;s servers. Previous Signal phishing attempts usually tried to hijack accounts outright, but this approach is a bit more surgical - if they get your recovery key, they can decrypt all your old messages, photos, and documents. Signal will never message you first and definitely won&#39;t ask for your PIN or recovery keys. <b>If you see a &quot;Signal Support&quot; chat pop up, it&#39;s not them.</b> (<a class="link" href="https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="apple-open-sources-quantum-proof-en"><a class="link" href="https://security.apple.com/blog/formal-verification-corecrypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Apple open sources quantum proof encryption code</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/55fcbbe9-160a-41b0-9b7f-36c4789092ea/Screenshot_2026-05-28_at_4.58.28_PM.png?t=1780005525"/></div><p class="paragraph" style="text-align:left;">Apple just open-sourced their quantum-resistant crypto implementation for <a class="link" href="https://github.com/apple/corecrypto?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">corecrypto</a> along with the formal verification tools they built to mathematically prove it&#39;s correct. This isn&#39;t your typical &quot;trust us, we tested it&quot; approach. They literally used mathematical proofs to verify their ML-KEM and ML-DSA implementations work exactly as the FIPS specs intended, covering over 2.5 billion devices.</p><p class="paragraph" style="text-align:left;">Their formal verification process caught a nasty bug that traditional testing missed. There was a missing step in the ML-DSA code that would have silently broken digital signatures - meaning iMessage users could have thought their messages were authenticated when they actually weren&#39;t. Apple&#39;s releasing their Cryptol-to-Isabelle translator and verification methodology, which should be a goldmine for other developers working on post-quantum crypto. (<a class="link" href="https://security.apple.com/blog/formal-verification-corecrypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="dbir-exploitation-is-now-31-of-brea"><a class="link" href="https://research.empiricalsecurity.com/research/dbir-confirms-the-new-bottleneck-in-security?utm_source=influencer&utm_medium=newsletter&utm_campaign=dbir" target="_blank" rel="noopener noreferrer nofollow">DBIR: Exploitation is now 31% of breaches. Prioritization is the bottleneck</a>.*</h3><p class="paragraph" style="text-align:left;">The 2026 data breach investigations report shows that exploitation is now 31% of breaches, median time to full remediation rose to 43 days, and 184 million known exploited vulnerability instances sat open past day 28. </p><p class="paragraph" style="text-align:left;">Discovery is cheaper and faster than ever, but picking what to fix is getting harder. <b>Empirical Security</b> builds local predictive models that tell your team which vulns actually matter in your environment. (<a class="link" href="https://research.empiricalsecurity.com/research/dbir-confirms-the-new-bottleneck-in-security?utm_source=influencer&utm_medium=newsletter&utm_campaign=dbir" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="project-glasswing-an-initial-update"><a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: An initial update</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58983925-c844-41e1-9ecd-65fbdbb55ed3/image.png?t=1780011952"/></div><p class="paragraph" style="text-align:left;">Anthropic with their initial Project Glasswing update. Of course, please read this through their is marketing mixed in lens - but good data to stay on top of. Their Mythos model has been going through open-source code for six months and found over 23,000 vulnerabilities across more than 1,000 projects. Over 6,000 of these are high or critical severity bugs, with about 1,500 confirmed as legitimate issues. Only 100 have been patched so far, which gives you an idea of the scale we&#39;re dealing with.</p><p class="paragraph" style="text-align:left;">While big players like Mozilla, Cloudflare, and various government agencies are lining up for access to scan their own stuff, the open-source maintainer community is getting absolutely swamped. Bug bounty programs are either shutting down or banning AI-generated reports entirely because sorting through the flood of automated submissions is becoming impossible. Some maintainers are literally asking Anthropic to slow down because they can&#39;t keep up with the flood of legitimate bug reports. (<a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="vulnerability-in-popular-conference"><a class="link" href="https://www.securityweek.com/vulnerability-in-popular-conference-software-granted-attackers-a-100-talk-acceptance-rate/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/872a23b8-d576-4057-bb78-9ce6155b8f13/image.png?t=1780005222"/></div><p class="paragraph" style="text-align:left;">Conference organizers, you might want to check your Pretalx installations. Novee Security found a stored XSS (CVE-2026-41241) that let attackers plant malicious code in talk submissions that would execute the moment an organizer searched for their proposal. The clever bit was chaining together legitimate platform features - file uploads and search display - to bypass both the platform&#39;s security and browser protections.</p><p class="paragraph" style="text-align:left;">Submit booby-trapped talk proposals to multiple conferences, stuff the titles with common search terms, then wait for organizers to search and get their accounts automatically compromised. With some automation, you could theoretically achieve a 100% talk acceptance rate across every Pretalx-powered conference. The vulnerability&#39;s been patched, but is a funny one. (<a class="link" href="https://www.securityweek.com/vulnerability-in-popular-conference-software-granted-attackers-a-100-talk-acceptance-rate/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="crowd-strike-disrupts-glassworm-bot"><a class="link" href="https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain</a></h3><p class="paragraph" style="text-align:left;">CrowdStrike just pulled off a takedown of the Glassworm botnet, working with Google and Shadowserver to simultaneously nuke four servers that were keeping this supply chain nightmare running. These Russian-linked attackers have been having a field day since early 2025, poisoning hundreds of open source packages including VSCode extensions, npm modules, and over 300 GitHub repos. Their whole game was infiltrating developer workflows to push malware downstream through the supply chain. (and no, this isn’t TeamPCP. Yet Another Supply Chain Nightmare ^ TM)</p><p class="paragraph" style="text-align:left;">They were using everything from the Solana blockchain to BitTorrent to Google Calendar to keep their C2 resilient. CrowdStrike&#39;s approach here is interesting - instead of waiting around for lengthy legal processes (good luck extraditing Russians), they went straight for the infrastructure. The idea is to make the attackers burn time and resources rebuilding rather than targeting new victims. (<a class="link" href="https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fbi-warns-extortion-hackers-are-vis"><a class="link" href="https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">FBI warns extortion hackers are visiting US law firms to steal data</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/389ae98c-74a3-4789-9268-53a9f8b1b358/Screenshot_2026-05-28_at_4.54.05_PM.png?t=1780005284"/></div><p class="paragraph" style="text-align:left;">The FBI is warning about Silent Ransom Group, a crew tied to the old Conti ransomware gang that&#39;s been hassling U.S. law firms since 2023. These guys are getting creative with their social engineering - they&#39;re not just sticking to phishing emails and fake IT support calls anymore. They&#39;re actually showing up at offices pretending to be IT folks who need to &quot;backup&quot; or &quot;image&quot; devices for security reasons, then copying data onto USB drives or external storage. Feels like I’m reading a Kevin Mitnick story from the 90s.</p><p class="paragraph" style="text-align:left;">They use legitimate remote management tools that IT departments already have, and exfiltrate data through trusted platforms like Google Drive and OneDrive. Law firms are prime targets to access sensitive legal, financial, and corporate information. The fact that they&#39;re willing to physically show up at offices was worth the callout here. I want to see the security cam footage of them coming in to do “backups.” (<a class="link" href="https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="iranian-intelligence-service-behind"><a class="link" href="https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Iranian intelligence service behind hack of LA transit system, researchers say</a></h3><p class="paragraph" style="text-align:left;">Turns out that March hack of LA Metro wasn&#39;t just some random hacktivist crew after all. Israeli researchers at Gambit Security traced &quot;Ababil of Minab&quot; back to Iran&#39;s Ministry of Intelligence (MOIS), despite the group&#39;s claims of being independent Palestine supporters. The attackers didn&#39;t just steal data - they went full scorched earth, wiping databases, virtual machines, and storage volumes using both automated scripts and manual keyboard work to maximize destruction and prevent recovery.</p><p class="paragraph" style="text-align:left;">What&#39;s particularly concerning is the speed and scale these guys operated at. They hit multiple other targets including Israeli media orgs, a Turkish insurance firm, and various websites across different sectors. The researchers are warning that this kind of &quot;straight to the recovery layer&quot; attack strategy is becoming easier to execute as AI tools lower the technical barriers. It&#39;s the same playbook we saw with Handala&#39;s devastating Stryker attack - another MOIS-linked group masquerading as hacktivists. The takeaway? Iran&#39;s getting better at both the technical execution and the cover stories.<br>(<a class="link" href="https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2c778dd2-e573-4df8-bece-d2df9ecc8b60/Screenshot_2026-05-28_at_6.54.08_PM.png?t=1780012451"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/65a3e06a-4343-4799-a38b-2363ddf7ec19/image.png?t=1780012400"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/66dedb98-934e-4ae3-a1f0-dc21c5018a8d/Screenshot_2026-05-28_at_6.55.18_PM.png?t=1780012524"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #169</title>
  <description>Github hack, npm madness, Cloudflare&#39;s experience with Mythos, CISA embarrassing data leak, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-169</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-169</guid>
  <pubDate>Fri, 22 May 2026 12:34:00 +0000</pubDate>
  <atom:published>2026-05-22T12:34:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d7fa149-3e5f-462f-841f-25479554625b/vulnu-header-2026-05-22.png?t=1779417300"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/35c82c1b-0ab7-4e1e-a1bd-6cf6bc0d2ffd/Newsletter_Sponsor_Logo.png?t=1759420232"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">I’m officially scuba certified! Fun stumbling into a new hobby. I’m going to get my advanced certification this week so I can use enriched oxygen and go deeper on my trip. Hoping that keeps me fresh for my keynote. I’ve been working on the slides this week and I’m excited for the talk, I’ll try to do a recap at some other conferences so those of you not going to <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> can watch. But if you’re into diving and infosec, this is a good group of people putting on this con and I’d get it on your radar.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4499308a-5f5d-4981-8d75-122dcaada6e7/Screenshot_2026-05-21_at_9.31.25_PM.png?t=1779417094"/></div><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: <a class="link" href="https://x.com/mattjay/status/2056817673904742510?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">This thread</a> filled with good advice on how to not pull npm or PyPi malware with your ai agents</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Inside the Secret Luxury Market For <a class="link" href="https://www.youtube.com/watch?v=KGgOJKVyXfo&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Crypto Thieves</a></p><p class="paragraph" style="text-align:left;">🎤 Something I said: I <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">talked to the hackers</a> that found a nation state iOS 0day</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Push <a class="link" href="https://pushsecurity.com/blog/7-things-we-learned-from-matt-johansen?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">published a blog</a> of lessons learned from a webinar we did recently. Some good quotes in here from yours truly.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="git-hub-confirms-breach-of-3800-rep"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>GitHub Confirms Breach of 3,800 Repos Via Malicious VSCode Extension</b></a></span></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/P8JYKaWMnk8" width="100%"></iframe><p class="paragraph" style="text-align:left;">Something’s got to give with this supply chain malware because now the latest victim is GitHub itself. The irony is brutal because GitHub owns NPM, which sits right at the center of the exact malware campaigns we’ve been screaming about for weeks now. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=chatgpt.com" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer’s report on the GitHub breach</a> lines up almost perfectly with the same Team PCP playbook we keep seeing over and over again with these “<a class="link" href="https://socket.dev/blog/antv-packages-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud</a>” worms. At this point there’s nothing “mini” about it anymore. Threat actors reportedly compromised a poisoned VS Code extension, which ultimately led to GitHub confirming roughly 3,800 repositories were stolen.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f6a3df14-19e9-48a5-a901-d3adf1ced6ee/Screenshot_2026-05-20_at_2.48.00_PM.png?t=1779304291"/></div><p class="paragraph" style="text-align:left;">The scary part is how little user error it actually took. The malicious extension was reportedly available for about 11 minutes, but the extension developers estimate more than 6,000 installs happened during that window. That means one GitHub developer likely just had auto-update enabled on what appeared to be a legitimate extension and suddenly malware landed directly inside their development environment. Nobody manually downloaded sketchy files. Nobody disabled antivirus. This is exactly why I keep saying browser extensions, IDE extensions, NPM packages, PyPI packages, and software supply chains are inching toward tied-for-first as the biggest security priority alongside help desk phishing. The attackers are openly telegraphing their playbook now. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://socket.dev/blog/antv-packages-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="traditional-sase-wasnt-built-for-ai"><a class="link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" target="_blank" rel="noopener noreferrer nofollow">Traditional SASE Wasn&#39;t Built for AI Agents. Island Is.</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b0caaf63-5d1c-49d3-b90a-e77a5a32d779/Island_network.png?t=1779304978"/></div><p class="paragraph" style="text-align:left;">AI agents don&#39;t follow the rules traditional SASE was built for. Legacy architectures inspect connections but they cannot interpret intent. Island&#39;s Perfect Packet architecture enforces security where work actually happens: at the point of interaction, inside the browser.</p><p class="paragraph" style="text-align:left;">Backhaul becomes the fallback, not the default, so up to 90% of sessions go direct with no forced TLS inspection or traffic rerouting. Across user and AI agent sessions alike, Island governs what&#39;s sent, to where, and by whom, with a full audit trail and no blind spots.</p><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" target="_blank" rel="noopener noreferrer nofollow">See how Island does it.</a></b></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="project-glasswing-what-mythos-showe"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>Project Glasswing: What Mythos Showed Us</b></a></span></h3><p class="paragraph" style="text-align:left;"><b>This is a top 5 blog of the year for me</b>. Cloudflare’s writeup of their experience with Mythos. The first parts of it are more of what we already knew, Mythos is better at writing exploits than the average AI model. The real magic in this post is when they start to talk about the harness and then the last few paragraphs.</p><p class="paragraph" style="text-align:left;">The people having the most success with Mythos aren’t just throwing source code at the model and saying “go find vulns.” They’re building advanced harnesses around it. Mozilla talked about it. The Cloudflare write-up talks about it. That seems to be where the magic actually happens: not just the model, but the surrounding tooling and workflows that let the model iterate toward a working exploit chain.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8ae3e141-984a-4e5d-b036-9a4b6529b1e0/Screenshot_2026-05-19_at_2.57.53_PM.png?t=1779217082"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Cloudflare’s vulnerability discovery harnass</a></p></span></div></div><p class="paragraph" style="text-align:left;">When the author starts to talk about how just fixing vulns faster is the wrong goal, I start to levitate off my seat. Music to my ears. Direct quote I love: “Patching faster does not change the shape of the pipeline that produces the patch.” - read it twice. then read it again. Fast whack-a-mole is still whack-a-mole. Vulnerabilities are just one way in, the layers you build around it are where security programs really earn their paycheck. (<a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="cisa-admin-leaked-aws-gov-cloud-key"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>CISA Admin Leaked AWS GovCloud Keys on Github</b></a></span></h3><p class="paragraph" style="text-align:left;">This CISA GovCloud leak story from Brian Krebs is insane. It was plaintext passwords, exposed AWS GovCloud credentials, public GitHub repos, and apparently very basic security hygiene failures. One of the exposed files literally contained admin creds for GovCloud systems. Another was apparently just a CSV full of usernames and passwords. Then you read the official response saying there’s “no indication sensitive data was compromised” while staring directly at screenshots of plaintext credentials. Shot. Chaser. Oh my god.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c0410132-cac2-46d2-93ea-f1589fd15562/Screenshot_2026-05-19_at_3.16.26_PM.png?t=1779218215"/></div><p class="paragraph" style="text-align:left;">The thing that really bothers me here is this clearly goes beyond “one contractor made a mistake.” There were supposed to be guardrails everywhere that should have caught this. GitGuardian reportedly flagged the exposed secrets. The repo was public. The passwords in some cases were apparently predictable formats like platform name plus current year. This would be embarrassing for any company. The fact that it’s tied to CISA-adjacent infrastructure and GovCloud makes it way worse. (<a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="microsoft-shares-mitigation-for-yel"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>Microsoft Shares Mitigation for YellowKey Windows Zero-Day</b></a></span></h3><p class="paragraph" style="text-align:left;">Microsoft finally assigned a CVE to the YellowKey BitLocker bypass after the researcher behind it basically said, “Fine, if coordinated disclosure isn’t working, I’m just going public.” This is the same researcher behind Blue Hammer, Red Sun, and Green Plasma. I get why this whole thing has turned messy. Microsoft’s response literally says the proof-of-concept was released “violating coordinated vulnerability disclosure best practices,” but you don’t really get to say that after frustrating somebody through the disclosure process so badly they just start dropping everything publicly. That’s the whole point of the protest.</p><p class="paragraph" style="text-align:left;">The really wild part is how easy YellowKey apparently is to use. This is a BitLocker bypass that has people legitimately asking out loud whether this feels “too convenient” to be accidental. Microsoft’s mitigation guidance right now is basically “mount WinRE images manually, modify registry hives, disable recovery utilities,” which is honestly a disaster-tier mitigation for most organizations. The entire situation feels like Microsoft scrambling because they wanted time for a clean fix, but instead got forced into publishing ugly interim guidance after the exploit already hit GitHub. (<a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ever-investigated-a-super-urgent-fi"><span style="background-color:rgb(255, 255, 255);"><b><a class="link" href="https://mazehq.com/blog/exploitability?utm_source=vulnu&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=secondary" target="_blank" rel="noopener noreferrer nofollow">Ever investigated a &quot;super urgent&quot; finding for it to be nothing?</a></b></span><span style="background-color:rgb(255, 255, 255);"><b>*</b></span></h3><p class="paragraph" style="text-align:left;">You&#39;ve spent hours digging into a &quot;critical&quot; CVE only to realize one config setting makes it impossible to exploit in your environment.</p><p class="paragraph" style="text-align:left;">You should never have had to look at it. That&#39;s not an exploitable finding, and reachability alone won&#39;t catch that. <b>Maze</b> AI agents determine exploitability like your best security engineer would, with context from your environment and business, before noise hits your backlog. (<a class="link" href="https://mazehq.com/blog/exploitability?utm_source=vulnu&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=secondary" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="welcome-to-black-file-inside-a-vish"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Welcome to BlackFile: Inside a Vishing Extortion Operation</a></h3><p class="paragraph" style="text-align:left;">Meet BlackFile (UNC6671), a threat group that Google just profiled who specializes in voice phishing. These guys call victims pretending to be IT support, claiming there&#39;s some urgent MFA update or passkey migration needed. While they&#39;ve got you on the phone walking through their fake portal, they&#39;re using your real credentials and MFA tokens in real-time to register their own devices on your accounts. Pretty slick adversary-in-the-middle setup that bypasses most traditional security controls.</p><p class="paragraph" style="text-align:left;">Once they&#39;re in your Microsoft 365 or Okta environment, they go full automation mode with Python and PowerShell scripts to hoover up massive amounts of data - millions of files in some cases. They&#39;re using direct HTTP requests that show up as &quot;FileAccessed&quot; events instead of &quot;FileDownloaded&quot; to stay under the radar. After stealing everything from SharePoint to Salesforce, they hit you with extortion demands starting in the millions but often settling for low six-figures. Their data leak site shut down in May 2026 with a cryptic &quot;shutting down under this name&quot; message, suggesting they&#39;re probably just rebranding for round two. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="1-password-teams-with-open-ai-to-st"><span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials</b></a></span></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/824b8ab4-350c-49b6-a0ae-1e5b7022693a/Screenshot_2026-05-20_at_11.57.34_AM.png?t=1779359898"/></div><p class="paragraph" style="text-align:left;">This 1Password and OpenAI partnership might actually be one of the smarter AI security ideas I’ve seen lately. The core idea is to stop stuffing secrets into environment variables, dotfiles, prompts, repos, and MCP configs where AI coding agents can accidentally expose them. That’s exactly how a lot of developers are working right now. People are using Codex, MCP servers, and other AI coding tools, and the workflow often becomes, “Yeah, just stick the API key into the ENV variable and let the agent use it.” Then suddenly your coding agent has long-lived access to sensitive credentials sitting directly inside the model workflow.</p><p class="paragraph" style="text-align:left;">What 1Password is proposing here is a just-in-time credential model where the secrets stay vaulted and only get issued temporarily for the specific task the agent is performing. In theory, I actually really like this idea. Keeping secrets out of prompts, repos, and model context windows is absolutely the right direction. The part I’d want to test hard is the enforcement side. It’s easy to say “credentials are scoped to the task,” but how do you actually guarantee that? You can’t just ask the AI agent nicely not to misuse the creds. Still, if this works the way they’re describing, it could genuinely reduce a lot of the secret leakage mess we’re seeing right now across AI-assisted development environments. (<a class="link" href="https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="coruna-respawned-compromised-arttem"><a class="link" href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package?utm_medium=feed#Stage-6-Final-Action-Dispatch-and-Payload-Invocation" target="_blank" rel="noopener noreferrer nofollow">Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit</a></h3><p class="paragraph" style="text-align:left;">My ears perked up when I read this headline as I just did a whole video about Coruna and it’s sister exploit DarkSword. This is also a bit different then the other npm stuff we’ve covered lately as it’s not targeting the developer pulling the npm malware, it’s targeting iOS devices of users who happen upon websites using the pwned packages.</p><p class="paragraph" style="text-align:left;">Socket&#39;s threat research team caught this in the popular art-template npm package. Someone got their way into taking over maintenance from the original author, then immediately started pushing weaponized versions. The compromised packages (4.13.5 and 4.13.6) inject a sophisticated iOS Safari exploit framework that&#39;s basically a respawned version of the Coruna exploit kit - the same commercial toolkit that Google documented earlier with 5 full exploit chains targeting iOS 13-17.2.</p><p class="paragraph" style="text-align:left;">The technical sophistication is impressive in a terrifying way - multiple obfuscation layers, content-addressed module loading, and even CPU architecture discrimination between regular iPhones and Apple Silicon Macs. If your app bundled those bad art-template versions, every user visiting your site got served this exploit framework automatically. (<a class="link" href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package?utm_medium=feed#Stage-6-Final-Action-Dispatch-and-Payload-Invocation" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="scammers-are-abusing-an-internal-mi"><a class="link" href="https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Scammers are abusing an internal Microsoft account to send spam links</a></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DYnQuetvS9z/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><h3 class="heading" style="text-align:left;" id="ghost-tree-unveiling-path-manipulat"><a class="link" href="https://www.varonis.com/blog/ghosttree-ntfs-trick?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security</a></h3><p class="paragraph" style="text-align:left;">Varonis just dropped details on a clever new evasion technique called GhostTree that&#39;s bound to give some EDR vendors headaches. The idea is to use NTFS junctions to create recursive directory loops that generate infinite file paths. Any user can pull this off with just write permissions and a couple mklink commands, no admin rights needed. Point a child folder back to its parent, and suddenly you&#39;ve got unlimited valid paths to the same file that can stretch all the way to Windows&#39; 260-character limit.</p><p class="paragraph" style="text-align:left;">The nastier variant creates multiple junction branches, turning your directory structure into a binary tree nightmare that can theoretically generate 2^ 126 unique paths (that&#39;s more paths than there are atoms in your body, for perspective). When EDR tools try to recursively scan these folders, they get stuck in the loop and hang, leaving your actual malware sitting pretty and unscanned. Microsoft initially brushed this off saying &quot;bypassing Defender isn&#39;t crossing a security boundary,&quot; but then quietly patched it anyway. (<a class="link" href="https://www.varonis.com/blog/ghosttree-ntfs-trick?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grafana-breach-caused-by-missed-tok"><a class="link" href="https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Grafana breach caused by missed token rotation after TanStack attack</a></h3><p class="paragraph" style="text-align:left;">Grafana is another ripple effect of the npm worms. Their CI/CD pipeline consumed one of those malicious npm packages and the credential-stealing malware did its thing and stole some GitHub workflow tokens from their environment. Grafana&#39;s incident response team jumped on it and started rotating tokens, but they missed one.</p><p class="paragraph" style="text-align:left;">That lone forgotten token was all the attackers needed to get into Grafana&#39;s private GitHub repos and make off with source code plus some business operational data (think contact names and emails, nothing too spicy). No customer production data got touched, and they didn&#39;t mess with the actual codebase, so if you&#39;ve been downloading Grafana recently, you&#39;re fine. But this hand in hand with the lead story on GitHub is a second order hack of the npm worm worth watching. (<a class="link" href="https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="europe-dismantles-vpn-service-used-"><a class="link" href="https://therecord.media/europe-dismantles-first-vpn?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Europe dismantles VPN service used by cybercriminals to hide ransomware attacks</a></h3><p class="paragraph" style="text-align:left;">European cops just took a wrecking ball to First VPN, the go-to service for cybercriminals looking to hide their dirty work. This coordinated takedown between France, Netherlands, and Ukraine happened this week and targeted a service that had been advertising itself on Russian-speaking crime forums for years. They grabbed 33 servers and, more importantly, the entire user database - which is basically a Christmas list of cybercriminals who thought they were untouchable.<br><br>First VPN wasn&#39;t just some regular VPN that happened to have bad actors as customers. This thing was specifically marketed to criminals, promising they&#39;d never cooperate with law enforcement and would keep users &quot;beyond the reach&quot; of authorities. (<a class="link" href="https://therecord.media/europe-dismantles-first-vpn?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/998b39cd-976a-428f-b843-46a5480968e2/image.png?t=1779400357"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c1f3ea35-a902-4181-bd1a-45f995dba462/Screenshot_2026-05-21_at_9.34.20_PM.png?t=1779417271"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b4b1adfb-0461-49d5-911f-02fef1e75a64/Screenshot_2026-05-21_at_9.38.05_PM.png?t=1779417499"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #168</title>
  <description>So many more supply chain worms, so many more linux 0days, some android 0days as a treat, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-168</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-168</guid>
  <pubDate>Fri, 15 May 2026 12:16:00 +0000</pubDate>
  <atom:published>2026-05-15T12:16:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/de428da1-d233-4c9f-9345-bcc638399b06/vulnu-header-2026-05-15.png?t=1778779973"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">I’ve fallen into a new hobby by force. I’m keynoting a conference in a few weeks called <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> - and will be scuba diving with CISOs and other industry. So I’ve been very busy getting scuba certified for the first time. What a wild process! Will I see any of you down there? I think the other keynote is the CISO of the NFL and there are a ton of industry vets going. I’m excited.</p><p class="paragraph" style="text-align:left;">If you’re reading this and enjoy a good livestream I’m officially a few months into Tue, Wed, Thur streams on <a class="link" href="https://www.youtube.com/@VulnerableU?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">YouTube</a> and <a class="link" href="https://www.twitch.tv/reshikote?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Twitch</a>. We have great convos and chat fills with practitioners living through the front lines. Love when I talk about something which causes someone in stream to have to go run an incident because thats how they found out. Come check it out. I start in the 9am hour CST and run about 2-4 hours depending on whats going on. This week I even had <a class="link" href="https://www.youtube.com/watch?v=n3zYAk0_njQ&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Andrew Peterson</a>, former CEO of Signal Sciences and current Investor for Aviso come in the studio and jam.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: My <a class="link" href="https://x.com/mattjay/status/2054304708060168263?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">ELI5 breakdown</a> of the recent supply chain malware issue</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Primeagen’s <a class="link" href="https://www.youtube.com/watch?v=zaGOKd4jqEk&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">run down</a> of recent Mythos news and capabilities</p><p class="paragraph" style="text-align:left;">🎤 Something I said: The most work we’ve put into a YouTube video yet. <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">I interviewed</a> the teams that found the recent iOS 0days in the wild.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: This org made a <a class="link" href="https://x.com/heyandras/status/2054512710017298463?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">honeypot GitHub</a> to catch AI bots pushing BS PRs so they can block them from their real repos.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="mini-shai-hulud-is-back-npm-worm-ke"><b><a class="link" href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud Is Back: NPM Worm Keeps Mutating as GitHub Supply Chain Attacks Accelerate</a></b></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bd5a4440-21e1-44bd-ad40-30b7639d10dd/Screenshot_2026-05-13_at_11.25.53_AM.png?t=1778696387"/></div><p class="paragraph" style="text-align:left;">Another week, another NPM worm. This latest wave, “Mini Shai-Hulud”, hit packages tied to TanStack, Mistral AI, and a growing list of projects across NPM and PyPI. At this point, the playbook is becoming painfully familiar: compromise a developer, steal GitHub and NPM tokens, poison legitimate packages, spread to additional maintainers and repos, repeat. But this one feels bigger because the attackers abused legitimate GitHub Actions workflows and trusted release pipelines to publish malicious updates under real developer identities. That’s a very different problem than typo-squatted malware packages sitting in a registry corner waiting for someone to accidentally install them.</p><p class="paragraph" style="text-align:left;">The malware itself was extremely focused on developers and CI/CD infrastructure. Once installed, it hunted for GitHub tokens, NPM credentials, AWS secrets, Kubernetes configs, SSH keys, and other high-value developer artifacts. If it found package publishing access, it attempted to spread itself further. That’s the worm behavior. And this is where the modern dependency ecosystem starts looking really fragile. Developers are now stuck in an impossible tradeoff: patch too slowly and you sit on known vulnerabilities; patch too quickly and you might automatically pull malware before researchers catch it. That’s why teams are now talking seriously about “minimum release age” policies, intentionally delaying dependency updates by several days so security vendors have time to identify malicious releases.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a8e62f99-1cef-4271-8ecd-cd1db54d736f/Screenshot_2026-05-13_at_11.22.58_AM.png?t=1778696607"/></div><p class="paragraph" style="text-align:left;">The really uncomfortable part is how much of this is just the ecosystem functioning as designed. Trusted automation. Trusted publishers. CI/CD pipelines moving at internet speed. The attackers are using the same workflows developers use. And they’re evolving fast. Some variants reportedly included dead-man-switch behavior where revoking a stolen GitHub token could trigger destructive actions on the victim machine. Others experimented with geofenced wiper functionality. This is active supply-chain warfare happening inside the developer ecosystems that run modern software. (Read more <a class="link" href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="timetoexploit-is-down-to-one-day-no"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Time-to-exploit is down to one day. Now what?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dfe53be7-5b81-4248-bfc0-ce84964997b9/ASM_report_header.png?t=1778780069"/></div><p class="paragraph" style="text-align:left;"><b>Intruder</b> analyzed 3,000 organizations&#39; attack surfaces. Top finding: more teams should be asking &#39;does this actually need to be on the internet?’</p><p class="paragraph" style="text-align:left;">There’s no better time to ask it. AI can now find zero-days autonomously and time-to-exploit has shrunk to a single day. Anything on the internet that doesn&#39;t need to be is a target the moment a new CVE drops.</p><p class="paragraph" style="text-align:left;">In the report:</p><ul><li><p class="paragraph" style="text-align:left;">What are the most common attack surface exposures?</p></li><li><p class="paragraph" style="text-align:left;">How long are organizations taking to fix them?</p></li><li><p class="paragraph" style="text-align:left;">How does your industry compare?</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Get the report</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="a-0-click-exploit-chain-for-the-pix"><a class="link" href="https://projectzero.google/2026/05/pixel-10-exploit.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>A 0-Click Exploit Chain for the Pixel 10: When a Door Closes, a Window Opens</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e74fbadf-9092-4852-960c-5cf11d4cf2b2/Screenshot_2026-05-14_at_2.56.54_PM.png?t=1778785037"/></div><p class="paragraph" style="text-align:left;">Project Zero dropped a really interesting write-up showing how they went from a zero-click context to full root on Android using just two exploits chained together. The original work targeted the Pixel 9 earlier this year, and then they adapted the same general approach to the Pixel 10. The wildest part is how straightforward they said portions of it were. One of the bugs apparently stood out specifically because it was “exceptionally simple to exploit.” Zero-click to root on a mobile device is still one of the scariest classes of bugs out there.</p><p class="paragraph" style="text-align:left;">The important context here is this was pre-Mythos. You can’t blame AI for this one. This is just elite vulnerability research and exploit development. But one encouraging thing was Project Zero actually praising Google’s response process, noting it was the first time the vendor patched within the 90-day disclosure window. It’s also kind of funny because even though both teams are technically Google, Project Zero still treats them like a third-party vendor relationship. (<a class="link" href="https://projectzero.google/2026/05/pixel-10-exploit.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fragnesia-linux-kernel-local-privil"><a class="link" href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8fcc3376-c850-47b3-9fdc-f573814e4d3a/Screenshot_2026-05-14_at_3.00.48_PM.png?t=1778785261"/></div><p class="paragraph" style="text-align:left;">Another day, another Linux privilege escalation. Idk whats going on. If you missed the last two, Copy Fail and DirtyFrag - you can catch up <a class="link" href="https://www.elastic.co/security-labs/copy-fail-dirtyfrag-linux-page-bugs-in-the-wild?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>. The latest, Fragnesia, which reportedly emerged as an unintended side effect of one of the patches for DirtyFrag. Security is hard. Just like the npm issues, if you patch it doesn’t mean you’re negating all risk.</p><p class="paragraph" style="text-align:left;">The good news is you can disable the vulnerable kernel modules (esp4, esp6, rxrpc) if you don&#39;t need them, or restrict unprivileged user namespaces. If you suspect you&#39;ve been hit, a simple reboot or cache flush will clear the in-memory modifications. (<a class="link" href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="gtig-ai-threat-tracker-adversaries-"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/981f90f6-073d-4785-bbec-0d5b4ce4b105/Screenshot_2026-05-13_at_12.30.10_PM.png?t=1778699858"/></div><p class="paragraph" style="text-align:left;">Google’s new threat intelligence report is the strongest evidence yet that AI is already being operationalized by threat actors in real attacks. The report goes through attackers using AI for vulnerability research, exploit development, phishing, malware refinement, and attack automation, and they even call out Team PCP, the same group behind the Mini Shai-Hulud supply-chain worm.</p><p class="paragraph" style="text-align:left;">What stands out to me is that attackers getting faster and scaling harder. Google says they’ve now seen evidence of AI being used to discover and help weaponize a zero-day for the first time, including a 2FA bypass exploit. Honestly, I think this is just the beginning. We’re already seeing vibe-coded malware, automated payload generation, and increasingly autonomous attack workflows. I’m probably going to do a long YouTube video walking through this whole report because it feels like one of those “this is where the industry changes” moments. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="check-out-the-opensource-matrix-for"><b><a class="link" href="https://hubs.li/Q04f_n420?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Check out the open-source matrix for browser-based attack techniques</a></b><b>*</b></h3><p class="paragraph" style="text-align:left;">AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — two years ago, most of these were research curiosities. Today they&#39;re industrialized, available as PhaaS, and behind the majority of identity compromises. <b>Push Security&#39;s</b> Browser & Identity Attacks Matrix maps every technique in one open-source framework. </p><p class="paragraph" style="text-align:left;">Explore the matrix from Push Security<b>.</b> (<a class="link" href="https://hubs.li/Q04f_n420?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="introducing-daybreak-frontier-ai-fo"><a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Introducing Daybreak: Frontier AI for Cyber Defenders</a></h3><div class="image"><a class="image__link" href="https://www.youtube.com/live/-ysFroySPxQ?si=P0I79fFPr8zhf9__&t=2345&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/519e25c9-df1b-4b20-bf0a-1a1b8b9a03d7/Screenshot_2026-05-14_at_12.38.07_PM.png?t=1778780320"/></a></div><p class="paragraph" style="text-align:left;">OpenAI launched yet another cybersecurity AI initiative, this one called Daybreak, and my first reaction is: what the hell is going on? Because at this point we’ve had Trusted Access for Cyber, Codex Security, Expanded Trusted Access, GPT-5 Cyber, scaling trusted access with GPT-5 Cyber… and now Daybreak. The branding and positioning are getting impossible to follow, even for people who live in this space every day.</p><p class="paragraph" style="text-align:left;">But underneath the marketing confusion, I do think there’s something important happening here. Daybreak feels less like “AI security tooling” and more like OpenAI acknowledging that frontier models are fundamentally changing vulnerability discovery and defensive operations. The Trail of Bits write-up framed it really well: frontier models are now finding bugs faster than maintainers can triage them:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/422a6ce4-55e4-471f-ac38-5f8c47dfb2d2/Screenshot_2026-05-13_at_12.16.01_PM.png?t=1778703802"/></div><p class="paragraph" style="text-align:left;">That’s a pretty massive shift if you stop and think about it. We’re heading toward a world where AI systems are acting more autonomously inside security workflows: vulnerability research, SOC operations, triage, remediation, code review, all of it. The interesting part is whether enterprises are actually going to trust these systems enough to let them operate at scale inside production environments. (More <a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://x.com/trailofbits/status/2054573243680559165?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="publicly-released-microsoft-0-days-"><a class="link" href="https://x.com/vxunderground/status/2054238975804531135?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Publicly Released Microsoft 0days By Disgruntled Researcher</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/25e58041-5c14-40a4-a011-d4b06e5deb09/Screenshot_2026-05-13_at_4.31.06_PM.png?t=1778704540"/></div><p class="paragraph" style="text-align:left;">So this researcher is fed up with Microsoft’s disclosure process and decided: “f it, we’re doing painful disclosure.” Instead of quietly coordinating fixes, he started publicly dropping the research straight onto GitHub, including the latest, YellowKey and GreenPlasma.</p><p class="paragraph" style="text-align:left;">The one that really stood out to me was YellowKey, which is a BitLocker bypass affecting Windows 11 and newer server builds. The way he describes it almost sounds like discovering some weird hidden debug or recovery functionality left inside WinRE. You boot into recovery, hit a specific key combo, and there’s behavior around BitLocker relocking that apparently should not exist. His whole point is basically: “why is this functionality even here?” And I’ll be honest, reading through it, I kind of get why he starts speculating about it being purposefully created backdoor. (read more <a class="link" href="https://x.com/vxunderground/status/2054238975804531135?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://github.com/Nightmare-Eclipse/YellowKey?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://github.com/Nightmare-Eclipse/GreenPlasma?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="not-a-preload-issue-xbox-responds-a"><a class="link" href="https://www.windowscentral.com/gaming/xbox/what-an-insane-screw-up-xbox-itself-leaks-forza-horizon-6-pc-files-in-full-a-week-before-launch-and-pirates-already-cracked-it?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>&quot;Not a Preload Issue&quot;: Xbox Responds As &#39;Forza Horizon 6&#39; PC Files Leak in Full a Week Before Launch — and Pirates Already Cracked It (UPDATED: Microsoft Responds)</b></a></h3><p class="paragraph" style="text-align:left;">The Forza Horizon 6 leak is one of those stories where I genuinely don’t know if it’s “cyber” or just an absolutely catastrophic operational screw-up. The initial reporting made it sound like somebody accidentally pushed the game live on Steam early with unencrypted files, which immediately led to the raw game assets leaking and pirates cracking it before launch.</p><p class="paragraph" style="text-align:left;">But then they came out and said it <i>wasn’t</i> a preload issue, which honestly just makes the whole thing weirder. Because if it wasn’t some accidental publishing mistake… then what was it? That’s the part that has everybody speculating right now. Meanwhile, the downstream effects are already happening: cracked builds circulating before release, pirated copies spreading everywhere, and the publisher threatening franchise-wide bans for anyone involved. (read more <a class="link" href="https://www.windowscentral.com/gaming/xbox/what-an-insane-screw-up-xbox-itself-leaks-forza-horizon-6-pc-files-in-full-a-week-before-launch-and-pirates-already-cracked-it?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/WeArePlayground/status/2053895284930105772?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="california-mayor-charged-with-actin"><a class="link" href="https://abcnews.com/Politics/california-mayor-accused-acting-illegal-agent-china/story?id=132860574&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>California Mayor Charged With Acting As Illegal Agent for China</b></a></h3><p class="paragraph" style="text-align:left;">The mayor of Arcadia pled guilty to acting as an illegal agent for China tied to operating a website that pushed pro-PRC messaging into the local Chinese-American community. From the reporting, it wasn’t just “generally pro-China opinions.” The allegation is she was actually receiving directives from PRC officials about what content to publish and sometimes even seeking approval before circulating material.</p><p class="paragraph" style="text-align:left;">The part that makes this way more serious is that this is an elected official. If this were just some random propaganda site, okay, that’s one thing. At the same time, this doesn’t sound like “spy movie” espionage stuff so much as an information operation, influence, messaging, narrative shaping, all of that. (<a class="link" href="https://abcnews.com/Politics/california-mayor-accused-acting-illegal-agent-china/story?id=132860574&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="canvas-update-instructure-just-conf"><a class="link" href="https://www.reddit.com/r/canvas/comments/1taj9mk/instructure_just_confirmed_they_paid_the_ransom/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>Canvas Update: Instructure Just Confirmed They Paid the Ransom</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/df6b6dc6-8dc6-4962-b044-61f87e0261dc/Screenshot_2026-05-13_at_5.00.18_PM.png?t=1778706056"/></div><p class="paragraph" style="text-align:left;">The Canvas/Instructure hack got really wild because the ransomware group didn’t just ransom the company, they basically threatened every school using Canvas too. The attackers published a giant list of something like 9,000 schools and essentially said: “If you don’t want your school’s data released, contact us.” That’s a pretty massive escalation compared to the normal playbook.</p><p class="paragraph" style="text-align:left;">ShinyHunters came out and basically said the matter was resolved and schools wouldn’t be further targeted. Then Instructure publicly confirmed they paid the ransom. Straight up. They said the data was returned and they received assurances it wouldn’t be further shared. FBI guidance is always “don’t pay.” But honestly I completely understand why companies do it, especially when the blast radius suddenly includes thousands of schools/children. (<a class="link" href="https://www.reddit.com/r/canvas/comments/1taj9mk/instructure_just_confirmed_they_paid_the_ransom/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="behind-the-scenes-hardening-firefox"><a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Behind the Scenes Hardening Firefox with Claude Mythos Preview</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ea4361c6-ef78-4c6d-9eb0-7ba45438a4a2/security-bug-fixes-1-scaled.webp?t=1778783642"/></div><p class="paragraph" style="text-align:left;">Mozilla used Claude Mythos Preview and other models to find 271 security vulnerabilities in Firefox - part of a massive 423 total bugs they squashed in April alone. The lesson that stands out to me is that we all better be building custom harnesses. Mozilla seemingly is more successful than other project Glasswing participants and all evidence points towards the fact that they’re using a very sophisticated harness on top of their legacy bug finding/fixing system to swap in models as they release.</p><p class="paragraph" style="text-align:left;">The &quot;agentic harness&quot; can actually test and validate bugs instead of just spitting out false positives. They went from AI bug reports being mostly useless noise to finding legitimate sandbox escapes that would make any red teamer jealous. Mozilla&#39;s basically saying the AI security audit game has fundamentally shifted - they&#39;re encouraging everyone to start building similar pipelines now because the models are finally good enough to be worth the effort. Given how many of these were sandbox escapes and parent process UAFs, attackers are probably already doing this too. (<a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/109cb304-3d7f-4027-a860-eae0ebdf8386/Screenshot_2026-05-14_at_7.13.07_PM.png?t=1778803990"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b80972ed-8ce0-4da5-9893-d53874ee7e99/image.png?t=1778804049"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4b52d058-cf7f-4f4b-a1d0-6d3f003a5bee/image.png?t=1778803765"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #167</title>
  <description>Massive education software hacked - Canvas ransomware, AI layoffs, Zero days in edge devices, Iran pretending to be cybercrime group, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-167</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-167</guid>
  <pubDate>Fri, 08 May 2026 12:18:00 +0000</pubDate>
  <atom:published>2026-05-08T12:18:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d9efc122-b2b9-4e4b-8b62-4a020897d2a6/vulnu-header-2026-05-08.png?t=1778195705"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6384ee26-3c52-468a-adac-cc3ff23bce99/Newsletter_Sponsor_Logo.png?t=1755788381"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">An odd week for me. Definitely feeling that Spring burnout. Feels like a lot of people around me also, what is in the air?</p><p class="paragraph" style="text-align:left;">I’m gearing up for some speaking gigs I’ve got this summer and really excited about some of the talks I’ve got cooking. </p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: zero days are not <a class="link" href="https://x.com/mattjay/status/2052398790150156782?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">invisibility</a> cloaks.</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This <a class="link" href="https://www.youtube.com/watch?v=3pkz-Ie_k_c&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">breakdown</a> of Anthropic and SpaceX stuff is the best I’ve seen</p><p class="paragraph" style="text-align:left;">🎤 Something I said: GitHub is <a class="link" href="https://www.youtube.com/watch?v=8MqOtYAw9dw&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">not ok</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Finding Zero-Days with Any <a class="link" href="https://www.provos.org/p/finding-zero-days-with-any-model/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Model</a> (best blog I’ve read in a long time)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="canvas-hacked-by-shiny-hunters"><b>Canvas hacked by ShinyHunters</b></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DYDVLJDPtI6/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><h3 class="heading" style="text-align:left;" id="vulnerability-fixes-without-an-owne"><a class="link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" target="_blank" rel="noopener noreferrer nofollow">Vulnerability fixes without an owner are just a suggestion</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/328d36d0-8893-489d-992a-2bd377020feb/Social_Share.png?t=1778170133"/></div><p class="paragraph" style="text-align:left;">Most vulnerability tickets die in the backlog. Sometimes the fix is hard. More likely, nobody knows who owns it, or the ticket didn&#39;t help the person fix it, just a request to patch a vague vulnerability.</p><p class="paragraph" style="text-align:left;">And when you do find the owner, the tags are stale, the original engineer moved on, and the new owner doesn&#39;t know what they inherited.</p><p class="paragraph" style="text-align:left;"><b>Maze</b>&#39;s AI agents show you the fix your developers will actually implement, not just the textbook fix. Then they cross-reference your repo history, CODEOWNERS, CMDB, and other signals to find who&#39;s fixed this before, so the fix lands with the right person every time.</p><p class="paragraph" style="text-align:left;">Vulns get closed. Period. (<a class="link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="exploitation-of-panos-captive-porta"><a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</a></h3><p class="paragraph" style="text-align:left;">Because apparently it’s consumer edge device vulnerability day ending in Y, we’ve got another PAN-OS bug getting actively exploited. This one is a buffer overflow in the User-ID authentication portal that lets an unauthenticated attacker execute arbitrary code as root. That’s about as bad as it gets.</p><p class="paragraph" style="text-align:left;">What stands out to me is this was already being exploited before the advisory dropped. So this was a zero day. And honestly, the part I keep coming back to with a lot of these edge-device bugs is that the vendor guidance usually says the same thing every time: <b>don’t expose these management and auth portals directly to the internet.</b> Because these vulnerabilities happen constantly.</p><p class="paragraph" style="text-align:left;">That’s the frustrating part. I don’t even beat vendors up too hard over some of this anymore because everybody ships vulnerable code eventually. The real issue is how often these things are internet-facing in the first place. The numbers on this one aren’t staggering, but some new evidence is pointed towards state actors out of China and hyper targeted so they don’t need numbers. (read more <a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="coinbase-cuts-headcount-by-14-citin"><b><a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Coinbase Cuts Headcount By 14%, Citing AI Acceleration</a></b></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bf219b5f-4d39-4d5e-a3f6-7b6d19151947/Screenshot_2026-05-05_at_11.18.22_AM.png?t=1778005631"/></div><p class="paragraph" style="text-align:left;">Coinbase laid off about 14% of the workforce, roughly 700 people.</p><p class="paragraph" style="text-align:left;">They are blaming AI, which at this point shows up in every layoff. “AI is changing how we work,” engineers shipping faster, non-technical teams shipping production code, workflows getting automated. I don’t even disagree with a lot of that. But I think AI is lowercase in reality and uppercase in the press release. This is cost cutting first, AI second. If you can reduce headcount and keep revenue the same, why wouldn’t you do that? That’s the magic corporate Ozempic everyone wants.</p><p class="paragraph" style="text-align:left;">The thing a bunch of people, myself included, found concerning here. We have a financial institution saying managers will be pushed to 15+ direct reports and be asked to be individual contributors too. No pure play managers. Player coaches. etc. etc. We’ll see how far this one goes, but non-tech teams pushing code to prod sounds sexy for startups, sounds concerning for finance.</p><p class="paragraph" style="text-align:left;">Zooming out, this isn’t just Coinbase. It’s happening everywhere. Companies trim the fat, point to AI, and say they’re more efficient. One possible outcome here is we end up with fewer massive companies and a lot more smaller ones, because it’s easier to build now. Code isn’t a moat like it used to be. But the other path is a lot uglier: widespread layoffs, less spending, everything slows down. I’m hoping we land closer to the first one. (<a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="muddy-water-uses-microsoft-teams-to"><a class="link" href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/abe4f75b-65c7-45a0-99d4-f8bd586fd81f/Screenshot_2026-05-07_at_10.11.33_AM.png?t=1778164591"/></div><p class="paragraph" style="text-align:left;">MuddyWater&#39;s getting creative with their false flag game. The Iranian state group just pulled off a ransomware attack that wasn&#39;t really about ransomware at all - they used the Chaos RaaS brand as cover while conducting what was actually a targeted espionage operation. The attack kicked off with some social engineering via Microsoft Teams, where they posed as IT support and got victims to screen-share their way into giving up credentials and bypassing MFA. Once inside, they skipped the whole file encryption thing and went straight for data exfiltration and persistence tools like DWAgent.</p><p class="paragraph" style="text-align:left;">(Do I need to keep saying it? Help desk social engineering should be top of your list)</p><p class="paragraph" style="text-align:left;">This fits a bigger pattern we&#39;re seeing where state actors are borrowing from the cybercrime playbook to muddy attribution waters. (get it?) It&#39;s getting harder to tell who&#39;s who when Iranian operators are using the same tools and tactics as profit-driven ransomware crews. This comes alongside other Iranian cyber escalations, including attacks on Omani government systems and that Port of Fujairah hit where stolen infrastructure data was allegedly used for missile targeting. We&#39;re watching the line between cyber and kinetic operations blur in real time.(I made a whole <a class="link" href="https://www.youtube.com/watch?v=L4ufU29PP4o&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">video</a> about that) (<a class="link" href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="romance-scammers-turn-sweet-talk-in"><a class="link" href="https://www.theregister.com/security/2026/05/05/romance-fraudsters-fleeced-uk-victims-of-102m-in-2025/5227963?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Romance Scammers Turn Sweet Talk Into £102M Payday</b></a></h3><p class="paragraph" style="text-align:left;">The UK just reported more than £102 million lost to romance scams in 2025, and honestly, I think the real number is way higher due to many being unreported. These scams are working. I personally know people whose parents lost tens of thousands of dollars. One was out 30 grand, another 60 grand, and in both cases the victims still fully believed they were in real relationships. Their families become “the bad guys” for trying to stop the bleeding. Both didn’t report due to being so convinced by the scam.</p><p class="paragraph" style="text-align:left;">That’s the part people don’t understand about these things. Once someone is emotionally locked in, logic stops mattering. One of the victims I know had their kids cutting off access to accounts and credit cards, and they still found ways to send money; gift cards, whatever they could. And the people who do realize what happened are often too embarrassed to report it, which means the stats we’re seeing are almost definitely underreported.</p><p class="paragraph" style="text-align:left;">The scary part is these scammers are still basically playing on easy mode. They’re not even really using the scary AI stuff yet: deepfakes, voice cloning, all of that. If they’re already this successful with basic manipulation and fake personas, it’s only going to get worse once those tools become standard. (<a class="link" href="https://www.theregister.com/security/2026/05/05/romance-fraudsters-fleeced-uk-victims-of-102m-in-2025/5227963?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="that-ai-extension-helping-you-write"><a class="link" href="https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">That AI Extension Helping You Write Emails? It’s Reading Them First</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fea7bd03-864b-4390-9dec-ca7110525a0c/Screenshot_2026-05-05_at_3.01.53_PM.png?t=1778007730"/></div><p class="paragraph" style="text-align:left;">Unit 42 dropped a report on high-risk gen AI browser extensions, and this is one of those “you should probably read this” things. They’re seeing this stuff in the wild. Extensions that look like AI tools, or maybe actually are AI tools, but they’re also doing some sketchy stuff on the side. Data exfiltration, adware, hidden iframes, prompt hijacking, redirecting searches, all the usual nonsense, just wrapped in AI branding.</p><p class="paragraph" style="text-align:left;">What stands out to me isn’t even that any one of these is massive. Some of them barely have users. A couple thousand here, one had like two users. That’s not the point. The point is the behavior. This stuff is getting into the Chrome Web Store, and it’s doing exactly what we’ve been talking about. Either it’s malicious from the start, or it does what it says it does for a while and then turns malicious later. (<a class="link" href="https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="that-ai-extension-helping-you-write"><a class="link" href="https://withpersona.com/solutions/workforce-idv?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_can_ds_wf-idv_fy26q2-vuln-u-wf-idv" target="_blank" rel="noopener noreferrer nofollow">Stop deepfakes and social engineering across the employee life cycle</a>*</h3><p class="paragraph" style="text-align:left;">Social engineering, deepfakes, and impersonation are the new security threats. <b>Persona</b>&#39;s Workforce IDV solution verifies real-world identity, not just credentials, with liveness detection, government ID checks, and passive signals. </p><p class="paragraph" style="text-align:left;">From onboarding and device enrollment to MFA resets and privileged actions, identity stays secure. (<a class="link" href="https://withpersona.com/solutions/workforce-idv?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_can_ds_wf-idv_fy26q2-vuln-u-wf-idv" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grok-tricked-into-sending-money-by-"><a class="link" href="https://www.youtube.com/shorts/tk2XFAgLgxs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Grok Tricked Into Sending Money By Prompt Injection</a></h3><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c7c6daba-1639-455e-b9ab-8035d731a6c3/image.png?t=1778185133"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/96e4160f-a588-4098-9bd1-3b08d385b2fe/image.png?t=1778185114"/></div></td></tr></table><p id="all-right-this-is-super-funny-someo" class="paragraph" style="text-align:left;">All right, this is super funny: someone prompt injected Grok and got it to transfer real crypto by tweeting Morse code saying “withdraw all, whatever the heck this coin is, and send it to this wallet.” Grok, being the super helpful AI that it is, decoded the Morse code and there was a special account tagged in this that actually listened to the command. It being the super helpful bot that it is said, “you got it,” and went ahead and withdrew the coin and sent it to that wallet.</p><p class="paragraph" style="text-align:left;">Turns out the Bankr thing allocates wallets to any account that interacts with it. Even though nobody managing the Grok account had any idea, it had been accruing some coins with real monetary value. Just an objectively hilarious prompt injection. (<a class="link" href="https://www.youtube.com/shorts/tk2XFAgLgxs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-high-severity-vulnerabilit"><a class="link" href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e98721df-9b8b-4cde-8fdd-d828bac3df52/Screenshot_2026-05-07_at_10.25.39_AM.png?t=1778163948"/></div><p id="apache-shipped-httpd-2467-on-sunday" class="paragraph" style="text-align:left;">Apache shipped httpd 2.4.67 on Sunday to patch CVE-2026-23918, a double-free in mod_http2 hitting every 2.4.66 and earlier deployment running HTTP/2. Send a HEADERS frame followed by RST_STREAM with a non-zero error code on the same stream, and two nghttp2 callbacks free the same h2_stream pointer twice. The DoS path is one TCP connection, two frames, no auth, worker dies on contact.</p><p class="paragraph" style="text-align:left;">Researchers also built a working RCE PoC using mmap reuse and Apache&#39;s scoreboard memory as a stable target, though it needs APR with the mmap allocator (default on Debian) and an info leak. No confirmed exploitation yet, but the DoS is a weekend project for anyone with nghttp2. Patch to 2.4.67 - kill HTTP/2 as a stopgap if you can&#39;t. (read more <a class="link" href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://lists.apache.org/thread/otwt07gfnp6x2b58hnbghgs9r4ovy3yf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://httpd.apache.org/security/vulnerabilities_24.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="critrical-c-panel-flaw-mass-exploit"><a class="link" href="https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Critrical cPanel Flaw Mass-Exploited In &quot;Sorry&quot; Ransomware Attacks</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b880c3fa-9da6-4f78-9031-85d1af13ed93/Screenshot_2026-05-05_at_3.44.52_PM.png?t=1778010323"/></div><p id="c-panel-is-getting-massexploited-ri" class="paragraph" style="text-align:left;">cPanel is getting mass-exploited right now, and honestly … of course it is. This thing has been around forever, like mid-90s forever, and it’s still sitting all over the internet. CVE-2026-41940 is getting hammered by ransomware crews. The &quot;Sorry&quot; gang is having a field day with this one, with Shadowserver reporting at least 44,000 compromised IP addresses since Thursday. The attackers are dropping a Go-based Linux encryptor that slaps a &quot;.sorry&quot; extension on files and uses ChaCha20 encryption with RSA-2048 key protection.</p><p class="paragraph" style="text-align:left;">This isn&#39;t some small-scale operation either - hundreds of compromised sites are already showing up in Google searches. Emergency patches dropped this week, so if you haven&#39;t updated your WHM/cPanel installations yet, now would be a really good time. The exploitation started back in February as a zero-day, so this crew has had plenty of time cause damage. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="microsoft-defender-wrongly-flags-di"><a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Microsoft Defender Wrongly Flags DigiCert Certs As Trojan:Win32/Cerdigent.A!dha</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bd810f3b-e882-409e-bc6d-3787df0cfc2a/Screenshot_2026-05-05_at_3.50.36_PM.png?t=1778010652"/></div><p class="paragraph" style="text-align:left;">This DigiCert situation was kind of wild because it was two problems stacked on top of each other. First headline everyone saw: Microsoft Defender started flagging legit DigiCert root certs as malware, even removing them from systems in some cases. Massive false positives. That alone is chaos.</p><p class="paragraph" style="text-align:left;">But underneath that, there was a real incident. DigiCert had a breach where attackers got access through - are you ready? You’re not going to believe it… - a customer support employee. Same playbook again. Not some AI super hacker. Just calling support, pretending to be someone they’re not, and getting access. From there, they were able to generate initialization codes for a small number of code signing certs, some of which were then used to sign malware.</p><p class="paragraph" style="text-align:left;">So now you’ve got this weird chain reaction. Real breach leads to real abuse of certificates, which leads Microsoft to start flagging things aggressively, and now you’ve got legit certs getting nuked. Some people in my live stream chat got their days ruined for this one. Rough! (<a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="pcp-jack-cloud-worm-evicts-team-pcp"><a class="link" href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</a></h3><p class="paragraph" style="text-align:left;">There&#39;s some drama brewing in the malware scene. A new framework called PCPJack is stealing creds from exposed Docker, Kubernetes, and MongoDB instances, but also actively kicking out TeamPCP infections from the same systems. SentinelLabs thinks this might be the work of a former TeamPCP member who went rogue and decided to start their own operation. &quot;Fine, I&#39;ll start my own criminal enterprise!&quot;</p><p class="paragraph" style="text-align:left;">PCPJack is pretty complex for malware beef. It&#39;s exploiting fresh CVEs like the React2Shell flaw and some WordPress vulnerabilities, then exfiltrating stolen creds to Telegram channels using proper encryption. The lateral movement game is strong too - it harvests SSH keys, enumerates Kubernetes clusters, and spreads through internal networks. What&#39;s wild is how methodically it scrubs TeamPCP artifacts - processes, services, containers, etc. It&#39;s like watching one hacker crew actively evicting another from compromised systems. Professional courtesy is clearly dead. (<a class="link" href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d95d847f-dec1-48aa-9607-357feffdb116/Screenshot_2026-05-07_at_6.12.44_PM.png?t=1778195568"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60daecbc-df03-4c3a-b33d-b641fcf26b59/Screenshot_2026-05-07_at_6.13.51_PM.png?t=1778195634"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/eafee781-bf80-421c-815f-169fb708cc96/Screenshot_2026-05-07_at_6.14.17_PM.png?t=1778195660"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #166</title>
  <description>GitHub RCE, Widespread vulnerability in most Linux distros gives users root, Robinhood with a very clever phishing attack, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-166</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-166</guid>
  <pubDate>Fri, 01 May 2026 12:53:00 +0000</pubDate>
  <atom:published>2026-05-01T12:53:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/20ab0577-6c95-4815-b135-afeef000e9fe/vulnu-header-2026-05-01.png?t=1777638734"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utm_source=vulnu&utm_medium=sponsor&utm_campaign=ztca_q2_26&utm_content=ztca-&utm_term=newsletter" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cda6c859-ee45-4374-ba4d-d4768220085b/Newsletter_Sponsor_Logo.png?t=1769108506"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">It’s felt impossible to keep up lately. It certainly feels like we’re now dealing with updates hourly instead of daily on types of vulns or breaches. Some deep research is certainly happening assisted by AI - but all of the breaches we’re reading about are still all the security basics.</p><p class="paragraph" style="text-align:left;">I went on a rant <a class="link" href="https://www.vulnu.com/p/vulnerable-u-165?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">last week</a> about what I thought everyone’s priorities should be to build out their security program and I’m sticking to it. Everything we’re seeing by threat actors is telegraphed, and I know budgets and resource prioritization is hard, but we need to shift our defenses to meet the threat actors where they are at.</p><p class="paragraph" style="text-align:left;">Let’s get into it.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: we knew Claude would be competing with security companies, well <a class="link" href="https://x.com/mattjay/status/2049902633243091130?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">with this announcement</a> that is confirmed.</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This new (to me) YouTube channel I found where they outline cyber criminals. <a class="link" href="https://www.youtube.com/watch?v=GpLfdBuRl3I&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Went through the case of a hacker</a> who just kept hacking celebrities.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: AI Didn&#39;t Cause These Breaches, <a class="link" href="https://www.youtube.com/watch?v=X807wlSAQb4&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">You&#39;re Just Now Paying Attention</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Best blog I’ve read all year. Must read if you’re subbed here. Niels Provos duplicates Mythos and Mythos like findings with currently available models using his custom harness. <a class="link" href="https://www.provos.org/p/finding-zero-days-with-any-model/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Finding Zero-Days with Any Model</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="securing-git-hub-wiz-research-uncov"><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Securing GitHub: Wiz Research uncovers Remote Code Execution in </a><a class="link" href="https://GitHub.com?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">GitHub.com</a><a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow"> and GitHub Enterprise Server</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e5496c43-6471-44b6-8efe-78dbb38840ec/image.png?t=1777556759"/></div><p class="paragraph" style="text-align:left;">This one got voted top story in my live stream but it was a hard choice with so much news this week. This is crazy - AI assisted fuzzing using IDA Pro MCP by the Wiz team found a critical RCE in closed source, blackbox appliance of GitHub Enterprise. With a small tweak, this bug also worked on GitHub dot com. With a single git push a user with access to <i>any</i> repo, even one they just created themselves, would be able to execute code on the server itself and get read/write to any other repo on that server.</p><p class="paragraph" style="text-align:left;">This is a huge deal on GitHub dot com because of their multi tenant architecture leading potentially millions of repos exposed. They had the fix out in under 2 hours which deserves huge kudos. It took a few days to package the fix into GitHub Enterprise and at the time of Wiz publishing the research 88% of servers out there were still vulnerable. So if you’re a GitHub Enterprise customer, get to patching. (<a class="link" href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ensure-only-trusted-devices-access-"><a class="link" href="https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utm_source=vulnu&utm_medium=sponsor&utm_campaign=ztca_q2_26&utm_content=ztca-&utm_term=newsletter" target="_blank" rel="noopener noreferrer nofollow">Ensure Only Trusted Devices Access Your Cloud Apps</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5bda548f-1dae-4418-b624-c17f6acd06c1/69bad320c89e9fc8e27d6303_ThreatLocker_Illustration_Zero-Trust-Cloud-Access__1_.webp?t=1777572619"/></div><p class="paragraph" style="text-align:left;">ThreatLocker Zero Trust Cloud Access prevents direct access to cloud applications by routing all connections through a secure, controlled broker. This ensures that only authorized devices can connect—regardless of valid credentials. By removing direct exposure and enforcing strict device-based policies, organizations can stop unauthorized access and maintain full control over their SaaS environment. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.threatlocker.com/capabilities/zero-trust-cloud-access?utm_source=vulnu&utm_medium=sponsor&utm_campaign=ztca_q2_26&utm_content=ztca-&utm_term=newsletter" target="_blank" rel="noopener noreferrer nofollow">Explore ZTCA</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="new-linux-copy-fail-flaw-gives-hack"><a class="link" href="https://copy.fail/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">New Linux ‘Copy Fail’ flaw gives hackers root on major distros</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ea3959ed-5158-4756-8e95-ef468a1a2a0d/Screenshot_2026-04-30_at_1.04.22_PM.png?t=1777572267"/></div><p class="paragraph" style="text-align:left;">Alright, this one is hard to understand but easy to know what you need to do about it. It is a privilege escalation bug in basically every Linux distro that came out after 2017. And like all good and serious vulnerabilities, it has a name and a web page of its own. The vulnerability research dropped at the same time as the POC, and it says that they gave the distros about a month to get ahead of this instead of 90 days. They didn&#39;t really say why. I&#39;m assuming it&#39;s because if the distro has started putting out updates, it was gonna be hard to keep a lid on this one.</p><p class="paragraph" style="text-align:left;">The gist is any user on a box can turn into root. So this is really important for shared boxes, things like CI/CD build machines, Kubernetes cluster machines, or any sort of cloud SaaS offering that lets users execute code on a shared box. Much less important to patch on just single-user Linux workstations or anything like that, but obviously still patch if you can. (<a class="link" href="https://copy.fail/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-c-panel-and-whm-bug-exploi"><a class="link" href="https://www.bleepingcomputer.com/news/security/critical-cpanel-and-whm-bug-exploited-as-a-zero-day-poc-now-available/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Critical cPanel and WHM bug exploited as a zero-day, PoC now available</a></h3><p class="paragraph" style="text-align:left;">cPanel was released to the world in 1997. Why the hell are we still chasing serious, actively exploited vulnerabilities in it across millions of endpoints?</p><p class="paragraph" style="text-align:left;">A critical auth bypass bug (CVE-2026-41940) has been getting exploited in the wild since late February, and now there&#39;s a public PoC floating around courtesy of watchTowr. The vulnerability is a CRLF injection in the login process that lets attackers bypass authentication. With ~1.5 million cPanel instances sitting on the internet, I can’t believe we’re still chasing this.</p><p class="paragraph" style="text-align:left;">Patches dropped on April 28th, but active exploitation goes back way before patches were available. Consider yourself owned if you’ve been on the internet with these vulnerable machines the last few weeks. cPanel also threw together a detection script to check if you&#39;ve been impacted. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critical-cpanel-and-whm-bug-exploited-as-a-zero-day-poc-now-available/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="checkmarx-confirms-lapsus-hackers-l"><a class="link" href="https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Checkmarx Confirms LAPSUS$ Hackers Leaked Its Stolen GitHub Data</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72a44316-c245-4768-882a-ff22d7059238/image.png?t=1777556821"/></div><p class="paragraph" style="text-align:left;">Checkmarx finally confirmed what actually happened here, and it ties straight back to the same supply-chain mess we’ve been watching unfold for weeks. The access vector was the Trivy supply chain attack. Trivy got hacked, attackers got credentials, and then they used those to get into Checkmarx’s GitHub and push malicious code. That was back on March 23rd. About a week later, data got exfiltrated, and now Lapsus$ has dumped that data publicly.</p><p class="paragraph" style="text-align:left;">There was a second wave of malicious artifacts a month later. That means whatever containment they did the first time didn’t fully remove the attacker, or they got back in. Docker images and VSCode extensions that were designed to steal credentials and config files seem to have been used against Checkmarx devs. If you were pinned to latest, you might’ve been pulling malicious code from a security vendor. (<a class="link" href="https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="robinhood-account-creation-flaw-abu"><a class="link" href="https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Robinhood Account Creation Flaw Abused to Send Phishing Emails</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8141cd11-509f-4585-84dc-b56ae3ecdb2e/image.png?t=1777556821"/></div><p class="paragraph" style="text-align:left;">This Robinhood attack is a nasty one that a lot of people in my comments say they fell for. I don’t blame them! This is one of those phishing emails where everything checks out. It’s actually from Robinhood, it passes every filter, it lands clean in your inbox, and there’s nothing about it that looks off at first glance. What the attacker did was abuse the Gmail dot trick to create a separate Robinhood account tied to your email, then trigger a legit “unrecognized activity” alert.</p><p class="paragraph" style="text-align:left;">The vuln that enabled this was HTML injection. They shoved attacker-controlled HTML into the device name field, so when Robinhood sent the email, the bottom half of it was basically the attacker’s phishing page rendered inside a legit message. This is why a lot of anti-phishing advice sucks, you can’t “check the sender” here to make sure it’s legit. It IS legit. The only real defense is after the click: If you land on that phishing page and you’re using a password manager, it’s not going to autofill because the domain isn’t Robinhood. (<a class="link" href="https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="new-linux-copy-fail-flaw-gives-hack"><a class="link" href="https://hubs.li/Q04dnpMq0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Learn how browser-based attacks have evolved — get the 2026 report (no gates!)</a>*</h3><p class="paragraph" style="text-align:left;">Most breaches today start with an attacker targeting cloud and SaaS apps directly over the internet. In most cases, there’s no malware or exploits. Attackers are abusing legitimate functionality, dumping sensitive data, and holding companies to ransom. This is now the standard playbook. </p><p class="paragraph" style="text-align:left;">The common thread? It&#39;s all happening in the browser. </p><p class="paragraph" style="text-align:left;">Get the report from <b>Push Security</b> to understand how browser-based attacks work and where they’ve been used in the wild, breaking down AitM attacks, ClickFix, malicious extensions, OAuth consent attacks (<a class="link" href="https://hubs.li/Q04dnpMq0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="i-couldnt-possible-cover-all-of-thi"><a class="link" href="https://socket.dev/blog?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">I couldn’t possible cover all of this in one newsletter.</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6dad5ea6-5f6c-422b-8c8c-af66b8919a22/Screenshot_2026-04-30_at_1.39.09_PM.png?t=1777574549"/></div><p class="paragraph" style="text-align:left;">Look at all this. First of all I couldn’t possible cover all the supply chain stuff that happened this week individually. Quick recap - Open VSX extensions are dealing with new variations and waves of GlassWorm, TeamPCP is still kicking around this time in SAP’s repos, a bunch of npm Typo Squats are out there stealing secrets out of env variables, and popular PyPi packages tied to ‘lightning’ were compromised.</p><p class="paragraph" style="text-align:left;">On top of all of that Socket acquired Secre Annex - and not to take credit or anything but Feross and Tuckner are the only two founders that have been on my YouTube channel and here they are succeeding together. Causation or Correlation, you decide. (<a class="link" href="https://socket.dev/blog?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="evolving-the-android-chrome-vr-ps-f"><a class="link" href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Evolving the Android & Chrome VRPs for the AI Era</a></h3><p class="paragraph" style="text-align:left;">Is bug bounty dying? It’s certainly changing. Google just announced it’s reducing a bunch of its bug bounty rewards, and the cited reasons make it sound like they’ve just gotten too damn good and efficient internally with the use of AI vuln scanning. They are prioritizing rewarding things that AI is bad at currently, like exploit development. They don’t want your lengthy vuln description thanks to Opus 4.7 - they can do that themselves. They want a PoC.</p><p class="paragraph" style="text-align:left;">They&#39;re also ditching some bonuses like renderer code execution rewards because AI has made demonstrating those techniques &quot;almost routine.&quot; Absolutely wild to think about where we were just a few months ago. While individual bug payouts might drop, they expect total rewards in 2026 to actually increase. Gotta wonder what this means for non-Google bounty programs. (<a class="link" href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="iranian-hackers-expose-personal-det"><a class="link" href="https://metro.co.uk/2026/04/28/iranian-hackers-expose-personal-details-thousands-us-marines-middle-east-28147059/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Iranian hackers expose personal details of thousands of US Marines in Middle East</a></h3><p class="paragraph" style="text-align:left;">This one is wild, but also frustrating because we don’t actually have the details that matter yet. Handala is out there claiming they dumped personal data on 2,379 U.S. Marines in the Middle East: emails, family details, home addresses, even “shopping habits” and “nightly activities.” The messaging is full-on cartoon villain stuff. Pure propaganda. But underneath that, there’s a real question I care about: <i>where did this data actually come from and how did they build these profiles?</i></p><p class="paragraph" style="text-align:left;">That’s the part we don’t have yet, and it’s the only part that really matters. War stuff is war stuff,  we all get that. But when this kind of targeting starts bleeding into private individuals, families, and potentially companies, that’s when it crosses into something we should be paying attention to. Right now, it’s noise and threats. I’m watching for how they got the data and whether this starts hitting closer to home. (<a class="link" href="https://metro.co.uk/2026/04/28/iranian-hackers-expose-personal-details-thousands-us-marines-middle-east-28147059/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="police-arrest-3-people-in-cybercrim"><a class="link" href="https://www.cbc.ca/news/canada/toronto/sms-blaster-police-cybercrime-investigation-9.7174756?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Police Arrest 3 People In Cybercrime Investigation, Seize ‘SMS Blasters’ Used to Defraud Victims</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/29b5c82b-e11c-4277-8405-117ba53ae15f/image.png?t=1777556898"/></div><p class="paragraph" style="text-align:left;">The normies ate this one up. This story was all over the news with this terrifying looking hacking machine in the trunk driving around HACKING PHONES!!11 But it’s actually just a fake cell tower. This stuff has been around forever. It’s not like if this thing drives past your house you instantly get hacked. It’s just an SMS blaster mimicking a tower so phones connect to it and it can send phishing texts directly.</p><p class="paragraph" style="text-align:left;">What <i>is</i> real is the scale and why they’re doing it. Instead of sending scam texts through normal telecom networks where they might get blocked, they just run their own “network” and blast messages straight to nearby devices. That’s why tens of thousands of phones connected and why you see numbers like millions of disruptions. It’s just SMS phishing at scale. (<a class="link" href="https://www.cbc.ca/news/canada/toronto/sms-blaster-police-cybercrime-investigation-9.7174756?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="home-security-giant-adt-data-breach"><a class="link" href="https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Home Security Giant ADT Data Breach Affects 5.5 Million People</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6f3a361b-d914-4454-80b4-73c8d273127d/image.png?t=1777556897"/></div><p class="paragraph" style="text-align:left;">ADT home security company just had data on about 5.5 million customers exposed. (Out of about 6 million total customers. So basically all of them.) Names, phone numbers, addresses, emails, the kind of stuff you’d expect, but still not great when it’s tied to people’s homes. From everything I’ve seen, this wasn’t some crazy technical exploit. This looks like the same thing we keep seeing over and over again. Someone gets access through an employee account and just pulls the data out.</p><p class="paragraph" style="text-align:left;">I call this kind of thing out as priority number 1 to address a lot. I wrote it up in <a class="link" href="https://www.vulnu.com/p/vulnerable-u-165?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">last week’s newsletter</a> if you missed it. The threat actors are screaming their MO from the rooftops on this stuff. If you don’t have your phishing (SMS, Voice, or otherwise) playbook locked down, they’re going to take advantage of it. (<a class="link" href="https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="money-launderer-for-crypto-thieves-"><a class="link" href="https://therecord.media/cryptocurrency-launderer-sentenced-californai?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">Money Launderer for Crypto Thieves Given 5-Year Sentence</a></h3><p class="paragraph" style="text-align:left;">This one is pretty straightforward, but it says a lot about how this whole ecosystem works. You’ve got a 22-year-old in California who just got sentenced to about five years for laundering crypto tied to a group that stole something like $260 million. His job wasn’t the hack. His job was taking the money after the fact, buying assets, moving funds around, basically helping clean it so it looks legit.</p><p class="paragraph" style="text-align:left;">The judge wasn&#39;t impressed with his &quot;young man who got swept up&quot; defense, especially considering he was driving around in a $300k Rolls Royce Ghost courtesy of his laundering fees. What people miss with a story like this is that the hack is one thing, but none of it works without someone on the back end turning stolen crypto into something usable. You steal it, move it, cash it out. What stands out to me is how young these guys are. Early 20s, already deep in this world, moving millions, part of an entire ecosystem built around making stolen money usable. (<a class="link" href="https://therecord.media/cryptocurrency-launderer-sentenced-californai?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aaaecf49-a6b0-4dca-99d6-d6b521761fd1/image.png?t=1777575635"/></div><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/mattjay/status/2049477144598692336?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166"><p> Twitter tweet </p></a></blockquote><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/kmcnam1/status/2048764537080291557?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-166"><p> Twitter tweet </p></a></blockquote><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Vercel Says Some of its Customers’ Data Was Stolen Prior to Recent Hack</title>
  <description>Vercel confirms customer data stolen before recent hack. Learn what happened, the security implications, and why this breach matters for startups and developers.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f5489a4e-d4ab-4f18-8595-b07644d889aa/Screenshot_2026-04-22_at_1.07.31_PM.png" length="158251" type="image/png"/>
  <link>https://www.vulnu.com/p/vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack</guid>
  <pubDate>Mon, 27 Apr 2026 23:07:00 +0000</pubDate>
  <atom:published>2026-04-27T23:07:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/zU-OwyPuZsk" width="100%"></iframe><p class="paragraph" style="text-align:left;">My new least favorite thing right now is how this <a class="link" href="https://x.com/rauchg/status/2045995362499076169?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack" target="_blank" rel="noopener noreferrer nofollow">Vercel breach</a> is being framed. We’ve got <a class="link" href="https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack" target="_blank" rel="noopener noreferrer nofollow">actual details</a> now, and guess what?  It wasn’t some AI super hacker, and somehow the narrative still drifted into “AI super hackers” and “accelerated attacks.” That’s not what this was. Not even close.</p><p class="paragraph" style="text-align:left;">Let’s start with what Vercel actually is: a hosting platform that’s incredibly popular with indie hackers and small startups. It’s built around speed: take a Next.js app, connect it to GitHub, push code, and it’s live. That convenience is the whole value prop. But the flip side is obvious: it’s full of secrets. Environment variables, API keys, credentials — everything you need to run real infrastructure lives there.</p><p class="paragraph" style="text-align:left;">So when the breach hit, the concern was legitimate. If attackers got access to those environments, they’re not just looking at code, they’re looking at the keys to everything that code connects to. Stripe, databases, third-party APIs; all of it.</p><h2 class="heading" style="text-align:left;" id="what-actually-happened">What Actually Happened</h2><p class="paragraph" style="text-align:left;">This didn’t start at Vercel. It started at a third-party company called Context.ai. An employee there got infected with infostealer malware, not through some advanced exploit or even a zero-day, but through downloading a Roblox cheat. That’s the entry point.</p><p class="paragraph" style="text-align:left;">From that single infection, attackers harvested credentials: Google Workspace tokens, access keys, whatever was sitting on that machine. And once you have that, you don’t need passwords anymore. You’ve got sessions, tokens and access.</p><p class="paragraph" style="text-align:left;">From there, they pivoted.</p><p class="paragraph" style="text-align:left;">They used those tokens to move through systems, enumerate access, and find paths into Vercel environments. This is what attackers do. They don’t sit there manually poking around, they run scripts. They operate at machine speed. They take whatever access they get and expand it as fast as possible.</p><p class="paragraph" style="text-align:left;">That’s the part that seems to keep surprising people, and it shouldn’t.</p><p class="paragraph" style="text-align:left;">I’ve said this over and over: if you’re not shutting attackers down in 10 to 30 minutes, you’re already behind. My real target is 10 minutes, because that’s how fast they move. Every security program I’ve ever built had to assume that speed. If you’re describing attacker velocity as “surprising,” then you weren’t prepared for how this actually works.</p><h2 class="heading" style="text-align:left;" id="more-customers-compromised-than-fir">More Customers Compromised Than First Reported</h2><p class="paragraph" style="text-align:left;">We’re now learning it didn’t stop there: <a class="link" href="https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack" target="_blank" rel="noopener noreferrer nofollow">Vercel has confirmed that additional customer accounts were compromised</a> and that the attackers were active beyond just the initial <a class="link" href="https://Context.ai?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vercel-says-some-of-its-customers-data-was-stolen-prior-to-recent-hack" target="_blank" rel="noopener noreferrer nofollow">Context.ai</a> foothold.</p><p class="paragraph" style="text-align:left;">Vercel’s messaging overall is a lot of bullshit. They talk about encryption at rest. That doesn’t matter here. Encryption at rest protects you if someone steals the drive. It does nothing when the application accessing the data is compromised. The app has the keys. That’s how it works.</p><p class="paragraph" style="text-align:left;">They talk about defense in depth. But if an employee can grant broad OAuth permissions to a third-party AI tool, and that access can be leveraged to pivot into internal systems, then whatever defense in depth you had didn’t stop the attack.</p><p class="paragraph" style="text-align:left;">They talk about highly sophisticated attackers accelerated by AI. No. These attackers already have playbooks. They already have automation. They already know how to take a stolen token and turn it into broader access. They don’t need AI to do that.</p><h2 class="heading" style="text-align:left;" id="all-this-has-happened-before-and-wi">All This Has Happened Before, and Will Happen Again</h2><p class="paragraph" style="text-align:left;">What we’re looking at is the same pattern we’ve been dealing with for years: infostealer malware, credential theft, session hijacking and lateral movement through SaaS environments.</p><p class="paragraph" style="text-align:left;">The only thing that’s changed is the story we’re telling about it. That’s the frustrating part. Instead of just saying, “This is what happened, and here’s how we’re going to fix it,” we get buzzwords, vague claims about advanced threats and explanations that don’t actually line up with how these attacks work.</p><p class="paragraph" style="text-align:left;">Security is hard. Everyone gets popped at some point. That’s not the issue.</p><p class="paragraph" style="text-align:left;">The issue is pretending this was something new, because it wasn’t.</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #165</title>
  <description>Vercel breach, Lovable incident, and more supply chain hacks than we know what to do with!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-165</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-165</guid>
  <pubDate>Fri, 24 Apr 2026 11:58:00 +0000</pubDate>
  <atom:published>2026-04-24T11:58:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/380bd9d6-9e67-4c46-a2da-b34b632db743/vulnu-header-2026-04-24.png?t=1776985006"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.paloaltonetworks.com/cortex/cloud ?utm_source=VulnerableU&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=header" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/405a9f6f-4a38-4682-a195-e6dac921f882/Newsletter_Sponsor_Logo.png?t=1764862180"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Go to sleep. Wake up. A new earth shattering AI headline paired with a new supply chain attack! The weeks are feeling a bit repetitive in nature. GPT 5.5 dropped and Checkmarx/Bitwarden are the latest supply chain victims to the same MO we saw the last few weeks.</p><p class="paragraph" style="text-align:left;">I will say though, none of these hacks are because of the AI super powers. Mythos hasn’t escaped the lab. Just same old blocking and tackling we’re not doing.</p><p class="paragraph" style="text-align:left;"><b>Hot take: two security priorities are structurally underweighted at most orgs in 2026. If yours is one of them, they deserve a seat at the top of your roadmap. this is where adversary ROI is highest and where defensive debt is deepest.</b></p><p id="1-helpdesk-and-identityreset-impers" class="paragraph" style="text-align:left;">1) Helpdesk and identity-reset impersonation</p><p class="paragraph" style="text-align:left;">Scattered Spider, DPRK IT-worker ops, and the broader phishing ecosystem have industrialized one attack: calling your helpdesk pretending to be an employee, or calling your employees pretending to be the helpdesk. Email, text, Teams, Zoom, voicemail, whatever same play, different surface.</p><p class="paragraph" style="text-align:left;">Hardware MFA alone doesn&#39;t close it. (but please do it if you can) They pivot to reset workflows, AitM session theft (Evilginx), SIM swap, and vendor compromise. Closing it is a program shift. Phishing-resistant MFA everywhere, helpdesk identity-proofing with callback verification, SSO + conditional access hardening, impossible-travel and session-anomaly detection wired to machine-speed containment, and tabletop exercises against the actual current TTPs.</p><p class="paragraph" style="text-align:left;">It&#39;s hard. It&#39;s also doable, and the component parts already exist in most stacks. If you can&#39;t describe your helpdesk impersonation story end-to-end, stop and get it done.</p><p id="2-if-you-ship-code-git-hub-hygiene-" class="paragraph" style="text-align:left;">2) If you ship code: GitHub hygiene and dependency/supply-chain integrity</p><p class="paragraph" style="text-align:left;">Threat actors are telling you this is the lane. npm/PyPI typosquats, compromised maintainers, poisoned Actions, CI token exfiltration, self-hosted runner takeover. You need to be focusing on 2 things. This is going to get worse before it gets better.</p><ul><li><p class="paragraph" style="text-align:left;"><b>Outbound integrity:</b> devs can&#39;t push malicious code by accident or coercion. Signed commits, branch protection, CODEOWNERS, required review on security-sensitive paths, secretless CI via OIDC, pinned Actions by SHA, hardened runners. Rami McCarthy&#39;s GitHub Actions <a class="link" href="https://www.wiz.io/blog/github-actions-security-guide?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">hardening guide</a> is the reference. read it. (not sponsored)</p></li><li><p class="paragraph" style="text-align:left;"><b>Inbound integrity:</b> your org can&#39;t pull malicious packages. Registry allowlisting, <a class="link" href="https://socket.dev/blog/introducing-socket-firewall?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Socket’s free firewall</a> (not sponsored) or equivalent scanning in the PR path, SBOM + provenance, dependency pinning with signed lockfiles.</p></li></ul><p class="paragraph" style="text-align:left;">If you rank every initiative by <code>breach probability × blast radius ÷ current maturity</code>, these two land at the top for most orgs that ship software, and almost nobody is treating them that way. Fix that.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Found this YouTube channel that does <a class="link" href="https://www.youtube.com/watch?v=L3JEP99zNR0&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">fantastic breakdowns</a> of cybercriminal stories.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Got a TON of great feedback on my breakdown of a <a class="link" href="https://www.youtube.com/watch?v=BznlV0ErsUE&t=201s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">“Mythos ready security program”</a> if you missed it, it’s worth a watch.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Important week to resurface this “How to Rotate” <a class="link" href="https://howtorotate.com/docs/introduction/getting-started/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">guide</a> if you leak secrets or they get stolen via supply chain madness.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="team-pcp-campaign-spreads-to-npm-vi"><a class="link" href="https://research.jfrog.com/post/bitwarden-cli-hijack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow"><b>TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/V6kwwgdiOpg" width="100%"></iframe><p class="paragraph" style="text-align:left;">Researchers just caught a supply chain attack targeting the Bitwarden CLI on npm. This is the same pattern we’ve been seeing for weeks. The attack appears tied to the broader GitHub Actions and supply-chain mess that has already hit other projects, including Checkmarx-related infrastructure. TeamPCP hijacked the @bitwarden/cli package identity and pushed version 2026.4.0 with a malicious loader that downloads the Bun runtime, then launches a comprehensive credential theft operation. It&#39;s going after all the secrets that would help it spread: GitHub tokens, npm credentials, SSH keys, AWS/GCP/Azure secrets, shell history, and AI tooling configs like Claude and MCP settings.</p><p class="paragraph" style="text-align:left;">The sophisticated part is how it handles exfiltration. Primary channel posts encrypted data to audit[.]checkmarx[.]cx, but if that fails, it pivots to GitHub abuse - staging PATs through commit messages, using RSA-signed commits for fallback domains, and even creating repos under victim accounts to upload stolen data. It can also weaponize GitHub Actions to extract more secrets from CI environments. If you&#39;ve got @bitwarden/cli 2026.4.0 installed anywhere, time to assume everything on that box is compromised. (read more <a class="link" href="https://research.jfrog.com/post/bitwarden-cli-hijack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://socket.dev/blog/bitwarden-cli-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="transforming-cloud-posture-security"><a class="link" href="https://www.paloaltonetworks.com/resources/whitepapers/posture-security-modern-cloud-stack?utm_source=VulnerableU&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=transforming-cloud-posture-whitepaper" target="_blank" rel="noopener noreferrer nofollow">Transforming Cloud Posture Security for the Modern Cloud Stack</a>*</h3><p class="paragraph" style="text-align:left;">The cloud security playbook has changed. AI-driven workloads, ephemeral nonhuman identities, and sprawling data pipelines have created an attack surface traditional CSPM wasn’t built to handle. Security teams face massive alert volumes while lacking the context to act. </p><p class="paragraph" style="text-align:left;"><b>Cortex Cloud</b> unifies CSPM, DSPM, CIEM, and AI-SPM to correlate signals across code, cloud, and SOC, surfacing risk in context and enabling real-time remediation. (<a class="link" href="https://www.paloaltonetworks.com/resources/whitepapers/posture-security-modern-cloud-stack?utm_source=VulnerableU&utm_medium=eNewsletter&utm_campaign=Cortex-Cloud&utm_content=transforming-cloud-posture-whitepaper" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="vercel-says-some-of-its-customers-d"><b><a class="link" href="https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Vercel Says Some of its Customers’ Data Was Stolen Prior to Recent Hack</a></b></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/90e75a40-2e0d-4760-a5a7-b7af8f8a1f51/image.png?t=1776952630"/></div><p class="paragraph" style="text-align:left;">My new least favorite thing right now is how this Vercel breach is being talked about. We’ve got actual details now, and guess what? It wasn’t some AI super hacker. It’s built for speed, it ties directly into GitHub, and it’s filled with secrets like environment variables, API keys, all the stuff you need to actually run apps. When the breach first hit, the real concern was if you’re hosting apps there, your secrets might be exposed.</p><p class="paragraph" style="text-align:left;">What actually happened is way less exotic and way more familiar. An employee at a third-party company, Context.ai, got infected with infostealer malware. Not Vercel. Not some AI exploit chain. Someone downloaded a Roblox cheat, got popped, and that gave attackers access to corporate credentials. From there, they grabbed Google Workspace tokens, pivoted, and eventually got into Vercel environments. That’s it. That’s the “super hacker” story.</p><p class="paragraph" style="text-align:left;">And now we’re learning it didn’t stop there: Vercel has confirmed that additional customer accounts were compromised and that the attackers were active beyond just the initial Context.ai foothold.</p><p class="paragraph" style="text-align:left;">And then we get the messaging. Encryption at rest, defense in depth, highly sophisticated attackers accelerated by AI: I call bullshit. Encryption at rest doesn’t matter when the application accessing the data is compromised. Defense in depth didn’t stop an employee from granting broad OAuth access to some random AI tool. And “surprising velocity”? Attackers have always moved this fast. If you’re surprised by that, you weren’t paying attention. This is the same playbook we’ve been dealing with for years just wrapped in AI hype, and clearly still playing out across more customers than initially disclosed. (read more <a class="link" href="https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://x.com/rauchg/status/2045995362499076169?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/tuckner/status/2046245323350081776?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="lovable-security-incident"><a class="link" href="https://x.com/Lovable/status/2046270357674299623?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Lovable Security Incident</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e411f1c8-25a9-4a6f-80f7-95992d4540a5/image.png?t=1776952718"/></div><p class="paragraph" style="text-align:left;">So we’ve got another one in the same general ecosystem as the Vercel mess: this Lovable situation. Someone reported a bug where you could see other people’s prompts, chat history, and in some cases secrets like API keys, database info, all that kind of stuff. This wasn’t some deep exploit chain. - and you had people on social media pairing this with Vercel and asking if Mythos leaked. /sigh</p><p class="paragraph" style="text-align:left;">The response is where it really goes off the rails. Instead of just owning it, the explanation was basically, “this isn’t a security issue, this is a documentation issue.” Thing is, you had people pulling database info and private data out of your platform. Saying “public means public” doesn’t magically make that okay. No one thinks their private chat with an AI tool is going to end up exposed like that. This wasn’t unclear documentation. This was a failure, and trying to spin it any other way just makes it worse. (<a class="link" href="https://x.com/Lovable/status/2046270357674299623?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="addicted-to-hacking-young-hacker-be"><a class="link" href="https://abcnews.com/US/addicted-hacking-young-hacker-historic-breach-speaks-1st/story?id=131855776&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">&#39;Addicted to Hacking&#39;: Young Hacker Behind Historic Breach Speaks Out for 1st Time, Before Reporting to Prison</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/474987a7-e05d-4b87-bb36-7861a24ba767/image.png?t=1776952812"/></div><p class="paragraph" style="text-align:left;">Meet Matthew Lane, the 20-year-old who just started a 4-year prison sentence for orchestrating one of the biggest education cyberattacks in US history. His story reads like a cautionary tale about how gaming platforms can be gateways to cybercrime. (I just was at PAX East talking about the intersection of gaming industry and cybersecurity like this) He started on Roblox at age 9, found his way to hacking forums, and by 15 was targeting Fortune 500 companies. The PowerSchool breach he helped pull off hit 60 million students and 10 million teachers, forcing the company to pay millions in ransom.</p><p class="paragraph" style="text-align:left;">What&#39;s genuinely unsettling is how Lane describes hacking as more addictive than any drug - &quot;incomparable to any drug at all&quot; was his exact phrase. He&#39;s part of a troubling trend where Gen Z hackers are causing unprecedented damage at younger ages. We&#39;ve got 15-year-olds taking down Vegas casinos and 16-year-olds running international cybercrime operations. Lane&#39;s now trying to be a cautionary tale from behind bars. (<a class="link" href="https://abcnews.com/US/addicted-hacking-young-hacker-historic-breach-speaks-1st/story?id=131855776&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="build-deploy-security-agents-at-sca"><a class="link" href="https://www.dreadnode.io/pricing/?utm_source=newsletter&utm_medium=email&utm_campaign=vulnerable_u" target="_blank" rel="noopener noreferrer nofollow">Build & Deploy Security Agents at Scale</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4ec3666d-a970-4b50-abcd-bc5a408958c8/Vulnerable_U.png?t=1776972355"/></div><p class="paragraph" style="text-align:left;"><b>Dreadnode</b> recently launched the first complete AI infrastructure platform for security agents. Dreadnode 2.0 provides security teams everything they need to build, evaluate, and deploy agents at scale — with pre-built capabilities, integrated evals, observability, and advanced AI red teaming. </p><p class="paragraph" style="text-align:left;">Close the loop between PoC and production: Build → deploy → evaluate → optimize → repeat. (<a class="link" href="https://www.dreadnode.io/pricing/?utm_source=newsletter&utm_medium=email&utm_campaign=vulnerable_u" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="former-ransomware-negotiator-pleads"><a class="link" href="https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Former ransomware negotiator pleads guilty to BlackCat attacks</a></h3><p class="paragraph" style="text-align:left;">Angelo Martino, a 41-year-old ransomware negotiator at DigitalMint, just pleaded guilty to secretly working with BlackCat operators while supposedly helping victims. This guy was literally sitting across the table from companies getting extorted, then texting the criminals about their insurance limits and negotiation strategies. He wasn&#39;t alone either - two other negotiators from Sygnia and DigitalMint were in on it, running the inside job.</p><p class="paragraph" style="text-align:left;">These three helped BlackCat squeeze out ransom payments including $25.6 million from a financial services firm and nearly $27 million from a nonprofit. They were operating as BlackCat affiliates, paying the gang a 20% cut of all proceeds while pretending to be the good guys. DigitalMint&#39;s CEO says they fired Martino and his accomplice when they found out, but the damage was done. Absolutely wild breach of trust. (<a class="link" href="https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="investigating-a-new-criminal-toolki"><a class="link" href="https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Investigating a new criminal toolkit for ConsentFix</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/90c49395-09f1-40df-8362-37a154eb1f35/image.png?t=1776984712"/></div><p class="paragraph" style="text-align:left;">Remember that ConsentFix attack we covered back in December? Browser-native OAuth hijacking technique that Russian APT29 was using? It must’ve been successful, because it is gaining steam. We’re looking at v3 which is basically a whole toolkit that enables the technique, and it&#39;s surprisingly polished - complete with step-by-step guides, automation tools, and integration with legit services like Cloudflare Workers and Dropbox. The forum post reads like a proper security vendor writeup, walking through OAuth grants, refresh tokens, and FOCI apps with the kind of detail you&#39;d expect from a red team blog.</p><p class="paragraph" style="text-align:left;">ConsentFix v3 automates the entire attack chain - from spinning up infrastructure to crafting email campaigns to automatically exchanging captured OAuth tokens for persistent access. The attack still bypasses MFA, passkeys, and device compliance checks by tricking users into copy-pasting legitimate Microsoft URLs. It&#39;s not quite PhaaS-level industrialized yet, but it&#39;s a clear signal that OAuth-based attacks are becoming the new normal for 2026. (<a class="link" href="https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="snow-flurries-how-unc-6692-employed"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b871796c-1025-47f4-894c-f56ed45f9ebd/image.png?t=1776984681"/></div><p class="paragraph" style="text-align:left;">Hefty Google threat intel report on a new threat actor, UNC6692. They start by spam-bombing their targets with emails, then come in via Microsoft Teams posing as helpful IT folks offering to fix the &quot;email problem.&quot; Once victims click their malicious link, they deploy a three-part malware suite they&#39;ve dubbed the &quot;SNOW&quot; ecosystem - SNOWBELT (browser extension), SNOWGLAZE (network tunneler), and SNOWBASIN (command shell).</p><p class="paragraph" style="text-align:left;">They abuse legitimate cloud services for everything - AWS S3 for hosting, Heroku for C&C, even using browser push notifications for low-latency commands. They&#39;re basically &quot;living off the cloud&quot; to blend in with normal traffic. Definitely worth a read for you blue teamers. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="house-republicans-unveil-data-priva"><a class="link" href="https://therecord.media/house-republicans-unveil-data-privacy-law-override-state-measures?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">House Republicans unveil data privacy law that would override state protections</a></h3><p class="paragraph" style="text-align:left;">I smelled BS on this one from a mile away. No way we’d actually get sensible privacy legislation with teeth. Privacy experts/advocates are confirming my gut on that one.</p><p class="paragraph" style="text-align:left;">The SECURE Data Act would override 20+ state privacy laws while offering what critics call watered-down protections with serious loopholes. The bill&#39;s data minimization requirements use vague language like &quot;adequate, relevant, and reasonably necessary&quot; - the same stuff 19 states already have that hasn&#39;t changed how companies actually handle data.</p><p class="paragraph" style="text-align:left;">And exemptions basically gut the whole thing. Companies can still collect data for &quot;improving products and services&quot; (hello, AI training), anything covered by contracts (which could include privacy policies), and data users &quot;requested&quot; through services. Plus there&#39;s no private right of action, so you can&#39;t even sue when companies ignore the rules. Privacy groups are calling it a &quot;privacy bill in name only&quot; that would actually make things worse by killing stronger state laws. Republicans spent 14 months on this thing and somehow made it weaker than the bipartisan bill from last Congress. (<a class="link" href="https://therecord.media/house-republicans-unveil-data-privacy-law-override-state-measures?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="crypto-scam-lures-ships-into-strait"><a class="link" href="https://arstechnica.com/security/2026/04/crypto-scam-lures-ships-into-strait-of-hormuz-falsely-promising-safe-passage/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Crypto scam lures ships into Strait of Hormuz, falsely promising safe passage</a></h3><p class="paragraph" style="text-align:left;">Well thats a headline. Scammers are having a field day with the chaos in the Strait of Hormuz. With about 2,000 ships stranded and desperate for safe passage, crypto fraudsters are posing as Iranian authorities and demanding bitcoin or tether payments for &quot;transit fees.&quot; At least one ship may have fallen for it - paid up, tried to cross, and promptly got lit up by actual Iranian forces who apparently didn&#39;t get the memo about the fake safe passage deal.</p><p class="paragraph" style="text-align:left;">You&#39;ve got ongoing military strikes between the US/Israel and Iran, a US naval blockade, Iranian forces attacking commercial vessels, and thousands of panicked mariners looking for any way through. What a recipe for scam success. When legitimate Iranian authorities are already demanding crypto payments for passage and everyone&#39;s confused about who&#39;s in charge of what, it&#39;s pretty easy for scammers to slip in with convincing fake authorizations. (<a class="link" href="https://arstechnica.com/security/2026/04/crypto-scam-lures-ships-into-strait-of-hormuz-falsely-promising-safe-passage/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="apple-fixes-i-os-flaw-that-let-fbi-"><a class="link" href="https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages</a></h3><p class="paragraph" style="text-align:left;">No Signal isn’t broken. Every time these headlines happen, my feeds blow up with people saying Signal has been hacked or broken, etc. As evidence by: you don’t need to do anything to Signal to catch this fix. </p><p class="paragraph" style="text-align:left;">Apple just patched the iOS bug (CVE-2026-28950) that was keeping copies of notifications even after apps got deleted. The FBI discovered this goldmine when they forensically extracted Signal messages from a suspect&#39;s iPhone in a detention center attack case - even though the app had been wiped. Turns out the push notification database was hoarding message content. (<a class="link" href="https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-165" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4cef38f6-0c44-4c9f-b57a-4ab7dfd22aba/Screenshot_2026-04-23_at_5.35.36_PM.png?t=1776983743"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4129d503-b42d-4a73-acdf-c78bfffd38cd/Screenshot_2026-04-23_at_5.36.06_PM.png?t=1776983770"/></div><p class="paragraph" style="text-align:left;"></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="upcoming-appearances">Upcoming Appearances</h1><p class="paragraph" style="text-align:left;">Add upcoming podcasts, speaking gigs, webinars, etc.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #164</title>
  <description>Claude Mythos! What do we need to know? Adobe, Microsoft and wolfSSL 0 days, major crypto breaches, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-164</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-164</guid>
  <pubDate>Fri, 17 Apr 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-04-17T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d361466a-d71c-41e5-b7ac-5c14edb88588/Newsletter_Header.png?t=1776392980"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://hubs.li/Q0495qyF0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/66e67c80-1f82-4c04-9c96-31de4fc5b164/Newsletter_Sponsor_Logo.png?t=1773369252"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Mythos!!11</p><p class="paragraph" style="text-align:left;">Ok, now that we got that out of our system. How are we all hanging in this week? Tech news is moving at a break neck pace lately. Hopefully I’m helping you keep above water and cutting through the noise.</p><p class="paragraph" style="text-align:left;">In case you missed it, I’ve been live streaming on <a class="link" href="https://www.youtube.com/@VulnerableU/streams?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">YouTube</a> and <a class="link" href="https://www.twitch.tv/reshikote?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Twitch</a> 3 days a week for 3-4 hours each shot in the mornings (tue, wed, thu) - come hang.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: My predictions on <a class="link" href="https://x.com/mattjay/status/2044519791319207948?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Opus 4.7</a> (early signs point to true)</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Watched the <a class="link" href="https://www.youtube.com/watch?v=B_7RpP90rUk&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">CISO of Google say</a> their goal is to eliminate all software vulnerabilities in the world…</p><p class="paragraph" style="text-align:left;">🎤 Something I said: <a class="link" href="https://www.youtube.com/watch?v=BznlV0ErsUE&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">My thoughts on Mythos</a> and what you need to do about it</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Anthropic gave defenders a playbook. <a class="link" href="https://research.empiricalsecurity.com/research/anthropic-is-right-about-epss-that-still-leaves-the-hard-part?utm_source=influencer&utm_medium=email&utm_campaign=newsletter&utm_id=influencer" target="_blank" rel="noopener noreferrer nofollow">The Last Mile Is Missing.</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="the-ai-vulnerability-storm-building"><a class="link" href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv4.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5a795e03-8f87-4e0f-97e6-f9e5412e3727/Screenshot_2026-04-15_at_10.54.19_AM.png?t=1776264873"/></div><p class="paragraph" style="text-align:left;">I’m reading this Cloud Security Alliance report because a lot of really smart people saw Mythos and said <i>we can’t sit on the sidelines anymore</i>. At a high level, the guidance is simple: use LLMs for vulnerability discovery and remediation, accelerate your teams with coding agents, and prepare for more incidents. None of that is new, but if you’re not doing it already, you’re behind. And yeah, prepare for burnout. That was true long before Mythos.</p><p class="paragraph" style="text-align:left;"><i><b>What’s actually changing is the speed and capability.</b></i> Time-to-exploitation is collapsing, we’re talking same-day weaponization now. But the bigger shift is in complex exploit chains. The kind of vulnerabilities that used to require a small number of elite researchers, tens or maybe hundreds of people, are starting to become more accessible. That’s the part that matters, not the hype about a “super hacker.”</p><p class="paragraph" style="text-align:left;">I’m not treating Mythos as a one-off. If Anthropic proved this is possible, then it’s going to show up everywhere else. </p><p class="paragraph" style="text-align:left;"><i><b>That’s the real takeaway: we’re on a clock.</b></i> </p><p class="paragraph" style="text-align:left;">Whether it’s months or a year, this capability is going to spread, including to nation-state actors with unlimited resources. I’m taking the marketing with a grain of salt, but the people actually using these systems are telling me they’re finding real vulnerabilities at scale and running incidents on them right now.</p><p class="paragraph" style="text-align:left;">At the same time, Mythos isn’t going to find every vulnerability in everything. What it looks really good at right now is old code, especially memory bugs in C, and that alone is a big deal because that code underpins so much of what we rely on. The opportunity is to use that capability on defense, find and fix faster than attackers can. But either way, this is a race, and the organizations that build the muscle now, process, tooling, and culture, are the ones that will keep up. (<a class="link" href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv4.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="browsers-are-where-breaches-start-c"><a class="link" href="https://hubs.li/Q0495qyF0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Browsers are where breaches start, come learn what to do about it</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e9b00390-12bf-4818-8136-119ed40a8c3e/State_of_Browser_Attacks_-_All__1_.png?t=1776291501"/></div><p class="paragraph" style="text-align:left;">I’m joining Push Security’s new research webinar series, State of Browser Attacks, and the guest lineup alone makes it worth your time. We’re talking Troy Hunt, John Hammond, and Push’s own research team all in one place.</p><p class="paragraph" style="text-align:left;">The browser has quietly become the most dangerous surface in modern attacks. Just this year we’ve seen ClickFix variants everywhere, phishing campaigns hijacking search engine results, and device code phishing scaled up by brand new PhaaS kits. And we’re barely into Q2.</p><p class="paragraph" style="text-align:left;">This series breaks it down simply so you know exactly what to watch for and how to respond.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://hubs.li/Q0495qyF0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Register your spot</a> and see you there!</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="kraken-attack-shows-the-real-threat"><a class="link" href="https://x.com/c7five/status/2043720915330969743?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Kraken Attack Shows the Real Threat: Your Help Desk</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/db7177bf-0e21-40d5-87a1-b04bdfb5137c/Screenshot_2026-04-15_at_12.52.56_PM.png?t=1776271986"/></div><p class="paragraph" style="text-align:left;">Kraken says it’s dealing with an active effort by threat actors to recruit insiders at crypto companies, gaming companies and telecoms, especially through third-party contractors and BPOs. </p><p class="paragraph" style="text-align:left;">This is something that keeps happening. Either weak processes let someone get socially engineered into resetting access, or someone just got bribed. That’s exactly what this looks like. They got access to about 2,000 accounts’ worth of data: balances, account info, wallet IDs, the kind of data you use to figure out who to target next.</p><p class="paragraph" style="text-align:left;">Once that access was used, the extortion started. They got video evidence of what the help desk employee could see, be it screen recordings or something else, and tried to cash in. Kraken didn’t pay and is working with law enforcement, and thinks it can track these people down. That’s the right move, but the bigger issue is how this keeps happening in the first place.</p><p class="paragraph" style="text-align:left;">If you haven’t locked this down, I’d argue this is security team priority number 1 because so many threat actors are doing this. (<a class="link" href="https://x.com/c7five/status/2043720915330969743?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="deleted-your-signal-app-fbi-might-s"><a class="link" href="https://cybernews.com/security/fbi-extracts-signal-messages-from-suspect/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Deleted Your Signal App? FBI Might Still Extract Your Messages</a></h3><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/39EAns9GMpc?si=0hxAER6RNKkSD6UT&start=10855" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><p class="paragraph" style="text-align:left;">I saw a ton of buzz this week around the FBI being able to read Signal messages, and every time this comes up, it’s the same reaction: “Signal is broken.” I get flooded with DMs saying exactly that. </p><p class="paragraph" style="text-align:left;">But Signal is not broken. It’s still the pinnacle of end-to-end encryption. It’s open source, it’s implemented correctly, and it does exactly what it’s supposed to do.</p><p class="paragraph" style="text-align:left;">What actually happened here is simple: they had an end. End-to-end encryption protects messages in transit, not once they hit the device. The endpoint is your phone. If someone has your phone, they have the end. At that point, there’s nothing to “break.” The message was encrypted all the way to the endpoint, and the endpoint is compromised.</p><p class="paragraph" style="text-align:left;">The interesting part is how they were still able to read messages even after the app was deleted. That points to data being stored elsewhere on the device, like in the notification log or push notification database. That’s where message content can still exist, outside of the app itself. That’s worth understanding, because most people don’t realize that’s happening. (<a class="link" href="https://cybernews.com/security/fbi-extracts-signal-messages-from-suspect/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="open-a-is-mac-apps-need-updates-tha"><a class="link" href="https://cyberscoop.com/openai-axios-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">OpenAI’s Mac apps need updates thanks to the Axios hack</a></h3><p class="paragraph" style="text-align:left;">OpenAI is rotating its macOS signing certificates and forcing app updates after getting caught in the Axios supply chain attack from late March. The good news is they say no user data or systems were actually compromised. The bad news, and why they’re being overly cautions, is their GitHub workflow downloaded a malicious version of Axios after North Korean hackers (UNC1069) social-engineered the lead maintainer and hijacked his accounts. The malicious code was only live for three hours, but given that Axios pulls over 100 million weekly downloads, the blast radius was massive.</p><p class="paragraph" style="text-align:left;">OpenAI believes the timing and setup of their workflow likely prevented the certificate from being stolen, but they&#39;re treating it as compromised and revoking it by May 8. If you&#39;re running their macOS apps, update now or they&#39;ll stop working. The root cause was a misconfigured GitHub workflow, which they&#39;ve since fixed. (<a class="link" href="https://cyberscoop.com/openai-axios-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="one-breach-got-exaggerated-the-othe"><a class="link" href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">One Breach</a> Got Exaggerated. <a class="link" href="https://x.com/k1rallik/status/2043408584340341158?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">The Other</a> Dumped a Full Movie Online</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5ce52f29-4de9-4569-8957-1c1a8081cdbc/Screenshot_2026-04-15_at_11.36.51_AM.png?t=1776267421"/></div><p class="paragraph" style="text-align:left;">I saw a lot of hype around the Rockstar Games breach, especially claims that anti-cheat source code was stolen. That got walked back pretty quickly. What actually appears to have been compromised is Snowflake analytics data: things like in-game revenue, purchase metrics, player behavior and support analytics. Rockstar confirmed a breach but said it was limited and non-material, with no impact on players.</p><p class="paragraph" style="text-align:left;">This looks like one of those BPO-style exposures, basically whatever data that third-party environment had access to. Not great, but not the catastrophic “source code leak” people were throwing around on Twitter. A good reminder that early breach narratives are almost always wrong.</p><p class="paragraph" style="text-align:left;">The other story is way messier: A hacker group leaked full HD clips and now the entire unreleased Avatar movie is online after an apparent extortion attempt failed. This isn’t rough cuts or unfinished footage. This is fully produced content, just out on the internet months before release. No official word yet, but this is a bad look, and it likely came down to the same thing we keep seeing: compromised employee access, probably via phishing or social engineering. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/k1rallik/status/2043408584340341158?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="the-sad-decline-of-trenchant-exec-w"><a class="link" href="https://www.zetter-zeroday.com/trenchant-exec-says-he-had-depression-money-troubles-when-he-decided-to-sell-zero-days-to-russian-buyer-also-new-info-reveals-nature-of-his-work-for-australian-intelligence-agency/?ref=zero-day-newsletter&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">The Sad Decline of Trenchant Exec Who Had Everything, Before Deciding to Steal and Sell Zero Days to Russian Buyer</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5c0b841a-f29a-4b95-a43d-5375759dc5ca/Screenshot_2026-04-15_at_12.07.53_PM.png?t=1776269280"/></div><p class="paragraph" style="text-align:left;">This story from Kim Zetter is wild: You’ve got a top executive at Trenchant, Peter Joseph Williams, who had everything and still decided to steal and sell zero-days to a Russian broker. He says he was dealing with anxiety, burnout, depression, and financial pressure. His attorney calls it an “extraordinarily poor judgment” period. But at the end of the day, he signed deals worth up to $4 million to sell eight hacking tools, including some incredibly powerful exploits, to a broker tied to the Russian government. </p><p class="paragraph" style="text-align:left;">The mental health angle matters, but it doesn’t explain this away. He admits depression and burnout weren’t the cause. Prosecutors are pretty clear: this was about lifestyle. He was making serious money already, millions in salary, and still chasing more. Luxury cars, expensive travel, jewelry, a $1.5 million house. He pulled in about $1.3 million from the deal on top of everything else. </p><p class="paragraph" style="text-align:left;">What makes this even crazier is how brazen it was. He wasn’t recruited, he reached out to the Russian buyer himself. He created an anonymous email account and started the relationship. While the FBI was investigating, he kept selling. While the company was investigating, he was put in charge and let a subordinate take the fall for his own actions. He was literally sitting in meetings with federal agents while continuing the crime. Next-level recklessness.</p><p class="paragraph" style="text-align:left;">Prosecutors say the exploits could potentially access millions of devices worldwide. By selling them, he may have handed adversaries the ability to target the U.S., Australia, and allies. It’s a reminder that sometimes the biggest risk isn’t the external attacker, but the person who already has the keys. (<a class="link" href="https://www.zetter-zeroday.com/trenchant-exec-says-he-had-depression-money-troubles-when-he-decided-to-sell-zero-days-to-russian-buyer-also-new-info-reveals-nature-of-his-work-for-australian-intelligence-agency/?ref=zero-day-newsletter&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="adobe-fixes-pdf-zeroday-security-bu"><a class="link" href="https://techcrunch.com/2026/04/14/adobe-fixes-pdf-zero-day-security-bug-that-hackers-have-exploited-for-months/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Adobe fixes PDF zero-day security bug that hackers have exploited for months</a></h3><p class="paragraph" style="text-align:left;">What year is it?! Adobe just patched a zero-day (CVE-2026-34621) that hackers have been exploiting for at least four months. The bug hits Acrobat DC, Reader DC, and Acrobat 2024 on both Windows and macOS, letting attackers drop malware on your system just by getting you to open a rigged PDF file. Security researcher Haifei Li caught this one when someone uploaded a malicious PDF to his scanner - the first sample showed up on VirusTotal back in November. (<a class="link" href="https://techcrunch.com/2026/04/14/adobe-fixes-pdf-zero-day-security-bug-that-hackers-have-exploited-for-months/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fake-ledger-live-app-on-apples-app-"><a class="link" href="https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Fake Ledger Live app on Apple’s App Store stole $9.5M in crypto</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/37f479df-f0ab-4b73-872d-930ae119ef6e/image.png?t=1776389080"/></div><p class="paragraph" style="text-align:left;">A fake Ledger Live app made it through Apple&#39;s App Store review and proceeded to drain $9.5 million in crypto from 50 people over just a few days in early April. Users downloaded what they thought was the legit Ledger app, entered their seed phrases, and watched their wallets get emptied across Bitcoin, Ethereum, Solana, and other chains. Three victims alone lost over $1 million each, with musician G. Love (who? I’m old.) getting hit for $430k in BTC.</p><p class="paragraph" style="text-align:left;">Apple&#39;s since pulled the app, and KuCoin froze the accounts receiving the stolen funds. Though that freeze expires April 20th unless law enforcement steps in. Worth noting: Ledger doesn&#39;t actually offer a macOS app through the App Store, only on their website, which is exactly the gap these scammers exploited. They pulled a similar stunt on the Microsoft Store back in 2023 for $768k, so this playbook isn&#39;t new. (<a class="link" href="https://www.bleepingcomputer.com/news/security/fake-ledger-live-app-on-apples-app-store-stole-95m-in-crypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="red-sun-blue-hammer-and-microsoft-0">RedSun, BlueHammer, and Microsoft 0-day drama</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aa97dee4-787e-4bd2-8cda-4c7889e9cf97/Screenshot_2026-04-16_at_8.34.40_PM.png?t=1776389819"/></div><p class="paragraph" style="text-align:left;">This one has just been kind of amusing. Disgruntled security researcher just painfully dropping 0-days publicly because he wasn’t happy with Microsoft bug bounty response.</p><p class="paragraph" style="text-align:left;">But now we’re seeing some exploit activity via Huntress. John Hammond’s research on this is dropping in the AM - I have an embargoed link but timing won’t work out to include it in this email. <a class="link" href="https://www.youtube.com/watch?v=Q0pKjLMOvFE&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">LowLevel did a good video on it</a> before we saw the exploit traffic. Keep an eye on this one.</p><h3 class="heading" style="text-align:left;" id="majority-of-australian-youth-still-"><a class="link" href="https://therecord.media/social-media-ban-australia-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Majority of Australian youth still use social media despite ban, researchers find</a></h3><p class="paragraph" style="text-align:left;">Australia&#39;s social media ban for under-16s is turning out to be more of a suggestion than an actual barrier. New research from the Molly Rose Foundation found that 61% of Australian kids aged 12-15 are still accessing their accounts on TikTok, Instagram, and YouTube just fine and they&#39;re not even using workarounds. The platforms simply haven&#39;t identified or removed their accounts in the first place.</p><p class="paragraph" style="text-align:left;">I go into depth about my feelings on Age Verification systems in this <a class="link" href="https://www.youtube.com/watch?v=7v0xRUukWl8&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">video here</a>.</p><p class="paragraph" style="text-align:left;">The UK is running pilot programs through May, France&#39;s Senate just voted on an under-15 ban, and Greece, Spain, and the Netherlands have all announced similar restrictions coming soon. The Molly Rose Foundation is pushing back, arguing that the UK should ditch the ban approach and instead strengthen its Online Safety Act with actual enforcement mechanisms that make platforms responsible for age verification and content safety. (<a class="link" href="https://therecord.media/social-media-ban-australia-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-flaw-in-wolf-ssl-library-e"><a class="link" href="https://www.bleepingcomputer.com/news/security/critical-flaw-in-wolfssl-library-enables-forged-certificate-use/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">Critical flaw in wolfSSL library enables forged certificate use</a></h3><p class="paragraph" style="text-align:left;">A critical vulnerability in wolfSSL (CVE-2026-5194) lets attackers bypass certificate verification by exploiting weak hash validation in ECDSA and other signature algorithms. The flaw basically allows forged certificates with smaller-than-allowed digests to pass verification checks, which could let malicious servers masquerade as legitimate ones. After OpenSSL this is the biggest footprint library of it’s type with 5 billion devices worldwide, including IoT, industrial control systems, and even aerospace and military equipment.</p><p class="paragraph" style="text-align:left;">The fix landed in wolfSSL 5.9.1 on April 8, so if you&#39;re running anything with wolfSSL baked in, time to check your version. Many devices don&#39;t use upstream wolfSSL directly, but they get it through vendor firmware or embedded SDKs, so you&#39;ll need to chase down vendor-specific advisories. Props to Nicholas Carlini at Anthropic for catching this one - presumably using Claude super secret hacking tools. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critical-flaw-in-wolfssl-library-enables-forged-certificate-use/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-164" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/34c54a2b-0c70-44b9-bbd9-28a8a36990c4/image.png?t=1776388118"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aefd668b-b6cd-4696-ae16-62771f08185d/Screenshot_2026-04-16_at_8.07.43_PM.png?t=1776388069"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4eb61e4e-f0c9-4505-b9e9-3613fe49ce08/Screenshot_2026-04-16_at_8.08.03_PM.png?t=1776388091"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Mythos and Glasswing: Did Anthropic Break the Internet?</title>
  <description>Anthropic&#39;s Mythos AI tool found so many security vulnerabilities they won&#39;t release it publicly. Here&#39;s what we actually know about the controversy.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/437eda25-f0c2-4a1d-be97-5d58d954a443/HFeYkuuXkAAn_LE.jpg" length="76694" type="image/jpeg"/>
  <link>https://www.vulnu.com/p/mythos-and-glasswing-did-anthropic-break-the-internet</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/mythos-and-glasswing-did-anthropic-break-the-internet</guid>
  <pubDate>Wed, 15 Apr 2026 15:16:00 +0000</pubDate>
  <atom:published>2026-04-15T15:16:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/hQHZoto3-FU" width="100%"></iframe><p id="mythos-is-here-the-internet-is-doom" class="paragraph" style="text-align:left;">Mythos is here! The internet is doomed! That’s been the early reaction, anyway.</p><p class="paragraph" style="text-align:left;">Here is what we actually know - it&#39;s been so successful at finding security vulnerabilities that if they released it, they&#39;re worried about national security, and the sanctity of the internet in general. They&#39;ve given the tool to 40 companies they consider critical infrastructure and they&#39;re allowing these people to use Mythos to try to find and then subsequently fix all of the vulnerabilities that it would be good at finding before this fallout could possibly happen.</p><p id="ive-gotten-more-hate-about-this-sto" class="paragraph" style="text-align:left;">I’ve gotten more hate about this story than anything in a long time on social media. People are absolutely revolting, saying it must just be marketing hype. But let me give you some inside baseball: I&#39;ve gotten to talk to people who run security for some of the people on this list that are telling me that the claims are real, that they are surprised at the amount and quality of the security vulnerabilities that this thing has been able to find.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a560d518-72d5-45a3-8282-8246ea93587f/Screenshot_2026-04-08_at_2.10.06_PM.png?t=1775760811"/></div><p class="paragraph" style="text-align:left;">Of course, Anthropic is incentivized to overhype this. I&#39;ve been super critical of all of the frontier model companies coming out and being like this thing that we just built is so dangerous. That being said, when we&#39;re talking about the ability to find security vulnerabilities, Opus was already getting crazy good at this.</p><p class="paragraph" style="text-align:left;">If you want to hear me talk about this for literal hours, check my live stream archive from this week - (specifically <span style="color:inherit;"><span style="text-decoration:underline;"><i><a class="link" href="https://www.youtube.com/live/263u4bfNLlY?si=EyiphCOen8eC1eFh&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-163" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(23, 94, 232)">here</a></i></span></span> and <span style="color:inherit;"><span style="text-decoration:underline;"><i><a class="link" href="https://www.youtube.com/live/Fme2eMdQ4tk?si=sEiwjk0R10JPnq0a&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-163" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(23, 94, 232)">here</a></i></span></span>) I pull up and react to TONs of hype and criticism of Mythos and talk about where I think this is all going. </p><p class="paragraph" style="text-align:left;">I also wrote this tweet while live, responding to all the hype (click the image to go to the full write-up):</p><div class="image"><a class="image__link" href="https://x.com/mattjay/article/2042268949249745213?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=mythos-and-glasswing-did-anthropic-break-the-internet" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9b1b914f-42d9-4d1d-b12e-48cfaa82b7a7/Screenshot_2026-04-09_at_2.49.08_PM.png?t=1775760584"/></a></div><p id="some-additional-thoughts-on-all-of-" class="paragraph" style="text-align:left;">Some additional thoughts on all of this:</p><h2 class="heading" style="text-align:left;" id="finding-bugs-vs-exploiting-them">Finding Bugs vs Exploiting Them</h2><p class="paragraph" style="text-align:left;">I&#39;ve been using Opus 4.6 for vulnerability research. I will say in the last week I&#39;ve been able to find vulnerabilities in browsers using Opus. What I&#39;ve not been able to do is write exploits. There&#39;s a big difference between finding a vulnerability and actually developing a proof of concept and exploiting it.</p><p class="paragraph" style="text-align:left;">I&#39;ve done enough validation to believe that I have found bugs of some severity with Opus 4.6. What they&#39;re saying they have access to right now is the percentage of trial models that actually generated a successful exploit. That is where things get scary.</p><h2 class="heading" style="text-align:left;" id="this-feels-different">This Feels Different</h2><p class="paragraph" style="text-align:left;">It takes a lot of time and tokens and direction to even find bugs. And then there&#39;s a small sliver that could actually exploit. What they&#39;re saying now is that sliver jumps dramatically. This is one of the charts that has scared me.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fadeeebb-cced-421e-891e-69047d089bfd/Screenshot_2026-04-08_at_1.42.43_PM.png?t=1775672225"/></div><p class="paragraph" style="text-align:left;">We have found Mythos is capable of identifying and exploiting zero day vulnerabilities in every major operating system and every web browser.</p><p class="paragraph" style="text-align:left;">Engineers with no formal security training have asked Mythos to find remote code execution vulnerabilities overnight and woken up the following morning to a complete working exploit validated by experts.</p><p class="paragraph" style="text-align:left;">That is a different world.</p><h2 class="heading" style="text-align:left;" id="the-real-problem-isnt-anthropic">The Real Problem Isn’t Anthropic</h2><p class="paragraph" style="text-align:left;">One of the issues here is not whether Anthropic can contain this. The point is that we now know that this is possible. So that means it is coming. Irregardless of Anthropic, it&#39;s coming. Even if it doesn&#39;t leak, there&#39;s distillation. We know that models are being distilled. The capability exists now.</p><h2 class="heading" style="text-align:left;" id="the-dangerous-gap">The Dangerous Gap</h2><p class="paragraph" style="text-align:left;">If the latest AI makes it cheaper than ever to find vulnerabilities and exploit them, it also makes it cheaper to find and fix them. The problem is when this new tool is only available to a privileged few. How fast do you think critical infrastructure can use the latest AI agent and recode itself? Do you think the water plant in the middle of Ohio is going to be able to use the latest AI agents to make sure that they are vulnerability free?</p><p class="paragraph" style="text-align:left;">There is going to be a huge lag time.</p><p class="paragraph" style="text-align:left;">There is no world where this instantly gets democratized and all critical code is suddenly secure. When&#39;s the last time you updated your firmware on your router.</p><h2 class="heading" style="text-align:left;" id="what-happens-next">What Happens Next</h2><p class="paragraph" style="text-align:left;">Software security was originally limited to the number of people that could execute it. What happens now if a single person can act like that or act like 100 with the right model and a couple of bucks?</p><p class="paragraph" style="text-align:left;">What happens when every single piece of software we rely on can be exploited in a loop with a few hundred dollars of compute? In the long run, software gets more secure out of necessity.</p><p class="paragraph" style="text-align:left;">But the in between is a scary time period where everyone is just constantly getting hacked.</p><p class="paragraph" style="text-align:left;">We&#39;re just trying to buy some time.</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Fortinet Customers Confront Actively Exploited Zero-Day, With a Full Patch Still Pending</title>
  <description>Fortinet customers face actively exploited zero-day in FortiClient EMS. Emergency patch available, full fix pending. Federal agencies have until April 9th to remediate.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/271c0dfc-84bd-48fc-a053-dddcbdab7b84/gettyimages-1670649574-612x612.jpg?t=1775663219"/>
  <link>https://www.vulnu.com/p/fortinet-customers-confront-actively-exploited-zero-day-with-a-full-patch-still-pending</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/fortinet-customers-confront-actively-exploited-zero-day-with-a-full-patch-still-pending</guid>
  <pubDate>Tue, 14 Apr 2026 18:49:00 +0000</pubDate>
  <atom:published>2026-04-14T18:49:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/flKb3GeSvgU?si=bsynmYwJ_ZfYeVU9&start=4574" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://cyberscoop.com/fortinet-forticlient-ems-zero-day-cve-2026-35616-hotfix-known-exploited/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=fortinet-customers-confront-actively-exploited-zero-day-with-a-full-patch-still-pending" target="_blank" rel="noopener noreferrer nofollow">Fortinet released an emergency software update</a> to address an actively exploited vulnerability in FortiClient EMS, an endpoint management tool for customer devices. Unknown attackers were first seen trying to exploit the vulnerability in March, and exploitation has already ramped up with growing attacker interest and broader targeting.</p><p class="paragraph" style="text-align:left;">Best time to apply the hotfix was yesterday. Otherwise, right now. </p><p class="paragraph" style="text-align:left;">Federal agencies have until April 9th to remediate. NHS England has already issued a high-severity alert and said it is almost certain there will be further exploitation in the immediate future. Compromise of an EMS server can provide a path to multiple managed endpoints, making this attractive to ransomware operators and espionage actors. This is endpoint management software with remotely exploitable code.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c1b20e8b-9d7f-49b8-b92f-45a84b2d15d2/Screenshot_2026-04-08_at_11.40.23_AM.png?t=1775662890"/></div><p class="paragraph" style="text-align:left;">Fortinet gave this a severity rating of 9.1 out of 10. Tenable calls it a 9.8, reflecting the fact that the attack can be carried out remotely.</p><p class="paragraph" style="text-align:left;">Who remembers the <a class="link" href="https://www.vulnu.com/p/iranian-attackers-retaliate-with-stryker-attack-and-much-more?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=fortinet-customers-confront-actively-exploited-zero-day-with-a-full-patch-still-pending" target="_blank" rel="noopener noreferrer nofollow">Stryker </a>vulnerability that we just talked about where someone compromised Intune, which is endpoint management software, and compromised it by compromising the admin?</p><p class="paragraph" style="text-align:left;">If Fortinet is running this endpoint management software and it has remotely exploitable code, then those who recall the Stryker attack will understand how serious this Fortinet security hole is.</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Unpacking The  2025 FBI IC3 Annual Report</title>
  <description>FBI IC3 2025 Annual Report: Internet crime complaints surge, with seniors losing $7B. Explore unreported cyberattacks, scams, and cybercrime trends.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cbf51929-e792-4d35-80ac-0c43d5d10569/Screenshot_2026-04-08_at_9.34.21_AM.png" length="1124361" type="image/png"/>
  <link>https://www.vulnu.com/p/unpacking-the-2025-fbi-ic3-annual-report</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/unpacking-the-2025-fbi-ic3-annual-report</guid>
  <pubDate>Tue, 14 Apr 2026 13:16:00 +0000</pubDate>
  <atom:published>2026-04-14T13:16:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/flKb3GeSvgU?si=X_9Jmij_-AeFv1pl&start=388" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><p class="paragraph" style="text-align:left;">The Internet Crime Complaint Center, otherwise known as IC3, put out their <a class="link" href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=unpacking-the-2025-fbi-ic3-annual-report" target="_blank" rel="noopener noreferrer nofollow">yearly report</a> and it&#39;s always staggering to see how the number of complaints per year is just straight up and to the right. These are people who lost stuff in cyberattacks, scams, whatever it is, and actually called and reported it. Which is not everyone, by any means.</p><p class="paragraph" style="text-align:left;">It&#39;s always old people losing the most, $7 billion in complaints for the 60+ crowd. </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/553b132f-701a-435b-9e97-8f39bcef6fd3/Screenshot_2026-04-08_at_9.55.46_AM.png?t=1775656566"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/30c39c44-b1c6-443d-a8de-c937e69a4f71/Screenshot_2026-04-08_at_9.56.31_AM.png?t=1775656603"/></div><h2 class="heading" style="text-align:left;" id="the-scams-people-dont-report">The Scams People Don’t Report</h2><p class="paragraph" style="text-align:left;">This was the one that I thought would have been bigger: I have been hearing about these romance scams at an alarming rate. If I tell you I get three of those stories in my DMs every month, I&#39;m not exaggerating. I know a number of people that have lost $30,000 to $60,000 that have not submitted a complaint. They are embarrassed.</p><p class="paragraph" style="text-align:left;">So 23,000 complaints leading to almost a billion dollars in losses. It jumps pretty high up the list from number of complaints to dollars.</p><p class="paragraph" style="text-align:left;">It&#39;s a numbers game for these scammers. They just spray and pray. They don&#39;t bounce off of everybody.</p><h2 class="heading" style="text-align:left;" id="crypto-dominates-everything">Crypto Dominates Everything</h2><p class="paragraph" style="text-align:left;">Investment-related fraud was once again the largest component. Operation Level Up reduced potential losses by more than $500 million. That leads me to believe that crypto is included in this.</p><p class="paragraph" style="text-align:left;">When you get into the investment scam side, 8 billion, I knew that that had to have been crypto. Crypto fraud is way more prevalent than anything else going on. Crypto, it&#39;s like you send it, it&#39;s gone. There&#39;s no bank to help you out.</p><p class="paragraph" style="text-align:left;">Cryptocurrency investment scam, 7.2 billion of the 8 billion: The scammers initiate contact through text messages, quickly move the conversation, introduce investment groups, show fake profits, offer loans to encourage larger investments, and when the victims try to withdraw, they get hit with taxes and fees and then recovery.</p><p class="paragraph" style="text-align:left;">They hit them on the way out, too. Have you lost money in a scam? We&#39;ll help you recover it. And it&#39;s literally the same people that just stole your money. </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5bb03bce-aa48-429b-bb77-349fb95331b8/Screenshot_2026-04-08_at_10.02.25_AM.png?t=1775656961"/></div><h3 class="heading" style="text-align:left;" id="how-the-scams-actually-work">How the Scams Actually Work</h3><p class="paragraph" style="text-align:left;"><b>Once you establish trust, criminals introduce the topic of investing.</b> The platforms seem legit. They&#39;ll even have two factor on them. Returns appear to be extremely lucrative, encouraging the victim to invest more and more.</p><p class="paragraph" style="text-align:left;"><b>It&#39;s common in the early stages to allow victims to withdraw. </b>This is tricking them. Scammers use various methods to sweeten the pot. Matching. Scarcity. Taxes and fees. The account gets frozen. It&#39;s another method used by the scammers to try to convince the victims to invest even more money.</p><p class="paragraph" style="text-align:left;"><b>Ramp and dump. </b>They secretly control a large number of low-price stocks, coordinate efforts to inflate the price, and then they rug-pull and sell it all.</p><p class="paragraph" style="text-align:left;"><b>Gold courier scams.</b> They instruct victims to liquidate assets, buy precious metals, send couriers to retrieve them, and then the victims never hear back and lose all their money.</p><h3 class="heading" style="text-align:left;" id="the-human-cost">The Human Cost</h3><p class="paragraph" style="text-align:left;">Sextortion skews super young. A lot of this is teenagers. It&#39;s disgusting and insane.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0bc4bf0c-31cf-4196-a1b3-f477c5e4fa24/Screenshot_2026-04-08_at_10.11.09_AM.png?t=1775657484"/></div><p class="paragraph" style="text-align:left;">A shocking amount of it is towards men. They&#39;ll pose as girls, get men to send sexual pictures, and then flip it and extort them.</p><p class="paragraph" style="text-align:left;">A lot of people involved, especially in sextortion, wind up committing suicide. You&#39;re talking about a teenager that you&#39;re basically threatening to ruin their life if they don&#39;t pay you money that they probably don&#39;t have, so a lot of them just off themselves.</p><p class="paragraph" style="text-align:left;">So yeah, a billion dollars in losses. How many lives lost?</p><p class="paragraph" style="text-align:left;">This is just US, just in 2025. The numbers are ridiculous. It is sad.</p><h2 class="heading" style="text-align:left;" id="why-advice-doesnt-work">Why Advice Doesn’t Work</h2><p class="paragraph" style="text-align:left;">Do not invest per the advice of someone you meet solely online.<b> </b>How? This is such useless advice.</p><p class="paragraph" style="text-align:left;">Hover over the link and make sure it&#39;s valid. How? You&#39;re talking about people that are falling for this stuff. If people are this far in the scam, they do not have the skills to do any of this stuff.</p><p class="paragraph" style="text-align:left;">You&#39;re hitting vulnerable people at a vulnerable time, the right people at the right time with the right script and they&#39;re just toast. None of this matters.</p><p class="paragraph" style="text-align:left;">Educate, educate, educate. I honestly think this is on the financial institutions to catch, and crypto is just an unregulated hellscape.</p><h2 class="heading" style="text-align:left;" id="ransomware-vs-scams">Ransomware vs. Scams</h2><p class="paragraph" style="text-align:left;">Sixty-three new ransomware variants. More than one new variant of ransomware a week. That&#39;s kind of staggering.</p><p class="paragraph" style="text-align:left;">But ransomware is way less prevalent. 32 million versus 20 billion in scams. </p><p class="paragraph" style="text-align:left;">A lot of this extortion doesn&#39;t even involve ransomware. They just extort you without encrypting everything. We have all your information. If you would like us to not release it, pay us.</p><h2 class="heading" style="text-align:left;" id="critical-infrastructure-and-real-wo">Critical Infrastructure and Real-World Impact</h2><p class="paragraph" style="text-align:left;">Healthcare got absolutely pounded in 2025. Manufacturing, financial services, energy, water. Water is a super small number. Just when it happens that it&#39;s a big fire.</p><p class="paragraph" style="text-align:left;">Physical threats now as well, especially if you own crypto. Break-ins.</p><p class="paragraph" style="text-align:left;">This real-estate stuff is crazy. The amount of hoops they make you jump through because of the amount of fraud is insane.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2d9368af-fa15-4be8-8ae8-bf41667fd3f4/Screenshot_2026-04-08_at_10.17.19_AM.png?t=1775657886"/></div><h3 class="heading" style="text-align:left;" id="trends-that-stand-out">Trends That Stand Out</h3><p class="paragraph" style="text-align:left;">Three-year complaint count: BEC went up. Botnet went up. Romance scams, pretty flat. </p><p class="paragraph" style="text-align:left;">SIM swaps are actually going down. Maybe the TeleCos are getting wise to it.</p><p class="paragraph" style="text-align:left;">Extortion has doubled. Harassment and stalking has more than doubled.</p><p class="paragraph" style="text-align:left;">Identity theft has damn near doubled. Investment scams, close to doubled.</p><p class="paragraph" style="text-align:left;">Phishing and spoofing going way down. That&#39;s interesting.</p><p class="paragraph" style="text-align:left;">Threats of violence skyrocketing. 3x since 2023.</p><p class="paragraph" style="text-align:left;">Crypto investment scams have gone from 4 billion to 8 billion.</p><h3 class="heading" style="text-align:left;" id="the-elder-problem">The Elder Problem</h3><p class="paragraph" style="text-align:left;">They have a whole section on the elderly because it&#39;s just the most prevalent: a 59% jump in amounts lost in 2025 to the elderly.</p><p class="paragraph" style="text-align:left;">Phishing, spoofing, tech support, and romance scams. Three billion in crypto investment scams. It&#39;s wild.</p><p class="paragraph" style="text-align:left;">Investment scams have more than doubled. Malware way up. Phishing, a 10x jump. Everything else is just up.</p><p class="paragraph" style="text-align:left;">They&#39;re just getting slammed with these romance scams.</p><h3 class="heading" style="text-align:left;" id="the-bottom-line">The Bottom Line</h3><p class="paragraph" style="text-align:left;">People know not how to see the warning signs and protect themselves.</p><p class="paragraph" style="text-align:left;">How can we prevent anyone from harming themselves if we don&#39;t increase the education of our citizens?</p><p class="paragraph" style="text-align:left;">Education is rarely stopping a lot of security breaches. Why is this possible?</p><p class="paragraph" style="text-align:left;">We need systemic guard rails that make it really hard for people to do that.</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The $280M Drift Heist: Six Months of Trust, 12 Minutes to Drain It</title>
  <description>How a sophisticated $280M crypto theft took 6 months of trust-building before draining Drift in just 12 minutes. Social engineering, fake apps, and organizational backing exposed.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2b8f3587-444c-4884-af73-2159cfcac437/Screenshot_2026-04-08_at_10.36.14_AM.png" length="2458232" type="image/png"/>
  <link>https://www.vulnu.com/p/the-280m-drift-heist-six-months-of-trust-12-minutes-to-drain-it</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/the-280m-drift-heist-six-months-of-trust-12-minutes-to-drain-it</guid>
  <pubDate>Mon, 13 Apr 2026 17:20:00 +0000</pubDate>
  <atom:published>2026-04-13T17:20:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/gfg1ZYOpaPo" width="100%"></iframe><p class="paragraph" style="text-align:left;">This one was crazy. This $280 million crypto theft was a six-month-long op. Drift experienced a structured intelligence operation that required organizational backing, significant resources, and months of deliberate prep. Contributors were approached in person at conferences, engaged across multiple countries, and worked with what appeared to be a legitimate trading firm that built trust over half a year.</p><p class="paragraph" style="text-align:left;">They onboarded a vault, deposited over a million dollars of their own capital, and built a functioning operational presence inside the ecosystem. They felt like co-workers at this point. But when the hack happened - it should all look familiar. Malicious GitHub repos exploiting VS Code vulnerabilities, fake TestFlight wallet apps, and months of social engineering that made these actions feel completely normal.</p><p class="paragraph" style="text-align:left;">On April 1st, in 12 minutes, $285 million. Boom. The attackers wiped chats, scrubbed evidence, and disappeared. The individuals they met in person were not North Korean nationals, but intermediaries used to build trust. This wasn’t someone you just met online. This was six months of real-world interaction before the rug was pulled.</p><p class="paragraph" style="text-align:left;">Drift is sharing this publicly because other teams in the ecosystem deserve to understand what this attack actually looked like.</p><p class="paragraph" style="text-align:left;">All remaining protocol functions have been frozen and the compromised wallets have been removed from the multisig. Attacker wallets have been flagged across exchanges and bridge operations. Mandiant has been engaged.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/47d2758c-4e28-4be6-a424-2a4cd1ad28c3/Screenshot_2026-04-08_at_10.31.36_AM.png?t=1775659763"/></div><h2 class="heading" style="text-align:left;" id="timeline-six-months-of-building-tru">Timeline: Six Months of Building Trust</h2><p class="paragraph" style="text-align:left;"><b>Fall 2025: </b>Drift contributors were approached by a group of individuals at a major crypto conference, in person, who presented as a quant trading firm looking to initiate on the protocol.</p><p class="paragraph" style="text-align:left;">It&#39;s now understood that this appears to have been a targeted approach where the individuals from this group continued to deliberately seek out and engage specific drift contributors in person at multiple major industry events, conferences in multiple countries over the following six months.</p><p class="paragraph" style="text-align:left;">They were technically fluent, had verifiable professional backgrounds, and were familiar with how Drift operated.</p><p class="paragraph" style="text-align:left;">A Telegram group was established upon the first meeting and what followed were months of substantive conversations around trading strategies and potential vault integrations.</p><p class="paragraph" style="text-align:left;"><b>December 2025 through 26: </b>They onboarded an ecosystem vault on Drift which required filing out of a form with strategy details. They engaged multiple contributors through multiple working sessions, asked detailed and informed product questions and deposited over a million dollars of their own capital.</p><p class="paragraph" style="text-align:left;">They built a functioning operational presence inside the Drift ecosystem deliberately and patiently. Integration conversations continued through February and March. Various Drift contributors met the individuals from this group face to face.</p><p class="paragraph" style="text-align:left;">By this point, the relationship was nearly half a year old. These were not strangers, but people Drift contributors had worked with and met in person.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c34102a9-8568-4ca0-be1c-8fda9bde04dc/Screenshot_2026-04-08_at_10.33.39_AM.png?t=1775659779"/></div><h2 class="heading" style="text-align:left;" id="the-intrusion-vectors">The Intrusion Vectors</h2><p class="paragraph" style="text-align:left;">After the exploit on April 1st happened, a thorough forensics review of the known affected devices, accounts, and communications histories was conducted.</p><p class="paragraph" style="text-align:left;">Interactions with the trading group came into focus as the likely intrusion vector. Right as the exploit happened, their telegram chats and malicious software had been completely scrubbed.</p><p class="paragraph" style="text-align:left;">There may have been three attack vectors. One contributor may have been compromised after cloning a code repo shared in the group. This is very similar to how they hack job interview type stuff, where they&#39;ll share some code in a code repo, you&#39;ll clone it and somewhere in that repo, it&#39;s actual malware. But this is after months and months and months of trust building. A second contributor was induced to download a test-flight app the group presented as their wallet product. This is basically side-loading in iOS with test flight.</p><p class="paragraph" style="text-align:left;">For the repository based vector, one possibility is a known VS code and cursor vulnerability that the security community was actively flagging through December. Simply opening a file, folder or repo in the editor was sufficient to silently execute arbitrary code.</p><p class="paragraph" style="text-align:left;">North Korea abusing VS Code hooks that run automatically in the background as you open a folder: Task.json, a fake font with malicious obfuscated JS code, runs immediately when you open the project in VS Code. It does not display the commands being read.</p><p class="paragraph" style="text-align:left;">That&#39;s huge.</p><h2 class="heading" style="text-align:left;" id="not-who-they-said-they-were">Not Who They Said They Were</h2><p class="paragraph" style="text-align:left;">With medium-high confidence supported by investigations done by SEAL&#39;s 911 team, this operation is assessed to have been carried out by the same threat actors responsible for the October 2024 Radiant Capital hack attributed to North Korea.</p><p class="paragraph" style="text-align:left;">It&#39;s important to note that the individuals who appeared in person were not North Korean nationals. North Korean threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship building.</p><p class="paragraph" style="text-align:left;">They basically have these mules that are paid actors to work with this group to build trust.</p><p class="paragraph" style="text-align:left;">Months of in-person meetings from the fall to January across multiple countries: This quant firm met with people at Drift. They then tied their vault to Drift and deposited over a million dollars of their own money.</p><p class="paragraph" style="text-align:left;">They&#39;re hopping on meetings, working together, giving them millions of dollars. They just feel like co-workers at this point. There&#39;s a ton of trust built up.</p><h2 class="heading" style="text-align:left;" id="the-moment-it-all-collapsed">The Moment It All Collapsed</h2><p class="paragraph" style="text-align:left;">They start sharing GitHub links like “hey check out this tool that I built.” Apparently this is all super normal in this ecosystem.</p><p class="paragraph" style="text-align:left;">But one of those GitHub repos actually takes advantage of a vulnerability in VS Code and cursor that executes code silently and immediately and compromises a contributor of the Drift protocol.</p><p class="paragraph" style="text-align:left;">Another contributor downloaded a fake TestFlight app wallet onto their iOS device. They tested it out, were like “let&#39;s see if our access works here back in March.”</p><p class="paragraph" style="text-align:left;">And then on April 1st, in 12 minutes, $285 million. Boom.</p><p class="paragraph" style="text-align:left;">And then all the Telegram chats and all the stuff that they were building over those last couple months was erased. All the evidence was completely erased at the exact same time that they pulled off the heist.</p><h2 class="heading" style="text-align:left;" id="the-uncomfortable-reality">The Uncomfortable Reality</h2><p class="paragraph" style="text-align:left;">To Drift&#39;s credit, they&#39;ve been very transparent about this investigation and they&#39;re doing forensics as they go.</p><p class="paragraph" style="text-align:left;">But I can&#39;t believe this. They met these people in real life.</p><p class="paragraph" style="text-align:left;">A lot of the advice talks about how you don&#39;t trust these people that you just meet online and start doing whatever the hell they&#39;re doing.</p><p class="paragraph" style="text-align:left;">No. They met these people for six months at conferences and meetings and they worked together until the rug was ready to be pulled.</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>How Command Injection Vulnerability in OpenAI Codex Leads to GitHub Token Compromise</title>
  <description>OpenAI Codex command injection flaw allowed attackers to steal GitHub tokens. Learn how this critical vulnerability affected ChatGPT, CLI, SDK, and IDE extensions.</description>
      <enclosure url="https://images.unsplash.com/photo-1654277041218-84424c78f0ae?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3w0ODM4NTF8MHwxfHNlYXJjaHwxfHxHaXRIdWJ8ZW58MHx8fHwxNzc1MDkxMTg4fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&amp;utm_source=beehiiv&amp;utm_medium=referral"/>
  <link>https://www.vulnu.com/p/how-command-injection-vulnerability-in-openai-codex-leads-to-github-token-compromise</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/how-command-injection-vulnerability-in-openai-codex-leads-to-github-token-compromise</guid>
  <pubDate>Fri, 10 Apr 2026 14:02:00 +0000</pubDate>
  <atom:published>2026-04-10T14:02:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Vulnerability]]></category>
    <category><![CDATA[News]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/idHWqPXJwnE?si=pqn6-J0ExltaeahL&start=5051" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><p class="paragraph" style="text-align:left;">A new <a class="link" href="https://www.beyondtrust.com/blog/entry/openai-codex-command-injection-vulnerability-github-token?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=how-command-injection-vulnerability-in-openai-codex-leads-to-github-token-compromise" target="_blank" rel="noopener noreferrer nofollow">BeyondTrust report</a> details a real command injection bug in OpenAI Codex, and yeah, this one is nasty.</p><p class="paragraph" style="text-align:left;">We’ve seen similar bugs lately but they’ve all been prompt injection - this one is straight command injection which is MUCH worse.</p><p class="paragraph" style="text-align:left;">According to BeyondTrust, the bug lived in the task creation flow, where the GitHub branch name could get reflected into shell during environment setup. That gave an attacker a way to run arbitrary commands inside the Codex environment and steal the victim’s GitHub user access token, which was the same token Codex was using to authenticate with GitHub on the user’s behalf. BeyondTrust says the issue affected the ChatGPT website, Codex CLI, Codex SDK, and the Codex IDE extension, and that the reported issues have since been remediated.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a2110c66-7808-4066-8b4c-56fc360aaffa/Screenshot_2026-04-01_at_2.44.42_PM.png?t=1775072717"/><div class="image__source"><span class="image__source_text"><p><i>Codex attack path</i></p></span></div></div><p class="paragraph" style="text-align:left;">What makes this one rough is where Codex runs. In <a class="link" href="https://developers.openai.com/codex/cloud/environments?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=how-command-injection-vulnerability-in-openai-codex-leads-to-github-token-compromise" target="_blank" rel="noopener noreferrer nofollow">OpenAI’s Codex cloud environment docs</a>, Codex says it creates a container, checks out your repo at the selected branch or commit, runs your setup script, and then starts the agent loop. So the branch name becomes part of the setup path for a real execution environment that can touch code, dependencies, and secrets.</p><p class="paragraph" style="text-align:left;">If attacker-controlled input is getting interpreted by bash there, you are owned.</p><p class="paragraph" style="text-align:left;">BeyondTrust says the branch parameter from the backend task request was reflected into the environment setup script. That means the branch name started being shell input. They first used that to trigger errors, then refined it into a payload that exposed the GitHub remote configuration and the embedded token. Once that worked, if a victim ran Codex against that repo and branch, the attacker could grab the OAuth token and pivot into GitHub.</p><p class="paragraph" style="text-align:left;">They found ways to make the payload work through GitHub branch naming itself, including tricks like <code>$&#123;IFS&#125;</code> so the branch would still be valid enough for GitHub while evaluating the way they wanted in bash. They also showed how Unicode ideographic spaces could make the payload look a lot cleaner in the UI than it really was.</p><p class="paragraph" style="text-align:left;">Still, BeyondTrust says the same bug class extended beyond the web experience. They report that local Codex clients stored auth material in <code>auth.json</code>, and that those tokens could be used to hit the backend API, pull task history, and recover task output there too. So this was not just a web portal issue.</p><p class="paragraph" style="text-align:left;">They reported the issue through Bugcrowd on December 16, 2025. OpenAI shipped an initial hotfix on December 23, a GitHub branch shell escape fix on January 22, and additional shell hardening plus tighter GitHub token limits on January 30. Public disclosure came later after coordination.</p><p class="paragraph" style="text-align:left;">Coding agents are inheriting the same ugly security problems we have already seen in CI systems, build pipelines, and developer tooling. Once you let an agent clone repos, run setup scripts, touch secrets, and authenticate to external services, input handling mistakes stop being quirky bugs and start becoming full compromise paths.</p><p class="paragraph" style="text-align:left;">Vulns are definitely back on the menu.</p></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
