<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Vulnerable U</title>
    <description>Infosec&#39;s favorite weekly newsletter for news, tools, and tips with 38,000+ CISOs, founders, change-makers, and straight up hackers.</description>
    
    <link>https://www.vulnu.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/lSfumbrEGk.xml" rel="self"/>
    
    <lastBuildDate>Sat, 12 Sep 2026 03:24:29 +0000</lastBuildDate>
    <pubDate>Fri, 11 Sep 2026 12:24:00 +0000</pubDate>
    <atom:published>2026-09-11T12:24:00Z</atom:published>
    <atom:updated>2026-09-12T03:24:29Z</atom:updated>
    
      <category>Mental Health</category>
      <category>News</category>
      <category>Cybersecurity</category>
    <copyright>Copyright 2026, Vulnerable U</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/71c1f7f0-15e9-4f22-932a-e61c0932a9e2/Newsletter_Thumbnail_2026_Bunny_Only.png</url>
      <title>Vulnerable U</title>
      <link>https://www.vulnu.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>🎓️ Vulnerable U | #185</title>
  <description>AI labs are taking an official stance that there is a high probability they are going to kill us all, and I guess other cyber news...</description>
  <link>https://www.vulnu.com/p/vulnerable-u-185</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-185</guid>
  <pubDate>Fri, 11 Sep 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-09-11T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>5 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2adae740-0ee7-4c57-b44a-09d6339a5039/Newsletter_Header.png?t=1789096464"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">It’s been hard to parse down what to cover the last few weeks. There is A LOT of stories taking up a lot of our attention. I’m trying to avoid too much random breach noise and stick to things that we can learn lessons from or are otherwise impactful/industry relevant.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: I got absolutely nerd sniped watching the speed of this tool built on top of security relevant data by Scanner - <a class="link" href="https://www.vulnu.com/p/the-question-nobody-can-answer-fast-enough?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">wrote up my impressions here.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=CzPKhdrqiFI&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">The latest Low Down</a> talking about the 153 million drivers licenses lost, people coming to the defense of TeamPCP hackers, Nigerian sextorion rings, and much more.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: We aren’t talking enough about <a class="link" href="https://youtu.be/Pu9uft6qomM?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">OAuth security risks</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="216000000-spy-t-vs-the-lg-smart-tv-"><a class="link" href="https://www.youtube.com/watch?v=Q9uefFYe6bM&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">216,000,000 Spy TVs, The LG Smart TV Problem</a></h3><p class="paragraph" style="text-align:left;">WTF is going on at LG? Last time it was 42% of their smart TV apps carrying a residential proxy SDK, alongside a Gamers Nexus video about adware on their $1,200 monitors. Steve Burke is back with two hours and fifteen minutes on the TVs themselves. Packet captures on retail OLED sets show the TVs enumerating everything on the local network. One test TV found 38 devices, including phones and watches belonging to staff who had nothing to do with the testing. Add nearby Wi-Fi names, signal data, and ACR fingerprints of whatever is on screen, all flowing back to LG&#39;s advertising side.</p><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/p/DdC840AsHRc/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><p class="paragraph" style="text-align:left;">They also reported RCE bugs to LG and used one to turn a G5 into a listening device, capturing room audio with the screen off and the ethernet unplugged, then uploading the file once the connection came back. Those bugs are still in disclosure so details are thin. The network enumeration and the ACR pipeline are the shipping product working as designed, which is the part that should actually bother you. Put the TV on your IoT VLAN and drive it with an Apple TV. (watch more <a class="link" href="https://www.youtube.com/watch?v=Q9uefFYe6bM&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and read more <a class="link" href="https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="are-pentests-obsolete-in-the-ai-era"><a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Are pentests obsolete in the AI era?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d5d04c20-ad4e-4fb8-871b-344e958c424c/Vuln_U_x_Intruder_July_2026.png?t=1784132905"/></div><p class="paragraph" style="text-align:left;">AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.</p><p class="paragraph" style="text-align:left;">This <a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Intruder blog</a> explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (<a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="i-resigned-from-anthropic-today"><a class="link" href="https://x.com/hilbertspaess/status/2097476196791709843?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">I resigned from Anthropic today</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0460125d-06ec-49dc-b9d5-f678e29d0567/Screenshot_2026-09-10_at_5.58.13_PM.png?t=1789081098"/></div><p class="paragraph" style="text-align:left;">Jacob Coxon, a pretraining researcher who worked at both OpenAI and Anthropic, quit Tuesday and posted why: both labs are racing to self-improving superintelligence and &quot;gambling with our lives.&quot; The thread did somewhere north of 150 million views overnight. Then Evan Hubinger, Anthropic&#39;s own Alignment Science Lead, <a class="link" href="https://x.com/EvanHub/status/2097497037956891126?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">quote tweeted it to agree</a>, saying the people inside &quot;really do earnestly believe AI could kill all humans&quot; and putting his personal number at greater than 10% within the decade. Bernie Sanders says he is introducing a bill to pause development and ban superintelligence. Musk called the whole thing a <a class="link" href="https://www.forbes.com/sites/siladityaray/2026/09/10/musk-touts-psy-op-and-mocks-ex-anthropic-staffer-who-warned-ai-could-kill-us-all/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">psy op</a>.</p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://www.forbes.com/sites/siladityaray/2026/09/10/musk-touts-psy-op-and-mocks-ex-anthropic-staffer-who-warned-ai-could-kill-us-all/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">reporting</a> also notes Coxon had been at Anthropic four months and walked two months short of his vesting cliff, which is either the price of a principled exit or a reason to read it carefully. (read more <a class="link" href="https://x.com/hilbertspaess/status/2097476196791709843?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://x.com/EvanHub/status/2097497037956891126?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.securityweek.com/anthropic-researcher-resigns-with-warning-about-the-dangers-of-ai-development/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="multiple-crypto-companies-warn-cust"><a class="link" href="https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Multiple crypto companies warn customers of phishing emails after alleged provider breach</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/93ad59ee-a8ae-4aa1-a2bd-3ba4c4e13f54/image.png?t=1789073933"/></div><p class="paragraph" style="text-align:left;">Thousands of crypto holders got phishing mail on Wednesday sent from real company domains, with SPF and DKIM passing and every instinct you have trained into your users passing right along with them. <a class="link" href="https://x.com/trezor/status/2097786518110609620?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Trezor</a>, CoinTracking and BitBox all confirmed it hit their newsletter subscribers. CoinTracking named the source as Brevo, the email marketing provider all three share, and BitBox noted that the other crypto companies getting hit were on the same platform. <a class="link" href="https://x.com/brevo_official/status/2098013044227915777?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Brevo</a> put out a notice Thursday saying an attacker had access to 120 customer accounts and used them to mail those clients&#39; contact lists, that the access is closed, and that a post mortem is coming. Trezor&#39;s lure was a critical security alert about an STM32 entropy vulnerability.</p><p class="paragraph" style="text-align:left;">The STM32 bug is invented, but Coldcard shipped a <a class="link" href="https://blog.coinkite.com/entropy-technical-backgrounder/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">real entropy failure</a> that cost holders around $89M in July, so the lure works on anyone who has been reading the news. Your marketing email vendor is now a load-bearing part of a hardware wallet&#39;s threat model, and one compromise there buys 120 sender reputations and every list behind them. Trezor is also still cleaning up the ShipMonk breach, <a class="link" href="https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">now at 81,000 customers</a> with names, phone numbers and shipping addresses, and customers have <a class="link" href="https://x.com/ellethereal/status/2097827558716780768?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">started reporting</a> malicious QR codes arriving by postal mail. (read more <a class="link" href="https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="detecting-and-countering-misuse-of-"><a class="link" href="https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Detecting and countering misuse of AI: September 2026</a></h3><p class="paragraph" style="text-align:left;">Anthropic published its threat intel report yesterday, eight months of actors it caught using Claude across seven harm areas. Everyone is covering the cyber section, and it earns it by being a crazy read. A Russian espionage operator whose tradecraft matches Midnight Blizzard hit more than 20 government and defense targets across Ukraine and Europe, running agents whose entire job was to watch whether security products flagged their malware and rebuild it until nothing did. Two undergrads at a Chinese university ran an exploit foundry producing more than a dozen possible zero days against appliance firmware in a single month. ShinyHunters affiliates, the same collective sitting on Florida&#39;s DMV data, dumped 2,100 Azure token sets across 40 tenants in 34 hours. Their own read on the trend is every technique in here is one you have already seen but who is doing the “work” changed from human to agent. Stolen credentials, unpatched edge devices, exposed services, SQL injection, phishing.</p><p class="paragraph" style="text-align:left;">Going deeper beyond cyber for a sec because again, this is crazy. A cell in northern Yemen used Claude Code in place of software engineers to build guidance software for a rocket, test-fired it, and was back in a session within hours working out why it failed. A Russian freelance team built an autonomous drone swarm designed for lethal engagement with a person target class and no human in the loop, trained on scraped Ukrainian combat footage. A China-based researcher&#39;s electronic warfare targeting suite switched its default scenario mid-project to twelve targets in Taiwan.</p><p class="paragraph" style="text-align:left;">And the biology section is the first time any AI company has published evidence of its own platform touching potential bioweapons work, including a reseller that tunneled around regional blocks and routed refused prompts to a competitor&#39;s more permissive model, with Claude writing much of that routing code because the developer described it as an over-refusal fix.</p><p class="paragraph" style="text-align:left;">Lets all keep the incentives in mind here. This is the vendor selling the model, publishing four days after the <a class="link" href="https://media.defense.gov/2026/Sep/08/2003992823/-1/-1/1/CSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">federal advisory</a> on Chinese distillation, in the same week its alignment lead put human extinction odds north of 10%. The case files are still the most specific public accounting anyone has of what this tooling does in the wrong hands. (read the full report <a class="link" href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and read more <a class="link" href="https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="attackers-drained-319-million-in-bi"><a class="link" href="https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Attackers Drained $319 Million in Bitcoin From Liquid Network, Then Returned 85% of Funds</a></h3><p class="paragraph" style="text-align:left;">Name your own bug bounty? On September 6 someone minted about 4,000 L-BTC that no bitcoin was backing, pushed it through SideSwap&#39;s peg-out service, and left with roughly 95% of the bitcoin in Blockstream&#39;s Liquid federation wallet. About $320M. Blockstream says the peg-out authorization key was never compromised, and neither were any others. The signers approved it because from where they sat the withdrawal looked completely ordinary. Root cause traces to a proof verification bug in Elements, the Bitcoin Core fork Liquid runs on.</p><p class="paragraph" style="text-align:left;">Then the attackers left an on-chain message declaring themselves white hats, opened a negotiation with Blockstream over OP_RETURN and PGP, and made the return conditional on the bug being fixed and every node patched first. Blockstream signed a message confirming the fix, and 3,400 BTC came back. The remaining 598.5 BTC, about $47M, they kept and called a bounty. Draining 95% of a federation&#39;s reserves and then setting your own fee is a novel reading of coordinated disclosure. (read more <a class="link" href="https://www.trmlabs.com/resources/blog/2026s-biggest-hack-to-date-attackers-drained-usd-319-million-in-bitcoin-from-liquid-network-then-returned-85-of-funds?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://therecord.media/liquid-network-blockstream-crypto-theft-hackers-keep-reward?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="singaporean-ringleader-of-245-milli"><a class="link" href="https://www.justice.gov/usao-dc/pr/singaporean-ringleader-245-million-cryptocurrency-racketeering-enterprise-pleads-guilty?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/94c9ef8e-ef4b-496b-8146-5c294c48f476/lam_2.png?t=1789072535"/></div><p class="paragraph" style="text-align:left;">Part of the Com, Malone Lam (22), pleaded guilty in DC this week to a RICO conspiracy count covering more than $245M in stolen and laundered crypto. The enterprise came together on gaming platforms, spread across California, Connecticut, New York, Florida and abroad, and ran on social engineering with the occasional home break-in. Lam picked the targets and assigned everyone their role.</p><p class="paragraph" style="text-align:left;">Like all these young pups who get arrested, the spending and bragging was a huge part of his downfall. DOJ lists nightclub tabs running to $500,000 a night, handbags given away at parties, watches from $100,000 to north of half a million, rental houses in LA, the Hamptons and Miami, private jets, a personal security detail, and a car collection topping out at $3.8M. They picked him up at his Miami rental in September 2025 and the status hearing is set for December 8. The entire $245M came out of phone calls and people who were willing to answer questions about their wallets. (read more <a class="link" href="https://www.justice.gov/usao-dc/pr/singaporean-ringleader-245-million-cryptocurrency-racketeering-enterprise-pleads-guilty?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and watch more <a class="link" href="https://www.youtube.com/watch?v=wW5VJZr77ak&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="shiny-hunters-hackers-claim-breach-"><a class="link" href="https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">ShinyHunters hackers claim breach of Florida &quot;DAVID&quot; DMV database</a></h3><p class="paragraph" style="text-align:left;">ShinyHunters says it pulled over 200,000 records out of <a class="link" href="http://www.flhsmv.gov/courts-enforcement/david/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">DAVID</a>, the Florida Highway Safety and Motor Vehicles system that law enforcement and court officials use to look up drivers. They told BleepingComputer they got in through a password reset flaw, took over multiple accounts belonging to DMV employees and an FBI agent, then walked the record IDs and saved the pages as they went. Their proof of breach was Jeffrey Epstein&#39;s DMV record. (<a class="link" href="https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="id-scan-confirms-breach-tied-to-153"><a class="link" href="https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">IDScan confirms breach tied to 153 million stolen driver&#39;s licenses</a></h3><p class="paragraph" style="text-align:left;">Following up on this one. IDScan has now confirmed that an unauthorized party accessed customer data in its cloud platform, which is the company Brian <a class="link" href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Krebs traced</a> on September 1 as the source behind a dark web service selling more than 153 million US and Canadian license scans, plus 10 million ID cards, 3 million travel documents and 579,000 medical cards. Krebs verified it by pulling his own record out of the thing. The FBI is investigating and the lawsuits were filed before the company acknowledged anything publicly. IDScan posted its <a class="link" href="https://idscan.net/notification-data-security-incident/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">notice</a> on September 4 with a noindex directive on the page so search engines would skip right past it, which <a class="link" href="https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">TechCrunch</a> spotted. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://idscan.net/notification-data-security-incident/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="mind-the-patch-gap-multiple-chinese"><a class="link" href="https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9fb1e37f-f90c-4971-a738-55f971d11e1d/image3-scaled.png?t=1789072505"/></div><p class="paragraph" style="text-align:left;">This is the good stuff. Researchers caught two separate Chinese threat actors, UTA0560 and JungleBamboo (APT31), running byte for byte identical exploit code against NGOs starting September 1. The chain is three bugs deep: a type confusion in Chrome&#39;s V8 for read/write inside the sandbox, a WebAssembly bug to get out of the V8 sandbox, then a Windows kernel bug to escape the renderer and land in the browser process. From there the payloads diverge. One group dropped a JScript backdoor. The other installed a credential stealing Chrome extension dressed up as Google Gemini.</p><p class="paragraph" style="text-align:left;">Low Level and myself tried to figure this one out to talk about on the podcast and it is REALLY hard to understand unless you’re a V8 expert. (read more <a class="link" href="https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="microsoft-patches-record-974-flaws-"><a class="link" href="https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days</a></h3><p class="paragraph" style="text-align:left;">With the power of AI! The vulnpocalypse continues. 974 CVEs, 723 of them in Windows, 999 total once you count the third party fixes bundled in. Two are already being exploited. One is a local privilege escalation in Windows ALPC, which is the same bug Volexity watched get used to break out of Chrome&#39;s renderer. The other is an improper link resolution flaw in the Windows Update stack that hands an attacker SYSTEM, and it is the first Windows Update Stack bug to be exploited in the wild. Both landed in <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">KEV</a> with a September 22 federal deadline. <a class="link" href="https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">ZDI</a> has Microsoft at 2,760 CVEs for the year so far, more than double the previous record with a quarter left to go.. (read more <a class="link" href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-185" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0c8abc71-bbf0-479d-836c-91857d4384ac/Screenshot_2026-09-10_at_5.44.18_PM.png?t=1789080263"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1e0610b0-da29-4556-9fe2-0592b8ecc7cc/Screenshot_2026-09-10_at_5.43.21_PM.png?t=1789080205"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/17f4b694-2003-421c-97e9-d87d061c82f0/Screenshot_2026-09-10_at_5.43.49_PM.png?t=1789080235"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The Question Nobody Can Answer Fast Enough</title>
  <description>Leveling up at the data layer is unlocking pathways for blue teamers I hadn&#39;t thought possible. </description>
  <link>https://www.vulnu.com/p/the-question-nobody-can-answer-fast-enough</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/the-question-nobody-can-answer-fast-enough</guid>
  <pubDate>Tue, 08 Sep 2026 21:55:54 +0000</pubDate>
  <atom:published>2026-09-08T21:55:54Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Ai]]></category>
    <category><![CDATA[Sponsored]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><i>Sponsored by</i><a class="link" href="https://fandf.co/4zETTGs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow"> Scanner.</a><i> They paid for this placement. The reporting, the opinions, and the parts where I go off on a tangent are mine.</i></p><p class="paragraph" style="text-align:left;">Every security team I have been on has had one question that arrives at the worst possible moment. Some vuln drops, some report gets written up, somebody senior reads a headline on their phone, and then my phone rings.<br><br><b>Do we run this? Are we exposed? Is it exploitable? Is it on the internet?</b><br><br>At one of the big banks I worked at, the head of cyber defense had a standing rule for the whole department. If he called and asked, he wanted an answer in 30 minutes. Seems like a totally reasonable ask. We could not do it. Our honest best case was about a week, because getting there meant network scans that took days to crawl the environment, a CMDB that nobody fully trusted, and a lot of very expensive people running very manual queries.<br><br>That was around 2015. The question has not changed since. The time it takes you to answer it is still the thing your program actually gets graded on, and most teams still measure it in days.<br><br>Post-AI, the attacker side of that clock is heading toward zero. Ours mostly is not.</p><h2 class="heading" style="text-align:left;" id="the-reason-your-answer-is-slow"><b>The reason your answer is slow</b></h2><p class="paragraph" style="text-align:left;">Here is the part that annoys me, because it has almost nothing to do with talent. Every team I have worked with could answer these questions if they had the data in front of them. They do not have the data in front of them, because at some point somebody did the math on per-gigabyte ingest pricing and started cutting.<br><br>It is common to see only a small slice of an org&#39;s log data actually searchable, with the rest sprawled across object storage, a warehouse, and whatever SaaS tool happened to generate it. The stuff that gets cut first is not because it lacks value, it’s because it is just enormous in volume: VPC flow logs, DNS, low-level EDR telemetry.<br><br>Those are also the exact sources that let you stitch a timeline together instead of staring at a wall of disconnected alerts.<br><br>Cliff Crosland, Scanner&#39;s CEO, told me the version of this that happened at his previous startup. They hit about a terabyte a day, and the Splunk renewal came in higher than their entire engineering budget. So they dropped VPC flow. Everybody drops VPC flow.<br><br>As your company grows, there is more to defend, more logs to defend it with, and a shrinking percentage of them you can afford to look at. Sequoia&#39;s Bogomil Balkansky<a class="link" href="https://sequoiacap.com/article/partnering-with-scanner-every-log-tells-a-story-if-you-can-find-it-fast-enough/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow"> wrote up his research on this</a> when they led Scanner&#39;s $22M Series A. One of the security leaders he interviewed put it about as bluntly as it can be put: they &quot;drown in logs we can&#39;t afford to keep,&quot; and then go blind on the ones they cannot afford to search.<br><br>I lived my own version of this at Reddit. When I got there, genuinely talented security engineers were spending their days as sysadmins keeping Elk alive. We tried a few things, including getting Chronicle basically free because we were a big GCP customer, and it was not ready for prime time back then. We went Splunk as the easy button, and then spent a couple of years clawing our way back off it onto BigQuery. The team <a class="link" href="https://www.reddit.com/r/RedditEng/comments/1ldu7p5/risky_business_desplunkifying_our_siem/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow">wrote the whole thing up publicly</a> after I left.<br><br>What I remember most is what I kept asking for and kept not getting. VPC flow and DNS.</p><h2 class="heading" style="text-align:left;" id="what-changed-is-who-is-asking-the-q"><b>What changed is who is asking the questions now</b></h2><p class="paragraph" style="text-align:left;">For twenty years the consumer of your security data was a person with a keyboard and a finite number of hours. That person rationed their threat hunts, because each one cost real time and sometimes real money. Athena queries at petabyte scale ran for hours and could cost several hundred dollars a pop, so you learned to be precious about which hunt you kicked off.<br><br>The consumer now is increasingly an agent, and agents do not ration anything. They iterate. They follow a thread, get a partial answer, and ask four more questions. An agent that has to wait six hours for a result is a batch job with a chat interface.<br><br>This is where query speed becomes the ceiling on everything you can build on top. Scanner says most of their usage now comes from agents rather than humans clicking around the UI, arriving over MCP, Claude Code, and their own set of skills. Agents drive about 80% of queries on the platform, and roughly a third of their customers had the <a class="link" href="https://fandf.co/4goOQCn?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow">MCP integration</a> in production within weeks of release.<br><br>That number tracks with what I have watched happen in my own workflow this year. Hunts I would have scoped, scheduled, and probably skipped are now things I just ask for.</p><h2 class="heading" style="text-align:left;" id="what-scanners-demo-actually-did"><b>What Scanner’s demo actually did</b></h2><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/J5YBnB09cqU" width="100%"></iframe><p class="paragraph" style="text-align:left;">I sat through a live one, and I have sat through a lot of these, so take the enthusiasm accordingly.<br><br>Cliff ran a search for a single IP address across petabytes of CloudTrail data spanning six months, sitting in S3. No field name specified, no schema defined ahead of time, just the IP. The index narrowed a petabyte down to a bit over a terabyte of files that could possibly contain hits, and returned results in tens of seconds. He then pivoted into aggregations across a roughly 300 terabyte slice and got those back in seconds too.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b87616a8-e8f2-4b76-bfe5-0cab2d78ef48/image.png?t=1788903895"/></div><p class="paragraph" style="text-align:left;">The mechanism is the interesting part, and it is why I think this is more than a pricing story. Scanner indexes data as it lands, schema agnostic, including deeply nested JSON straight out of S3 with every field searchable. Those index files live in cheap object storage in your own AWS account. At query time it spins up serverless compute, hits only the index files that matter, and spins back down. Cliff&#39;s team came out of distributed systems and Rust, and <b>the obsession with performance and speed shows.</b><br><br>Cost lands around 30 cents per terabyte actually scanned, and the whole point of the index is that it scans a fraction of what you store. That petabyte query cost a couple of dollars.<br><br>Turning your security logs into something that responds at roughly search engine speed is a good outcome on its own, because nobody enjoys watching a spinner at one in the morning during an incident.<br><br>What I cannot stop thinking about is what it lets you build on top.</p><h2 class="heading" style="text-align:left;" id="the-part-i-got-genuinely-nerd-snipe"><b>The part I got genuinely nerd sniped by</b></h2><p class="paragraph" style="text-align:left;">Right now the sequence is: a question forms in somebody&#39;s head, a human opens a tool, an investigation begins.<br><br>If a six month sweep costs about a dollar of query compute and a dollar of tokens and comes back in seconds, you can flip that sequence entirely. Threat intel lands. An agent with context on your actual environment decides whether it is even applicable, skipping the Microsoft-flavored intel if you are all AWS. It runs the sweep across six months of history. Then it posts to Slack before your CISO has finished reading the headline that would have generated the question.<br><br>Nobody ever opens an investigation. The answer just shows up.<br><br>Cliff showed me a beta of this running in their own Slack, and it is the shape of the thing. Today&#39;s KEV batch, IOCs extracted from each entry, swept against about ten months of log data, came back clean, with the reasoning attached for why it believed that.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/65b58b20-47ca-4ae8-abaa-f17fbcdf19bd/image.png?t=1788903978"/></div><p class="paragraph" style="text-align:left;">Extend it one more step and the trigger does not have to be threat intel at all. It can be the anomaly itself. Cliff&#39;s example was the Hugging Face and OpenAI mess I covered in the newsletter and on a bunch of videos/podcasts a few weeks back, where the weird activity was sitting in a package manager for months with nobody watching that corner. Base64 blobs in absurdly long directory names, megabyte-scale paths, the kind of thing that is obviously wrong the moment a human looks at it. Nobody looked, because that log source was never going to survive a per-gigabyte ingest budget.</p><p class="paragraph" style="text-align:left;">Cheap storage plus fast search plus an agent that never gets bored is a real answer to that class of problem, and it&#39;s the same logic behind <a class="link" href="https://fandf.co/4y5jrLa?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow">what it takes to stop an AI swarm. </a>The bottleneck stops being the query and starts being agent speed. If your whole data stack is faster than Claude, you’re winning.</p><h2 class="heading" style="text-align:left;" id="where-they-sit-in-a-very-crowded-ro"><b>Where they sit in a very crowded room</b></h2><p class="paragraph" style="text-align:left;">I made a joke at Black Hat this year that AI SOC vendors are undergoing carcinisation. Evolution keeps independently arriving at the crab body plan, and our industry keeps independently arriving at the same company. Two years ago the floor was full of differentiated products. This year it was forty variations of the same agent triaging the same alerts.<br><br>Scanner is deliberately standing somewhere else, and I asked Cliff about it directly. He does not want to build agents that plug into your entire environment and run response. His words: he wants to be an unbelievably fast data layer that AI SOC and MDR companies build on top of. Several of them already resell Scanner underneath their own offerings, because their customers want the agent without paying twenty years of SIEM feature accretion for the storage.<br><br>I think that is the right call, and selfishly it is the version I want as a builder. Give me the fast data layer and I will build my own harness on top. I never would have attempted this on BigQuery. Every time I hit run on a BigQuery query I was nervous I had just spent real money on a broken query I would find out about in twenty minutes.</p><h2 class="heading" style="text-align:left;" id="before-you-go-eval-them"><b>Before you go eval them</b></h2><p class="paragraph" style="text-align:left;">A few things worth knowing, because a sponsored post that only lists strengths is worthless to you and to me.</p><p class="paragraph" style="text-align:left;"><b>Deployment is AWS-only today.</b> Scanner will index data from anywhere, GCS buckets, Azure blob storage, Kafka, Snowflake, Okta, CrowdStrike, Google Workspace. The compute deploys into your AWS account, or into their managed environment if you are fine with the index files living in their bucket. GCP and Azure deployment are on the roadmap without a firm date. If you are a regulated Azure shop with low SaaS tolerance, that conversation is worth having early, and Cliff was upfront that customer demand is what decides which cloud comes next.</p><p class="paragraph" style="text-align:left;"><b>It is more of a practitioner&#39;s tool right now.</b> Cliff volunteered this before I could ask. Engineers get it immediately. CISOs who want a visual posture overview are less served today. Dashboards are the known gap and the thing they are working on. (I actually tried to talk him out of building dashboards at all. Practitioners begging for a performant tool is what’s driven adoption everywhere I’ve worked, though I’ll admit that’s shaped by the kind of shops I’ve worked at, mostly high tech places.)</p><p class="paragraph" style="text-align:left;"><b>Per-terabyte-scanned pricing means your agents can spend money.</b> A few dollars per hunt is nothing until an unsupervised loop runs a thousand of them overnight. Teams are handling this by batching medium and low severity work on a schedule and letting only high-severity alerts trigger immediately. Budget for it like compute, not like a license.</p><h2 class="heading" style="text-align:left;" id="where-this-leaves-us"><b>Where this leaves us</b></h2><p class="paragraph" style="text-align:left;">Ten years ago my honest answer to &quot;are we exposed to this&quot; was &quot;give me a week, and I will be guessing on day seven anyway.&quot;<br><br>A dollar fifty and thirty seconds would have been a hell of a trade.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://fandf.co/4zETTGs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=the-question-nobody-can-answer-fast-enough" target="_blank" rel="noopener noreferrer nofollow">Scanner</a></p><div class="custom_html"><iframe src="https://embeds.beehiiv.com/a6407365-5497-4de1-b83b-acb60b1ae802" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="border-radius: 4px; border: 2px solid #e5e7eb; margin: 0; background-color: transparent;"></iframe></div></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #184</title>
  <description>Massive drivers license data breach, McKesson breached by ShinyHunters, TeamPCP OSINT investigation, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-184</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-184</guid>
  <pubDate>Fri, 04 Sep 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-09-04T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fda4bd2d-ff1f-4d2e-9ec3-1ac05720ca95/Newsletter_Header.png?t=1788489972"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://info.legitsecurity.com/agenticappsec?utm_source=vulnerableu&utm_medium=newsletter2&utm_campaign=agentic-appsec-vulnerableu&utm_content=newsletter-ad" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3d368dda-b4ae-4c42-a53e-30d0d2ff0c07/Newsletter_Sponsor_Logo.png?t=1788482724"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Why do kids sports in Texas start in August? Cruel and unusual. I went to exactly 1 soccer game at 11:30am without a shadow in sight and only brought a camping chair. I felt like a complete rookie, and immediately placed a way too large Amazon order to never feel that way again.</p><p class="paragraph" style="text-align:left;">I’m now rolling up to games looking like Tom from Parks and Rec when he goes camping. Shade, fans, cooling towels, the works.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/91db3b7f-6177-4b65-a509-84d49c576a37/Screenshot_2026-09-03_at_1.21.11_PM.png?t=1788459679"/></div><p class="paragraph" style="text-align:left;">If you haven’t hopped on our new podcast bandwagon yet, what are you waiting for? Filming <a class="link" href="https://www.youtube.com/@lowdownpod?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">The Low Down</a> is the most fun I have every week. Sound off if you like what we’re shipping over there. If YouTube isn’t your thing, catch us on <a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Spotify</a>, <a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Apple</a>, or wherever you get your finest podcasts.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: hot take? $250k for a full chain <a class="link" href="https://x.com/mattjay/status/2095223210539168031?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">chrome exploit</a> is too low.</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=b9UMKfiP2j4&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">The Low Down episode</a> on the GTA 6 leaks, Omarchy 0days, and a bunch more (Thanks <a class="link" href="https://mazehq.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Maze</a> for the continued support!)</p><p class="paragraph" style="text-align:left;">🎤 Something I said: <a class="link" href="https://youtu.be/OJIsyQtdQzE?si=fcFDoBPlYNmza_Ua&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Great convo</a> with Cal dot com CEO on why they went closed source due to perceived security risk of being open source in the age of AI code scanners</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Woke up to NightmareEclipse dropping a <a class="link" href="https://x.com/intcyberdigest/status/2095419549537427480?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">CrowdStrike 0day</a> and <a class="link" href="https://x.com/nahrzf/status/2095400925535813971?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">RSA-260 being broken</a> getting announced via a tweet.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="fbi-probes-service-selling-153-m-dr"><a class="link" href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">FBI Probes Service Selling 153M+ Drivers Licenses</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8598d9c6-d266-45bc-835d-3ed59c409da2/nexus-totals.png?t=1788456800"/><div class="image__source"><span class="image__source_text"><p><i><a class="link" href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Source: KrebsOnSecurity</a></i></p></span></div></div><p class="paragraph" style="text-align:left;">Oh look the thing we all said would happen. A service that launched on a Russian cybercrime forum this week is selling scans of more than 153 million US and Canadian drivers licenses, plus ID cards, travel documents and medical cards. Each record carries front and back, plus the infrared and ultraviolet captures, with a timestamp on every file. Krebs found his own license in there as the free sample, then got a dozen friends and family to let him search for theirs. His mother&#39;s timestamps land a few seconds off his own, because the two of them handed their licenses across the same Hertz counter at the same time.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/FRbDaQQwWlY" width="100%"></iframe><p class="paragraph" style="text-align:left;">The thread runs to idscan[.]net in New Orleans, which does ID verification for Hertz, Target, FedEx, Caesars and a thousand-plus dispensaries, at 21 million verifications a month. The FBI&#39;s New Orleans field office opened an investigation Tuesday and pulled Krebs onto a call with half a dozen agents once word got around that he was digging. The seller claims a year of continuous exfiltration, and the record count climbed by roughly 400,000 in the 24 hours he was reporting it out. The site went dark within hours of publication, which fixes nothing. Zach Edwards makes the point I keep coming back to: every age verification law we pass pushes drivers licenses into another few thousand third party vendors, and a leaked UV scan of your ID is not a password you get to rotate. (<a class="link" href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="your-ai-coding-tools-ship-vulnerabi"><a class="link" href="https://info.legitsecurity.com/agenticappsec?utm_source=vulnerableu&utm_medium=newsletter2&utm_campaign=agentic-appsec-vulnerableu&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">Your AI coding tools ship vulnerabilities. Legit stops them before commit.</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f727e32-4c64-4a1e-8399-d4e7b91aba3f/image__12___1_.png?t=1788276964"/></div><p class="paragraph" style="text-align:left;">AI-generated code moves at machine speed, but most AppSec programs still rely on find-it, fix-it triage built for a slower era. Legit&#39;s Agentic AppSec platform closes that gap. It secures code the moment AI writes it, using business context (exposure, sensitivity, criticality) to separate real risk from noise. When issues do surface, autonomous agents remediate automatically and feed what they learn back into your AI coding tools, so fewer vulnerabilities get introduced with each cycle. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://info.legitsecurity.com/agenticappsec?utm_source=vulnerableu&utm_medium=newsletter2&utm_campaign=agentic-appsec-vulnerableu&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">See how Legit protects AI-first development.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="mc-kesson-discloses-breach-after-sh"><a class="link" href="https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">McKesson discloses breach after ShinyHunters claims patient data theft</a></h3><p class="paragraph" style="text-align:left;">About a third of the pharmaceuticals in North America move through McKesson, and we have shockingly few details about this massive breach. The company filed an 8-K on August 28 and told customers that attackers reached third party applications and took data tied to its oncology, multispecialty and medical-surgical units. ShinyHunters claimed responsibility and their MO can give us some assumptions on the way in. Vishing into some corporate Okta SSO accounts, then walking into Salesforce and Snowflake and pulling about a terabyte over four days before anyone noticed on the 25th. They asked for $55,236,150 with a 72 hour clock. McKesson never answered, and the Tuesday contact deadline came and went.</p><p class="paragraph" style="text-align:left;">The 284 million figure is getting quoted as patients, and the group itself corrected that to say it is a raw row count out of Snowflake, and they say they have not analyzed it yet. Take the claimed contents with that same salt. I’ve been saying this should be everyone’s top priority for a few years now as these threat actors are screaming their playbook from the rooftops. Your help desk identity verification process is the control that was supposed to catch this. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.mckesson.com/utility/cybersecurity/customer-cybersecurity-information-center/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">McKesson&#39;s notice</a>)</p><h3 class="heading" style="text-align:left;" id="unmasking-team-pcp-king-of-software"><a class="link" href="https://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Unmasking TeamPCP, King of Software Supply Chain Attacks</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5f03bb0d-c0a2-4c75-bc79-6a50cd773a4c/TeamPCP-arrest-AFP-1030x582.png?t=1788456800"/><div class="image__source"><span class="image__source_text"><p><i>Source: </i><i><a class="link" href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">AFP</a></i><i>, via </i><i><a class="link" href="https://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Flare</a></i></p></span></div></div><p class="paragraph" style="text-align:left;">Last week I covered the <a class="link" href="https://www.vulnu.com/p/vulnerable-u-183?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">two arrests in Perth</a>. Flare published the other half of that story, which is how one of them got found, and it is one of the cleaner OSINT walkthroughs I&#39;ve read. Start with one distinctive handle the crew used in earlier operations. Run it across social platforms and a HackerOne profile comes back with a real name on it. A Hugging Face account under the same handle lists a domain that later shows up as command and control for one of their worms. From there a school email address turns up in a credential dump, the password on it gets reused, and the reverse pivot lands on a personal Gmail. That Gmail leads to a TikTok under the same name, the TikTok shows off a Steam account, and the Steam profile picture is the same cat sitting in front of monitors that fronts the group&#39;s Telegram channel.</p><p class="paragraph" style="text-align:left;">This crew was loud on purpose, running Telegram channels, taunting victims on X, giving an interview to Forbes about being teenagers who couldn&#39;t find work. That appetite for credit is what made the campaigns spread, and it is also what left a distinctive avatar parked on a gaming profile since 2016 waiting for someone to look. (read more <a class="link" href="https://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">AFP release</a>)</p><h3 class="heading" style="text-align:left;" id="update-on-security-at-metr"><a class="link" href="https://metr.org/blog/2026-08-31-security-update/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Update on Security at METR</a></h3><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.vulnu.com/p/vulnerable-u-183?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Last week&#39;s lead</a> was OpenAI&#39;s Hugging Face postmortem, with METR and Redwood running the independent investigation. This week METR published its own two incidents, and the March one is going to live in my head rent free. A researcher with no sensitive access stood up a personal EC2 box behind Google auth to run some agents on. The app was vibe coded, and it failed open, silently turning authentication off and leaving an agent orchestration dashboard on the public internet for days.</p><p class="paragraph" style="text-align:left;">METR and OpenAI are also getting major criticism from the infosec community as nobody at METR is a cybersecurity expert, incident responder, forensics specialist, or anything like that. They eval’d the Hugging Face incident for their report and stuck just to the prompt and response transcripts, never looking at any of the logs. Zack has a good video on this topic <a class="link" href="https://www.youtube.com/watch?v=0HHuSBIViMc&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a>.</p><p class="paragraph" style="text-align:left;">Nobody caught it for three weeks because METR runs enormous evals and is used to weird rate limit errors, the tokens were donated so no invoice ever showed up, and there was no way to cap spend on that key. The May incident is a sustained campaign against them by someone financially motivated and hunting frontier model access, using agents to automate discovery, credential stuffing their auth providers and phishing staff. During the same window they had accidentally exposed a read-only query path on their public transcript viewer that a bug could push past into unpublished evaluation data, which an outside researcher found and got paid for. (<a class="link" href="https://metr.org/blog/2026-08-31-security-update/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="anthropic-warns-infostealer-malware"><a class="link" href="https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Anthropic warns infostealer malware is hijacking Claude sessions to drain usage</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e6095b1c-0a17-44c5-9aed-edb952550276/image.png?t=1788457778"/><div class="image__source"><span class="image__source_text"><p>source: <a class="link" href="https://www.reddit.com/r/ClaudeAI/comments/1w1jqsh/thank_you_anthropic_really/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">https://www.reddit.com/r/ClaudeAI/comments/1w1jqsh/thank_you_anthropic_really/</a></p></span></div></div><p class="paragraph" style="text-align:left;">It seems a lot of common infostealer malware has added a new goal to their arsenal. Anthropic started emailing affected users this week to say that commodity infostealers on their machines lifted live Claude session cookies, and somebody is now sifting Claude sessions out of the stolen piles and spending other people&#39;s usage. They are signing those accounts out, stripping saved payment methods, and refunding charges they can identify as unauthorized. Named families are the usual crowd: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on a handful of Macs. The Redditor who posted his email confirmed he&#39;d installed a pirated game which is how he caught some malware.</p><p class="paragraph" style="text-align:left;">Anthropic is explicit that the malware has nothing to do with Claude and arrived through ordinary downloads, and that&#39;s worth repeating because the headline reads the other way. (read more <a class="link" href="https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://www.reddit.com/r/ClaudeAI/comments/1w1jqsh/thank_you_anthropic_really/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">original email</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-exploit-critical-j-frog-art"><a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Hackers exploit critical JFrog Artifactory flaw to forge admin tokens</a></h3><p class="paragraph" style="text-align:left;">If you run self-hosted Artifactory, go patch. CVE-2026-82329 is an authentication bypass that works against the default configuration and hands an unauthenticated attacker with network access administrative privileges. JFrog fixed it on August 28 and says cloud instances were already covered. Days later watchTowr&#39;s honeypots caught real exploitation, with attackers minting themselves admin tokens and enumerating users, groups, credential sets and federated access topologies. CISA had not added it to KEV as of Wednesday.</p><p class="paragraph" style="text-align:left;">The detail that turns this from a patch into an incident is that Artifactory access tokens are independent credentials with their own lifecycle, so upgrading the binary does not invalidate a token an attacker already minted. Patch, then go find tokens and revoke them. Admin on the box everything else pulls from means an attacker can swap trusted artifacts and let your build systems distribute the result for them, which is the part Guillermo Rauch and Black Duck&#39;s Collin Hogue-Spears both flagged. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://docs.jfrog.com/releases/docs/jfrog-security-advisories?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">JFrog advisory</a> and <a class="link" href="https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a>)</p><h3 class="heading" style="text-align:left;" id="nigerians-extradited-to-us-for-sext"><a class="link" href="https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Nigerians extradited to US for sextortion, deaths of two teens</a></h3><p class="paragraph" style="text-align:left;">Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, were extradited from Nigeria on Thursday to face charges tied to sextortion schemes that ended in the deaths of two minors, one in Mississippi and one in North Carolina. Both were arrested in Nigeria in August 2023 under Operation Artemis, the joint international effort against Nigerian sextortion rings targeting American children. Adekunle&#39;s charges include sexual exploitation of a minor resulting in death, production of child sexual abuse material, coercion and enticement of a minor, and interstate threats with intent to extort. That death charge carries a 30 year mandatory minimum and a life ceiling. It took three years to get them into a US courtroom.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8bb3a429-ef4d-4dd2-b0a2-29f8fed17434/Screenshot_2026-09-03_at_1.00.43_PM.png?t=1788458448"/></div><p class="paragraph" style="text-align:left;">404 Media ran a piece the same week that explains why that three year gap matters. Erin West, who founded Operation Shamrock, and cybercrime researcher Paul Raffile set up decoy accounts posing as a teenager, got approached within days, and worked backward: a link that logged the scammer&#39;s IP put him in Lagos, a second attempt captured his location and his face, and a move to WhatsApp gave up a phone number that resolved to a name. They flew out, got GPS coordinates, and drove to his village. He refused to meet them, so West told him on the phone that they knew who he was and where he lived and that it was going to the FBI. His accounts went dark that day. Her read on it is the thing to carry: these are people who are not afraid of being arrested, and somebody showing up is the first consequence any of them have felt. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://www.justice.gov/opa/pr/two-nigerian-nationals-extradited-nigeria-united-states-face-sextortion-charges-north?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">DOJ release</a> and <a class="link" href="https://www.404media.co/how-cyber-sleuths-tracked-a-nigerian-scammer-to-his-doorstep/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">404 Media</a>)</p><h3 class="heading" style="text-align:left;" id="chinese-implants-in-the-supply-chai"><a class="link" href="https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Chinese Implants in the Supply Chain</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cd4fee7f-4ac9-4be8-a004-aaa5fa05496c/darklantern-scan.png?t=1788456801"/><div class="image__source"><span class="image__source_text"><p><i><a class="link" href="https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Source: VulnCheck</a></i></p></span></div></div><p class="paragraph" style="text-align:left;">Running theme around here lately, between the <a class="link" href="https://www.vulnu.com/p/vulnerable-u-183?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">LG smart TV proxy SDK and the car head units</a>, and now the router itself. VulnCheck published ENDLESSDOORS last month, a phone-home implant running as root with no authentication across twenty Zbtlink router models. Then they went shopping to see how far the supply chain reached, bought an $88 white-labeled unit on Amazon from a small New York company, and found two more implants on it. One listens on the WAN and executes commands with an authentication check that has a hardcoded bypass sitting in it. The other beacons outbound and supports hijacking your DNS, stealing the credentials that authenticate your ISP connection, and opening a reverse SSH tunnel home. They registered an abandoned backup C2 domain and sinkholed it. 392 devices reported in, 390 of them in China, mostly one carrier CPE model, one of them beaconing uninterrupted for nearly two years.</p><p class="paragraph" style="text-align:left;">Zbtlink&#39;s answer to the first implant was that it assists customers who explicitly request support. VulnCheck could not find any mechanism for a customer to request or authorize it, and since none of the three implants authenticate or encrypt anything, the vendor has no way to know who has used them. The same hardware surfaces under brand names across the US, Canada, Australia, Germany and the Philippines, so match on model number rather than the logo. On the cheap streaming box side, Bitsight found preinstalled apps on H96 Android boxes rewriting the device identity to look like a phone, clicking ads and renting the home connection out as a residential proxy, roughly 38,000 unique MACs in a single day of telemetry. There is no patch coming for any of this. Inventory it, put it behind strict egress control, or throw it away. (read more <a class="link" href="https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://www.vulncheck.com/blog/zbt-endlessdoors?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">ENDLESSDOORS writeup</a> and <a class="link" href="https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-184" target="_blank" rel="noopener noreferrer nofollow">Bitsight on the TV boxes</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/baee78b3-46ae-4581-8457-fb436a6697e1/Screenshot_2026-09-03_at_1.28.04_PM.png?t=1788460089"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6b685c66-50f1-4f84-a9e9-5ecb0dcda9a4/Screenshot_2026-09-03_at_1.30.28_PM.png?t=1788460236"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #183</title>
  <description>OpenAI detailed Hugging Face report, GTA 6 leaks, Omarchy 0days, TeamPCP arrests, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-183</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-183</guid>
  <pubDate>Fri, 28 Aug 2026 12:17:00 +0000</pubDate>
  <atom:published>2026-08-28T12:17:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/95a82b2d-b9fe-4a03-8c97-4a02f7473a47/Newsletter_Header.png?t=1787763289"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://torq.io/ai-soc-platform/?utm_source=third-party&utm_medium=newsletter&utm_campaign=202608-vulnerableu" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4b10eec1-5ccb-455f-b85b-a27ea0a4429c/Newsletter_Sponsor_Logo.png?t=1787763297"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Last night was the final day with a sunset later than 8pm for the year. I heard that and it immediately felt like I was now riding downhill. Summer is a bit oppresive here in Austin, but overall this was a good one.</p><p class="paragraph" style="text-align:left;">It reminded me of that Treebeard quote to Merry and Pippen: “I always like going south; somehow, it feels like going downhill” - so let’s not be hasty and hope for this all to get over with, and enjoy the last of summer together.</p><p class="paragraph" style="text-align:left;">If you haven’t - make sure to check out my new podcast with Low Level TV. We’re getting a ton of good feedback. We just recorded Episode 10 which apparently only about 20% of podcasts ever reach that milestone.</p><p class="paragraph" style="text-align:left;">Leave it to 2 guys who’ve been making weekly videos consistently for years to lock in I guess? Thanks, Maze, for all the continued support helping make the show happen.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/D_FsVapKwP8" width="100%"></iframe><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: John <a class="link" href="https://www.youtube.com/watch?v=nj9e2Qfe3Cc&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">walks through an investigation</a> of how TeamPCP got arrested</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Everything we know about the <a class="link" href="https://www.youtube.com/watch?v=eAGcu52R99E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">GTA 6 leaks</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Vibe coders have their <a class="link" href="https://www.usermag.co/p/vibe-coders-now-have-their-own-language?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">own language</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="the-hugging-face-incident-and-the-r"><a class="link" href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">The Hugging Face incident and the road ahead</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/45d7310e-28c6-4a6a-8197-e025dc839be1/Screenshot_2026-08-27_at_9.36.54_PM.png?t=1787884621"/></div><p class="paragraph" style="text-align:left;">I’ve been saying sandboxing is not something you accomplish in a Guardrails[.]md file. OpenAI&#39;s postmortem makes that case better than I did. Models running cyber evals in sandboxes with no internet and no way to talk to each other found both those restrictions were merely suggestions. They left files in the internally hosted package manager, the one service they could still reach, and turned it into a message board. Then they got that same service making outbound requests for them. Nine weeks later they had code execution across dozens of Hugging Face servers and credentials from four regions.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9a6c8bb1-e5b5-44f2-8613-a107ada70f6e/Screenshot_2026-08-27_at_10.14.07_PM.png?t=1787886897"/></div><p class="paragraph" style="text-align:left;">I hate personifying AI agents, and it is really hard to talk about this incident without slipping into that. Like how else do you say: the agents divided labor and started calling themselves a collective. One paused, reasoning that hitting a third party with leaked credentials was probably unauthorized. Another posted GO with a six-minute deadline. It went. <i>Peer pressure?</i> And the safeguards that would have caught all of this existed already, they just weren&#39;t switched on for internal evals, where the production harness cuts this behavior 100x and the monitors would have paged security a day early. (read more <a class="link" href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">technical report</a> and the independent <a class="link" href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">METR and Redwood investigation</a>)</p><h3 class="heading" style="text-align:left;" id="there-are-100-ai-soc-vendors-now-it"><a class="link" href="https://torq.io/resources/ai-soc-apocalypse/?utm_source=third-party&utm_medium=newsletter&utm_campaign=202608-vulnerableu" target="_blank" rel="noopener noreferrer nofollow">There are 100+ &quot;AI SOC&quot; vendors now. It&#39;s loud. What should you evaluate?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d1270d57-cbb2-4354-900a-842de7b1e5db/TORQ_AI_SOC_Apocalypse_Social_1280x720_1.png?t=1787694241"/></div><p class="paragraph" style="text-align:left;">A year ago, a handful of vendors claimed the &quot;AI SOC&quot; category. Today it&#39;s more than a hundred, and almost every one has slapped &quot;agentic&quot; on the box. Most stop at triage, wrap a chatbot around a legacy stack, or hide the AI&#39;s reasoning in a black box.</p><p class="paragraph" style="text-align:left;">The plainest test is if it can&#39;t take action across the threat lifecycle, it isn&#39;t an AI SOC. Torq put the whole argument, and how to vet any vendor, in the AI SOC Apocalypse Manifesto.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://torq.io/resources/ai-soc-apocalypse/?utm_source=third-party&utm_medium=newsletter&utm_campaign=202608-vulnerableu" target="_blank" rel="noopener noreferrer nofollow">Read it now</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="2-click-code-execution-on-omarchy-0"><a class="link" href="https://mehmetince.net/omarchy/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">2-click code execution on omarchy 0-day</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7e4e329b-e875-4808-9a30-a7c1a8a24cce/Screenshot_2026-08-27_at_4.21.59_PM.png?t=1787865724"/></div><p class="paragraph" style="text-align:left;">Doing my best TikTok influencer voice: <i>OMG you guys. Come with me to check out the viral new Linux Distro, Omarchy! It has everything. Including 0days!</i></p><p class="paragraph" style="text-align:left;">The proof of concept is a fake DHH hoodie drop that tells you to hit a keyboard shortcut to claim your size. That shortcut is Omarchy&#39;s download-video feature, which grabs the video off the page and then offers a click-to-play notification when it finishes. The problem is that the notification&#39;s play command got assembled partly out of the video&#39;s title, and the page decides what the title is. Mehmet Ince (@mdisec) wrote a title that turns the play command into a command of his own.</p><p class="paragraph" style="text-align:left;">Separately this week, the command that sets up SSH access announces it&#39;s configuring key-based auth, then starts the server with distro defaults that accept passwords and opens the firewall before any key is authorized.</p><p class="paragraph" style="text-align:left;">My main point on this whole story - just like the AI powered browsers. These Distros/Browsers are HARD to secure and get right. Going viral and working on this with a small team is bound to lead to vulns. Especially with all of the attention on this, they’re going to get found and published. Not saying don’t use it, but just know what you’re getting into here. (read more <a class="link" href="https://mehmetince.net/omarchy/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://github.com/basecamp/omarchy/pull/7926?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">fix</a> and the <a class="link" href="https://github.com/basecamp/omarchy/issues/8363?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">sshd issue</a>)</p><h3 class="heading" style="text-align:left;" id="the-gta-vi-leaks-are-breaking-the-i"><a class="link" href="https://cyberscoop.com/grand-theft-auto-6-data-theft-extortion-leaks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">The GTA VI leaks are breaking the internet. Security researchers have seen this before.</a></h3><p class="paragraph" style="text-align:left;">A threat actor, CyberLeek, has been releasing stolen GTA VI footage daily for over a week behind a manifesto about Rockstar going disc-less. The crypto wallets watermarked into the videos, the memecoin, and the offer to sell ad space on future leaks undercut the whole manifesto as they are just monetizing this. Katie Moussouris put it well: &quot;The manifesto is what keeps them watching.&quot; To me it just reads as an insider with access to a real build rather than a network intrusion, which matches how Take-Two (Rockstar parent co) is responding.</p><p class="paragraph" style="text-align:left;">Take-Two got DMCA subpoenas against Discord, Google, Microsoft and X, and the Discord one asks for device identifiers, login records and cloud storage contents for every person who spoke in three servers going back to June. Actually the same Windows Device ID that just caught the Scattered Spider hackers. Meanwhile fake Rockstar sites advertising a demo that does not exist are serving an infostealer. And of course with all the virality, torrents are up preteneding to be the unreleased game and are filled with <a class="link" href="https://x.com/vxunderground/status/2092289399060873477?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">malware</a>. (read more <a class="link" href="https://cyberscoop.com/grand-theft-auto-6-data-theft-extortion-leaks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="webinar-rumors-of-the-vulnpocalypse"><a class="link" href="https://www.rootevidence.com/resources/webinars/?utm_source=vulnerable-u&utm_medium=newsletter&utm_campaign=vulnu-2026-08" target="_blank" rel="noopener noreferrer nofollow">Webinar: Rumors of the Vulnpocalypse Have Been Greatly Exaggerated</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f70be823-2484-4304-a7de-1083b5a89b3c/image-1787244426319.png?t=1787846397"/></div><p class="paragraph" style="text-align:left;">The Vulnpocalypse was supposed to be here by now…so where is it? Root Evidence traced every confirmed exploitation of a published CVE since 2018: all 3,769 of them, against the 253,912 published in that window. They found that adversaries never touched 98.5% of vulns.</p><p class="paragraph" style="text-align:left;">Join Root Evidence co-founders Jeremiah Grossman and Robert &quot;RSnake&quot; Hansen on Wednesday, Sept. 2 for a first look at the data in their upcoming Vulnpocalypse Report. Attendees get the full report before it&#39;s publicly released.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.rootevidence.com/resources/webinars/?utm_source=vulnerable-u&utm_medium=newsletter&utm_campaign=vulnu-2026-08" target="_blank" rel="noopener noreferrer nofollow">Save Your Seat</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="australian-police-arrest-two-over-t"><a class="link" href="https://techcrunch.com/2026/08/27/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor-openai-and-others/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others</a></h3><p class="paragraph" style="text-align:left;">Cat hacker down! Two men from Western Australia, 21 and 23, appeared in Perth Magistrates Court on Thursday facing a combined 14 charges, accused by the AFP and the FBI of being principal participants in TeamPCP. That&#39;s the crew behind the March compromises of Trivy, Checkmarx KICS and LiteLLM, with the European Commission, Mistral, GitHub, OpenAI and Mercor also on the list. Police put it at more than a thousand organizations, over half a million stolen credentials and at least 300GB of data.</p><p class="paragraph" style="text-align:left;">We covered this ad nauseum because the pattern was super clear and effective: poison a tool developers already trust, then use what falls out of that compromise to reach the next one.</p><p class="paragraph" style="text-align:left;">Krebs had been talking to the alleged former leader, who goes by Ellis, since July, and that interview is the part worth your time. He claims he cleared roughly <i>$20,000</i> total. A thousand organizations, half a million credentials …twenty grand. He also told Krebs he is &quot;nowhere close to a skill level where I am comfortable,&quot; which is certainly interesting given how successful they were. It also really shines light on why a lot of people are cheering them on for exposing super easy weaknesses in the supply chain house of cards. Your build pipeline wasn’t tough enough against someone who describes himself as still learning. (read more <a class="link" href="https://techcrunch.com/2026/08/27/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor-openai-and-others/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Krebs&#39; interview</a>)</p><h3 class="heading" style="text-align:left;" id="the-infrastructure-quartermaster-in"><a class="link" href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">The Infrastructure Quartermaster: Inside a China-Nexus State Enablement Model</a></h3><p class="paragraph" style="text-align:left;">DOJ and the FBI seized three domains on Wednesday and killed the two platforms running behind them. Court documents name a PRC group, QTFY, working out of a Nanjing tech company, with confirmed victims including NASA, the Federal Reserve, DOE, DOJ, HHS, NIH and the Senate across about eight years. QTFY rents the capability, and its customers do the breaking in, hence “Quartermaster.” What it rents is a scanning platform that finds and profiles targets, an encrypted relay network to reach them through, and a preconfigured router that gets an operator onto that network.</p><p class="paragraph" style="text-align:left;">Rather than grinding out a botnet from compromised home routers, they bought premium access on a Chinese commercial proxy service, so espionage traffic rides alongside real paying consumers and rotates on its own. I’d read the IOCs and the CVE list that they are hitting and bang out some detections since this is just a speed bump in infra takedown. (read more <a class="link" href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="not-another-log-4-shell-a-serialize"><a class="link" href="https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Not Another Log4Shell: A Serialized-Event Receiver Boundary</a></h3><p class="paragraph" style="text-align:left;">We all heard an echo of a word this week that probably sent shivers down spines. Or at least brought back some sleepless night memories. &quot;Log4j RCE.” Log4j2 (Electric Boogaloo) went floating around. A public PoC exists, but from what I can tell it is mostly a nothing burger. Go ahead and use this as an excuse to test that if this was real you’d be able to respond and find all your log4j installs quickly. But this by default is not exploitable. Highly conditional.</p><p class="paragraph" style="text-align:left;">You need one of these network listeners running, an untrusted peer who can reach it, a usable gadget library already on that machine, and no JVM-level filter in the way. Ordinary logging never touches this path, and finding log4j-core in an SBOM proves nothing about exposure. There&#39;s no CVE and no fixed release, and Apache treats it as hardening. A public PoC exists. Go find out whether you run one of these listeners at all, and kill the ones you don&#39;t need. (read more <a class="link" href="https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://github.com/apache/logging-log4j2/discussions/4168?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Apache discussion</a>)</p><h3 class="heading" style="text-align:left;" id="first-android-malware-targeting-aut"><a class="link" href="https://securelist.com/android-head-unit-malware/121106/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">First Android malware targeting automotive head units</a></h3><p class="paragraph" style="text-align:left;">A few weeks back it was LG smart TVs shipping an SDK that rented your living room out as a residential proxy node. This week it&#39;s your car dashboard. Kaspersky found the first malware built specifically to infect car head units, targeting Android units running firmware from DoFun, whose own site claims more than 30 million vehicle owners. The way in was the head unit&#39;s own updater. The preinstalled app that handles software updates takes its instructions from a server the attackers got control of, so the malware arrived down the same pipe as legitimate updates.</p><p class="paragraph" style="text-align:left;">The malware supports a decent range of commands and the only one Kaspersky watched anybody actually use was the one that installs the proxy, just like the Smart TVs. Nobody is steering your car with this. What they want is the thing sitting in your driveway with a SIM slot and a permanent connection, because traffic sourced from there looks like a person. (read more <a class="link" href="https://securelist.com/android-head-unit-malware/121106/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="ali-express-webpage-keeping-multipo"><a class="link" href="https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting</a></h3><p class="paragraph" style="text-align:left;">This got caught because it broke a guy&#39;s headphones. Matt Callaghan noticed his multipoint pair would not hand back to his phone whenever an AliExpress tab was open, and muting the tab did nothing, because there was no video or audio player to mute. Digging in, he found two obfuscated scripts from Alibaba&#39;s anti-abuse stack generating a tone, measuring how his machine rendered it, and routing the result to the system audio output at zero volume. Nothing to hear, and the audio path stays busy the whole time.</p><p class="paragraph" style="text-align:left;">The audio measurement is one input into a much larger fingerprint that also pulls canvas, graphics, hardware details and pointer behavior. Tom Ritter on the Firefox team reports they neutered the audio piece back in version 118, with 99.24% of users landing in one of three buckets that differ only by CPU, and a long tail of 48 people with strange enough hardware to be unique. He expects Chrome, Brave and Safari have similar defenses. Callaghan solved his own problem by blocking the two scripts. Fingerprinting works right up until it stops somebody&#39;s music. (read more <a class="link" href="https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://ritter.vg/blog-webaudio_alibaba.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="comcast-adds-motion-sensing-to-mill"><a class="link" href="https://techcrunch.com/2026/08/18/comcast-adds-motion-sensing-to-millions-of-its-newer-routers-with-a-privacy-catch/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Comcast adds motion sensing to millions of its newer routers, with a privacy catch</a></h3><p class="paragraph" style="text-align:left;">Comcast is now selling WiFi Motion detection as part of its privacy-invading repertoire. You nominate a few stationary devices around the house, a speaker or a thermostat, and the gateway watches how bodies moving between them disturb the signal. It&#39;s sensitive enough that Comcast ships tuning to filter out pets under 40 pounds and warns it can&#39;t reliably tell a small dog from a small child. The capability has quietly existed since 2024, so the launch is really a marketing event.</p><p class="paragraph" style="text-align:left;">The catch is in Xfinity&#39;s own <a class="link" href="https://www.xfinity.com/support/articles/wifi-motion?pageid=7194ef805fa2d04b0f7e8c9521f97343&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">support documentation</a>, which says Comcast may hand information generated by your WiFi Motion to third parties &quot;without further notice to you&quot; for a law enforcement investigation, any dispute Comcast is party to, or a subpoena. What it doesn&#39;t say is what gets kept or for how long. So there&#39;s a record of when people move around your house sitting somewhere with an unpublished retention policy.</p><p class="paragraph" style="text-align:left;">Between this and the browser audio fingerprinting - I’m just seeing some bad misuse of radio frequencies as everyone is getting creative to privacy intrusions when our protections get better. (read more <a class="link" href="https://techcrunch.com/2026/08/18/comcast-adds-motion-sensing-to-millions-of-its-newer-routers-with-a-privacy-catch/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="chrome-152-stable-327-security-fixe"><a class="link" href="https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">Chrome 152 stable: 327 security fixes</a></h3><p class="paragraph" style="text-align:left;">Chrome 152 shipped Tuesday with 327 security fixes, ten of them critical and most of those memory-safety bugs in the graphics and UI layers. Nothing reported as exploited in the wild. The interesting read is the credit list, where the overwhelming majority say &quot;Reported by Google&quot; and only a couple dozen carry an outside name. Two of those belong to XBOW, the AI pentest outfit. Top bounty was $25,000 for a critical graphics bug found by a researcher going by Goodluck. Restart your browser. (<a class="link" href="https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-183" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/88cf560f-c1f1-409b-ad92-6e6b4c641b0f/Screenshot_2026-08-27_at_10.24.52_PM.png?t=1787887508"/><div class="image__source"><span class="image__source_text"><p>zoom in. got a <i>good</i> chuckle</p></span></div></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0c49e162-349a-4fdc-8c6f-014e3dd0f855/Screenshot_2026-08-27_at_10.24.40_PM.png?t=1787887505"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/90d19391-f781-4a6b-84dd-ce95d154427b/Screenshot_2026-08-27_at_10.24.31_PM.png?t=1787887502"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #182</title>
  <description>Rust supply chain attack, Big crypto stealing browser extension campaign, AI is critical Infrastructure now, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-182</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-182</guid>
  <pubDate>Fri, 21 Aug 2026 12:43:00 +0000</pubDate>
  <atom:published>2026-08-21T12:43:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/74de4498-a843-408d-8773-720c87caef7b/Newsletter_Header.png?t=1787233521"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e5009ce8-470c-4cd2-876e-627d235bca8d/Newsletter_Sponsor_Logo.png?t=1787233528"/></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">I’m still not caught up post Vegas. Absolutely buried this week! It’s not just the stuff you miss from being out its the weeks leading up to it that you kick to “after blackhat” that will get you.</p><p class="paragraph" style="text-align:left;">We’ve been working a TON on the podcast lately so if you haven’t checked that out yet, make sure you do. We’re getting tons of good feedback and we’re excited with the direction it’s going and everything we have planned.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Asked the community why npm/PyPi get more supply chain issues than Rust. <a class="link" href="https://x.com/mattjay/status/2090480928904618353?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Got some interesting replies.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: The latest episode of <a class="link" href="https://www.youtube.com/watch?v=h10UTCc6fxY&t=1s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">The Low Down was fire</a>. AI comitting felonies, WiFi Pineapple on a plane panic, and North Korea 0days.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Nasty Google Doc malware technique <a class="link" href="https://www.youtube.com/watch?v=sql1XWAtPOY&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">targeted the wrong people!</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: This <a class="link" href="https://x.com/matthew_d_green/status/2088253720303694039?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">thread by Matthew Green</a> about what happens when easy bugs dry up and law enforcement still needs access.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="post-def-con-phishing-uses-google-d"><a class="link" href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware</a></h3><p class="paragraph" style="text-align:left;">If you came home from Vegas to a friendly DM in broken English about going to someone&#39;s conference, turns out it was a scam. Shocked. My hook on this one is “dumbest hacker of the year?” Who targets malware analysts publicly on Twitter with malware? On August 9 an X account posing as CoinDesk&#39;s VP of marketing DMed a Huntress researcher and sent over a &quot;planning doc.&quot; Opening it in Google Docs renders a custom Apps Script sidebar that asks for an encryption key, which the actor helpfully supplies in DMs, and which fails on purpose. The sidebar then offers to fix it: ClickFix instructions for macOS (curl piped to zsh), a .dmg with steps to bypass Gatekeeper, or a ClickOnce installer on Windows signed with a cert from a Norwegian daycare company. Russian comments throughout the code.</p><p class="paragraph" style="text-align:left;">When the researcher stalled, the actor sent a second lure the next day, a fake DocSend installer signed with a stolen Discord cert. That one drops NetSupport RAT. The researchers figured, why not keep getting them to send us their bag of tricks and said they were on Linux at which point the threat actor offered to invest $1M in their company? Who knows where that part of the scam would’ve led but this is a good write-up of a unique combination of techniques I hadn’t seen before, just happens to be driven by not the brightest bulb in the shed. (<a class="link" href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="attackers-are-hijacking-fortune-500"><a class="link" href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_github&utm_content=blog" target="_blank" rel="noopener noreferrer nofollow">Attackers Are Hijacking Fortune 500 Brands to Spread Malware</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0c04c404-f58f-4513-9e0c-8c879a3e66c9/FakeGit_Island.png?t=1787078970"/></div><p class="paragraph" style="text-align:left;">A sprawling campaign of roughly 7,600 malicious GitHub repositories is hiding behind dozens of trusted brands. Attackers used the names of Fortune 500 companies such as Walmart, Amazon, Uber and Tesla, along with major entities like Databricks and the SEC. Island dubbed the tactic “AgentBaiting” because it uses 800+ fake AI Skills and MCP servers to exploit how developers and AI agents discover software—and turn brand trust into a malware delivery mechanism.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_github&utm_content=blog" target="_blank" rel="noopener noreferrer nofollow">Read the Research</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="two-popular-rust-crates-arrayref-an"><a class="link" href="https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b7701e1a-4ff9-408c-aab8-80eecca3881b/image.png?t=1787258327"/><div class="image__source"><span class="image__source_text"><p>source: aikido booth @ blackhat</p></span></div></div><p class="paragraph" style="text-align:left;">Aikido caught this one today, and by download count it is the largest Rust crate compromise so far. Two crates from the same maintainer, arrayref (244M downloads) and append-only-vec (4M), suddenly picked up a dependency on a package called proc-macro1. That is a typosquat of proc-macro2, copying the real crate&#39;s description, author name and docs to pass. Both compromised crates ship the genuine upstream library code. The entire compromise is one injected line in each Cargo manifest.</p><p class="paragraph" style="text-align:left;">We’ve been seeing this a ton in npm and a bit in PyPi but rarely in Rust. I think its a combination of popularity, and also a bit of the culture of Rust doesn’t just include random packages for every little thing like JS does. It also stood out to me that this one didn’t try to worm like the npm malware does. Just pretty traditional infostealer malware.</p><p class="paragraph" style="text-align:left;">The malicious logic lives in proc-macro1&#39;s build[.]rs, which Cargo runs automatically, so compiling a project that pulls in either crate is enough. Bad versions are arrayref 0.3.10 and append-only-vec 0.1.9. If a build machine pulled either, rotate whatever that machine could reach, because the payload ran with your developer&#39;s permissions. (<a class="link" href="https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="77-firefox-extensions-linked-to-cry"><a class="link" href="https://socket.dev/blog/firefox-crypto-wallet-theft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">77 Firefox Extensions Linked to Crypto Wallet and Credential Theft</a></h3><p class="paragraph" style="text-align:left;">This blog is super long because the attacker’s campaign is pretty broad. It’s actually kind of wild that all of these are attributed to the same campaign because the strategy and packaging is very different for all of them.</p><p class="paragraph" style="text-align:left;">Socket is tracking 77 linked Firefox extension identities, 40 of them confirmed malicious, running since at least March and impersonating OKX, Rabby and TronLink. Three theft models across the malicious set. Seven use attacker-controlled Supabase projects as a remote switch, where flipping one value in a public_notes table turns the extension&#39;s popup from a working notepad into a wallet phishing page with no update and no re-review. Fifteen embed the phishing flow directly and ship recovery phrases to Cloudflare Workers. Thirteen modified Rabby builds hook persistAllKeyrings() and POST the serialized keyring over plain HTTP on port 9000 before Rabby encrypts it locally, while the wallet keeps working normally.</p><p class="paragraph" style="text-align:left;">Thirty-seven of the 77 are advertised as password managers, VPNs, dark mode toggles and note takers, and all they actually do is pull live football scores from API-Sports using one shared API key. Nine confirmed-malicious identities started life as those sports shells before a later version under the same Firefox ID got swapped for wallet code. Several of the Supabase loaders request only storage and tabs permissions, so anything scoring extension risk on requested permissions rates them clean. (<a class="link" href="https://socket.dev/blog/firefox-crypto-wallet-theft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="operation-camera-swarm-over-14000-d"><a class="link" href="https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia</a></h3><p class="paragraph" style="text-align:left;">Two IP camera stories this week. First, Hunt[.]io recovered an entire operator toolkit because the operator served their own working directory over an open HTTP server. Over 14,500 Dahua cameras in 35 days across three parallel paths: credential brute force on port 37777, the 2021 auth bypass pair CVE-2021-33044 and CVE-2021-33045, and Dahua&#39;s cloud relay, which will reach a camera behind NAT from a serial number alone. 1,923 cameras got a backdoor account (p2pwn / p2password) installed over RPC that survives a password change and most factory resets.</p><p class="paragraph" style="text-align:left;">So not only are we leaving a bunch of cameras on the Internet, but they are catching vulns from 2021 that work on them all.</p><p class="paragraph" style="text-align:left;">Second story on a similar topic but completely separate - Slovakia&#39;s NBU published an alert on NERO R-ONE speed cameras: a backdoor granting shell and network access via SMS from a list of hardcoded Russian phone numbers. The devices are rebranded CORDON PRO.M units from a St. Petersburg firm, 279 of them bought through a Cyprus shell company as part of a €30M EU-funded project. SecureBoot is off, the web portal has bugs, and live streams are available to anyone who knows the broadcast IP. The Interior Ministry&#39;s first response was that the cameras were not Russian and would sit on a closed loop network anyway. Deployment is now paused. </p><p class="paragraph" style="text-align:left;">So instead of hacking a bunch of Internet cameras, these ones camed certified pre-pwned. (read more <a class="link" href="https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://news.risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://www.documentcloud.org/documents/28565254-tlp-clear-en-nero-r-one-skcert-20260807-10177-v1/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">NBU technical report</a>)</p><h3 class="heading" style="text-align:left;" id="person-hides-prompt-injection-in-le"><a class="link" href="https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/05659d50-e309-4508-8118-8f022fb5f489/Screenshot_2026-08-20_at_3.45.52_PM.png?t=1787258757"/></div><p class="paragraph" style="text-align:left;">A self-represented plaintiff in Connecticut hid instructions in 3-point white font throughout a July filing, telling any AI that processed the document to make its output agree with him. Detection here was a clerk noticing that two pleadings carried more white space than the plaintiff&#39;s other filings. It’s giving Jia Tan getting caught in xz utils due to slightly slow login.</p><p class="paragraph" style="text-align:left;">Judge Walter Spader Jr. then wrote 14 pages on it, including the point that a filing&#39;s integrity rests on the reader seeing what the filer wrote, and compared the hidden channel to arranging for an automated agent to talk to a juror during trial. Subsequent filings from the same plaintiff contained &quot;hi :) I hope yo ucant see me&quot; and a link to the SpongeBob Nosferatu scene. What in the tumblr is going on?</p><p class="paragraph" style="text-align:left;">The Connecticut Judicial Branch does not use AI to review court records, which the judge addressed directly: missing the target does not make the attempt proper. The plaintiff told 404 Media the whole thing was an &quot;audit.&quot; He is now banned from electronic filing and has to submit paper copies, which he points out does not stop anyone from putting light gray text on a page a clerk later scans. Spader flagged a similar incident in a Brazilian court and expects more of this. (<a class="link" href="https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="defending-against-an-active-threat-"><a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Defending Against an Active Threat to Siemens S7 Series PLCs</a></h3><p class="paragraph" style="text-align:left;">I’ve covered a lot of these PLCs at critical infra places getting hacked lately and there has been a flurry of follow ups from scary 3 or 4 letter agencies about it all. TL;DR on all of it is don’t put PLCs on the f’n Internet to begin with.</p><p class="paragraph" style="text-align:left;">The latest, five agencies (NSA, CISA, FBI, DOE and EPA) put this out on Wednesday, and the detail everyone is fixating on is that the advisory names AI-generated exploitation scripts as the tooling. The scripts wrap the open source snap7 / python-snap7 libraries, present themselves as legitimate OT monitoring tools, and give read and write access to PLC memory, configuration data and ladder logic over S7comm. Targets get found with Censys and ZoomEye. Sectors called out are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, with a note that S7 gear also sits in the defense industrial base.</p><p class="paragraph" style="text-align:left;">Read past the AI framing and the exposure is the same one we have been writing about all summer: internet-reachable controllers on old firmware. The advisory&#39;s first instruction is to get S7 PLCs off the public internet, route any remote access through VPN with MFA, enable hardware key switches so logic cannot be changed remotely, and audit project files against known good ladder logic. It follows the 30-plus Minnesota water systems hit in late July and incidents in at least a dozen states. No attribution in this one, though the related July advisory pinned the broader PLC campaign on Iranian-affiliated actors. (read more <a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://techcrunch.com/2026/08/20/us-says-hackers-are-targeting-vulnerable-water-systems-with-the-help-of-ai/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="going-with-the-flows-distinct-clust"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia</a></h3><p class="paragraph" style="text-align:left;">Google is tracking three Russian espionage clusters going after academics, defense contractors, diplomats and think tanks across Europe and the US, and the tradecraft is all authentication abuse. App passwords, OAuth tokens, device codes, WhatsApp device linking. Every path ends with the victim approving something their provider treats as a normal action, so MFA holds and the mailbox gets read anyway. UNC6293 and UNC7005 look like APT29 sub-clusters handling initial access. UNC6293 runs quiet, fewer than five targets at a time, diplomatic lures. UNC7005 is louder and was behind July&#39;s hotel WiFi captive portal redirects that served device code phishing, plus VIDAR and ATOMIC delivered through fake conference sites.</p><p class="paragraph" style="text-align:left;">The WhatsApp operation is a fun one to hone in on for your teams. The target believes they are joining a secure call, links their account to the actor&#39;s device, and the page records their audio and video and ships it out. UNC5976 runs separately with heavier malware, focused on Ukrainian and Armenian defense through fake file-sharing OAuth phishing. All of it leans on personal accounts and encrypted messengers where corporate logging never reaches. Detection lives in consent grants, app password creation and device link events. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="net-scaler-adc-and-net-scaler-gatew"><a class="link" href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939&articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_19489_and_CVE_2026_19490&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490</a></h3><p class="paragraph" style="text-align:left;">Another pre-auth bypass on the appliance that fronts everyone&#39;s remote access. CVE-2026-19490 lets an unauthenticated attacker get past authentication on a NetScaler acting as a Gateway or AAA vserver, which is the entire job of the box. Rapid7 <a class="link" href="https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">says</a> it has not seen exploitation yet and still recommends treating this as emergency patching, and the track record backs that up. Twenty-two Citrix bugs have been exploited in the wild over the past five years, six of them in ransomware, and when the March pair dropped, attackers were on them within days and CISA gave federal agencies three days to patch. ShadowServer currently sees north of 22,000 ADC and 1,800 Gateway instances answering on the internet.</p><p class="paragraph" style="text-align:left;">Recent builds are only affected when a SAML action is configured. Older builds are affected by any Gateway or AAA vserver configuration at all, so the further behind you are, the more likely you are already in scope regardless of how you do auth. Citrix published grep-able config strings for this and for the SIP ALG denial of service that shipped with it, so scoping is one pass over your running config rather than an afternoon with a version matrix. If you get a hit and cannot take an outage tonight, Global Deny List signatures through NetScaler Console are the stopgap. An auth bypass leaves behind activity that looks authenticated, so budget time to hunt after the upgrade. (read more <a class="link" href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939&articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_19489_and_CVE_2026_19490&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="pacing-model-development-in-an-era-"><a class="link" href="https://openai.com/index/pacing-model-development-cyber-capabilities/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Pacing model development in an era of cyber-critical capabilities</a></h3><p class="paragraph" style="text-align:left;">OpenAI decided it’s models have committed too many felonies recently and paused reinforcement learning (RL) training on deployment-bound models for two weeks. They still have their largest planned frontier run on hold, after the Hugging Face incident and a preliminary finding on August 7 that its upcoming Astra model may hit the Critical cybersecurity threshold in their Preparedness Framework.</p><p class="paragraph" style="text-align:left;">The rebuild looks a whole lot like a security engineering program to me: stronger sandboxes for anything executing model-generated or untrusted code, and network segmentation so one compromised workload cannot reach the internet or internal systems on its own. (AKA the thing we all said when we read that Hugging Face incident)</p><p class="paragraph" style="text-align:left;">Activation classifiers inspect sampled tokens, anything flagged goes to automated investigators that review tool calls, available reasoning and the full action sequence, and the target is an alert within 30 minutes. If the safety, security and research teams cannot conclusively call it a false positive within another 30 minutes, they are expected to pause the activity. It applies to all tool-using RL training and evals at Sol capability or above, plus all Astra inference with tools, and OpenAI estimates it adds around 20% to inference compute on monitored workloads. A company voluntarily paying a fifth of its compute and pausing its biggest training run is a real signal about what they think these models can do. (<a class="link" href="https://openai.com/index/pacing-model-development-cyber-capabilities/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="the-push-to-designate-ai-as-the-nex"><a class="link" href="https://cyberscoop.com/ai-critical-infrastructure-designation-cisa-report/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">The push to designate AI as the next critical infrastructure sector</a></h3><p class="paragraph" style="text-align:left;">A new report from Americans for Responsible Innovation argues AI should get formal critical infrastructure status with CISA as the lead agency for its cyber protection. Their scope is wide: frontier models, model weights, datacenters, AI chips, essentially the whole stack. The case is that AI is now embedded in everything, concentrated among a handful of companies, and that an attack on it cascades into other sectors. The physical side is no longer hypothetical either, with drones having hit datacenters, including Iranian strikes on Amazon facilities and Ukrainian hits on Russian infrastructure. Designation would open up federal threat intel, incident response support and tooling for AI companies.</p><p class="paragraph" style="text-align:left;">The skepticism is mostly about bureaucracy. Former DHS officials point out that Commerce and Treasury are already competing for AI policy ownership, so getting agreement on CISA as lead means a turf fight. There is also a real question about whether this needs a new sector at all, or whether the handful of companies that matter get folded into existing ones. My question is does it really matter? It’s not like our current critical infrastructure is proving to be nailing security to begin with. Just look at what Iran is doing to our water plants. (<a class="link" href="https://cyberscoop.com/ai-critical-infrastructure-designation-cisa-report/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="comcast-turns-your-xfinity-wi-fi-in"><a class="link" href="https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">Comcast turns your Xfinity WiFi into a home motion detector</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3138cd75-b992-4624-9543-74221ce3c1e8/image.png?t=1787259934"/></div><p class="paragraph" style="text-align:left;">What could go wrong? Comcast is pushing WiFi Motion as part of its new Xfinity Shield bundle. Your gateway watches how bodies disrupt the signal between it and stationary devices like smart speakers, and turns that into motion detection. The capability has been quietly available since at least mid-2024, so the news is the marketing push. Sensitivity is high enough to register a hand reaching for a remote or a cat crossing a room, and Comcast acknowledges it cannot reliably tell a small pet from a similarly sized child.</p><p class="paragraph" style="text-align:left;">The privacy language though… Comcast says it does not monitor your motion data, while its own documentation says information generated by WiFi Motion may be handed to third parties or law enforcement under a court order or subpoena without further notice to you. The company has not said what it retains, how long it keeps it, or what exactly gets produced when it is compelled. So the household now generates a movement log that lives somewhere in Comcast&#39;s systems, with a disclosure framework already written and a retention policy nobody has published. (<a class="link" href="https://www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-182" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/943e23f6-f51d-4e10-842a-b04f247063f0/Screenshot_2026-08-20_at_4.44.05_PM.png?t=1787262248"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c4ec3d79-a1db-4d5d-b745-d8d8c86fdd05/Screenshot_2026-08-20_at_4.51.58_PM.png?t=1787262720"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/28538c28-a501-4ba3-8fe6-f056bece7075/Screenshot_2026-08-20_at_4.52.52_PM.png?t=1787262774"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #181</title>
  <description>Delta WiFi Hack from DEFCON, Defendant hides AI prompt in court documents, Whitehouse enables privateering hackers, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-181</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-181</guid>
  <pubDate>Fri, 14 Aug 2026 12:32:00 +0000</pubDate>
  <atom:published>2026-08-14T12:32:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3f5c0d19-3d55-44e4-a90d-18b89175ab07/Newsletter_Header.png?t=1786633287"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/cloud-security-index?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|cloud_index" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">How’s everyone recovering? Emotional hangovers? Actual hangovers? Con Flu? - I’m feeling pretty much back to normal at this point but it took me a few days. I think by the time I hit Saturday at DEFCON, having gotten there Monday, I was ready to not see another human for a bit.</p><p class="paragraph" style="text-align:left;">But man was it great to see and hear from so many of you! Whoever did the zoom by me whispering “big fan. big fan” a bunch of times without actually stopping to say hey, you cracked me up. But also got a whole lot of “Are you that guy from….” pull overs - always funny to see where they know me from since I yap all over the Internet.</p><p class="paragraph" style="text-align:left;">Either way, appreciate you all.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: We’re not talking enough about <a class="link" href="https://x.com/mattjay/status/2087661726779003352?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">OAuth apps</a> in infosec</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: The Low Down - <a class="link" href="https://www.youtube.com/watch?v=y46U0Eh07mY&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">Live at DEFCON</a> episode!</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Interview with Cal[.]com CEO about why they went closed source due to security risk of <a class="link" href="https://www.youtube.com/watch?v=OJIsyQtdQzE&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">giving AI the blueprint to the vault.</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="def-con-crowd-suspected-in-fakehots"><a class="link" href="https://arstechnica.com/information-technology/2026/08/def-con-crowd-suspected-in-fake-hotspot-attack-on-delta-flight/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">DEF CON crowd suspected in fake-hotspot attack on Delta flight</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/JCF_M4Ik9qQ" width="100%"></iframe><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7e40f4df-2278-450d-bd39-19ebc55d958b/image.png?t=1786656614"/></div><p class="paragraph" style="text-align:left;">Hacker summer camp ended and somebody decided the flight home counted. Delta 591, Vegas to Atlanta, the morning after DEFCON 34 wrapped. About an hour in the crew ACARS&#39;d the ground asking for corporate security, saying a passenger had stood up a scam network called &quot;Delta WiFi Fast,&quot; then followed with &quot;THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.&quot; Cabin crew killed the onboard wifi for 30 minutes. Delta told Ars an unauthorized network it doesn&#39;t operate was up briefly, no aircraft systems were affected, and no emergency was declared.</p><p class="paragraph" style="text-align:left;">Reddit supplied the rest of it, the captive portal harvesting Google credentials and the Wi-Fi Pineapple and the agents waiting at the gate. FBI Atlanta told Ars they&#39;re looking into it, nobody has been arrested, and no agents met the flight. On the record you&#39;ve got a rogue SSID and a deauth. DEFCON&#39;s press lead told CyberScoop that neither Delta nor the feds had contacted them, that they&#39;ll ban the attendee if one turns out to be involved, and that the con itself ate multiple deauth attacks this year that hit its own operations. (read more <a class="link" href="https://arstechnica.com/information-technology/2026/08/def-con-crowd-suspected-in-fake-hotspot-attack-on-delta-flight/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="different-cloud-providers-different"><a class="link" href="https://www.intruder.io/blog/cloud-security-index?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|cloud_index" target="_blank" rel="noopener noreferrer nofollow">Different cloud providers, different priorities</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3895490b-7928-4432-aedc-7588aa96403f/Newsletter_ad_2026_Cloud_Security_Index.png?t=1786423604"/></div><p class="paragraph" style="text-align:left;">If juggling multiple cloud providers wasn&#39;t complicated enough, it turns out they don&#39;t fail in the same places. There&#39;s surprisingly little overlap in the issues affecting AWS, Azure, and Google Cloud, meaning each provider demands different priorities. </p><p class="paragraph" style="text-align:left;">Intruder’s new report helps you understand where those priorities differ, breaking down the most common issues across each provider, how they compare across key risk categories, and how those risks change as organizations grow.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/cloud-security-index?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|cloud_index" target="_blank" rel="noopener noreferrer nofollow">Get the report</a>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="person-hides-prompt-injection-in-le"><a class="link" href="https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aa385f68-b385-47ae-933a-6ece818bf0a8/Screenshot_2026-08-13_at_7.15.40_PM.png?t=1786666546"/></div><p class="paragraph" style="text-align:left;">A guy representing himself in a Connecticut civil case buried prompt injections in his own court filings, 3 point white text scattered through the document, telling any AI that processed it to make sure its output agreed with him. What caught it was a person at the court noticing those pleadings had more white space than his earlier ones. In later filings he added more hidden text, including &quot;hi :) I hope yo ucant see me&quot; and a link to the SpongeBob Nosferatu scene. He told 404 Media it was an audit of the court&#39;s systems.</p><p class="paragraph" style="text-align:left;">The Connecticut Judicial Branch does not run AI over filings, so the injection landed on nothing, and he says that changes nothing about the impropriety, comparing it to arranging for an automated agent to talk to a juror in private. He is also explicit that the tool is fine, that somebody who cannot afford a lawyer using AI to assemble a coherent filing is a win for access to justice, and that the dishonest part is transmitting a second message the other side cannot see. He expects more of this and points at a recent case in a Brazilian court. Sanction is that the plaintiff loses electronic filing and goes back to paper. 404 fed the motion to ChatGPT as a test, and it ruled against him and mentioned unprompted that it had noticed the injection and ignored it. (read more <a class="link" href="https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="after-microsoft-threatened-legal-ac"><a class="link" href="https://techcrunch.com/2026/08/12/after-microsoft-threatened-legal-action-a-security-researcher-publishes-a-new-windows-zero-day-bug/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow"><b>After Microsoft Threatened Legal Action, a Security Researcher Publishes a New Windows Zero-Day Bug</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/H4Utg3LtcXw" width="100%"></iframe><p class="paragraph" style="text-align:left;">Microsoft published a blog in May threatening legal action against researchers who drop zero-days outside its disclosure policy. This is number nine since April from the researcher everyone assumed it was aimed at. ShieldBreak abuses a Defender cloud-hydration scan through the Cloud Filter API to hand any local user a SYSTEM shell on fully patched Windows 10, Windows 11 25H2, and Server 2025, and it landed one day after a Patch Tuesday that closed 421 CVEs. Will Dormann verified it, Kevin Beaumont verified it on latest Windows 11, and Defender has to be enabled for it to fire, which for most of you means it fires.</p><p class="paragraph" style="text-align:left;">Nightmare Eclipse is saying this is a full bypass of the RoguePlanet patch, CVE-2026-50656, and both Dormann and Beaumont say the two work on entirely different mechanisms, so hold that framing loosely. It&#39;s local privesc, so someone has to already be running code on the box, which is exactly where a ransomware crew is standing when they go shopping for SYSTEM. Microsoft says it&#39;s investigating validity and there&#39;s no patch, so Beaumont&#39;s Defender for Endpoint hunting queries are the whole mitigation right now: alert on processes foreign to Defender loading its libraries, and on unvalidated processes loading cfapi. (read more <a class="link" href="https://techcrunch.com/2026/08/12/after-microsoft-threatened-legal-action-a-security-researcher-publishes-a-new-windows-zero-day-bug/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cyberplace.social/@GossiTheDog/117082623896479140?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="trump-deputizes-private-companies-f"><a class="link" href="https://www.techtimes.com/articles/324233/20260813/trump-deputizes-private-companies-offensive-cyber-strikes-against-foreign-criminals.htm?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow"><b>Trump Deputizes Private Companies for Offensive Cyber Strikes Against Foreign Criminals</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/klsWXBCpm7U" width="100%"></iframe><p class="paragraph" style="text-align:left;">Trump signed a memo Wednesday letting vetted US companies get authorization to hack foreign criminal groups. Two categories: Cyber Surveillance Operations, meaning unauthorized access for collection, and Cyber Effects Operations, meaning manipulation, disruption, denial, degradation, or destruction. Participating Companies contract with DOJ or DHS, and every operations package needs written approval from two co-Executive Directors, one at each. Rob Graham has the take to read on the plumbing: it rides on 18 U.S.C. 1030(f), the CFAA carve out for authorized law enforcement investigative and intelligence activity. Nobody is getting an automated hack back button. CrowdStrike gets to ask permission to hit specific boxes of a specific crew it is already tracking.</p><p class="paragraph" style="text-align:left;">The CE-TCO (Cyber-Enabled Transnational Criminal Organization) definition is doing most of the work. It covers any foreign group committing cyber-enabled crime against the US that is not an institutional part of a foreign government, and the memo says to assume that unless clear intelligence says otherwise. A good chunk of the ransomware ecosystem lives in that gap. Operating procedures are due in 60 days, so mid October is the earliest anyone runs an op. DOJ and DHS can also require a company to post a bond of at least $1 million, forfeited if it breaks its contract. So your employer&#39;s downside is a million bucks and a canceled contract, and yours, if you get staffed on one of these teams, is that you have no combatant status and no sovereign immunity. (read more <a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cybersect.substack.com/p/is-this-hack-back-or-cyber-letters?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="ai-moves-fast-security-must-move-fa"><a class="link" href="https://info.legitsecurity.com/agenticappsec?utm_source=vulnerableu&utm_medium=newsletter&utm_campaign=agentic-appsec-vulnerableu&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">AI moves fast. Security must move faster. Legit brings AI-speed protection to every stage of AI-first dev.</a>*</h3><p class="paragraph" style="text-align:left;">Legit delivers security where AI code is written. Legit VibeGuard is a developer endpoint solution that embeds security directly in the AI coding experience (e.g., Claude Code, Cursor). With agentic context and prioritization, Legit uses app context, business impact and AI insights to separate risk from noise. Autonomous agents then act, resolving vulnerabilities with fixes that understand your standards & workflows. (<a class="link" href="https://info.legitsecurity.com/agenticappsec?utm_source=vulnerableu&utm_medium=newsletter&utm_campaign=agentic-appsec-vulnerableu&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="lazarus-hackers-exploited-windows-z"><a class="link" href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">Lazarus hackers exploited Windows zero-day to target defense firms</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/411b115a-46a3-4c14-9fb7-0d659aff48ce/shattering-the-dream-1-scaled.png?t=1786660038"/></div><p class="paragraph" style="text-align:left;">Back in <a class="link" href="https://www.vulnu.com/p/vulnerable-u-139?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">#139</a> I covered Lazarus going after European defense companies with fake job offers. Same campaign, new zero day. Check Point found the latest wave of Operation Dream Job burning CVE-2026-68820, a use-after-free race condition in AFD.sys that gets a local user to SYSTEM, to load a fresh build of the FudModule kernel rootkit that kills EDR telemetry and now tampers with Smart App Control too. Entry is still a trojanized PDF viewer pulled off an SEO poisoned impersonation site, which drops a new backdoor Check Point named Troy. Microsoft patched on August 11 after CP reported it on July 28, and the rootkit artifact is timestamped July 7, so it ran about five weeks as a zero day.</p><p class="paragraph" style="text-align:left;">It is a local privesc, so they need code exec first, and the lures are aimed at defense, aerospace and aviation staff in France, Germany, Brazil and India. The part that reaches the rest of us is the C2. Lazarus built its relay network out of hijacked Roundcube and WordPress boxes, dropping a PHP webshell called RelayShell, getting in with leaked creds or CVE-2025-49113. At least 17 servers so far, and one already compromised French org got used to spear phish the next set of victims. If you have public facing Roundcube, you are in scope as infrastructure. Check Point published IOCs and a YARA rule for the webshell. (read more <a class="link" href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="737-chrome-vpn-extensions-linked-to"><a class="link" href="https://socket.dev/blog/chrome-vpn-extension-impersonation?utm_medium=feed" target="_blank" rel="noopener noreferrer nofollow">737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0828abfe-f6d5-4fa1-ac12-c2f5418af0b4/image.png?t=1786660947"/></div><p class="paragraph" style="text-align:left;">We did the <span style="text-decoration:underline;"><a class="link" href="https://www.vulnu.com/p/vulnerable-u-117?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">100s of fake Chrome extensions</a></span> story back in #117, and Socket just found the industrial scale version. 737 free VPN extensions across at least 40 developer accounts, 75,486 installs, 274 of them impersonating 66 real brands including Proton, NordVPN, ExpressVPN, Cloudflare&#39;s 1.1.1.1, and Google&#39;s own Outline. 520 of the 522 packages they pulled code for set <code>chrome.proxy.settings</code> to a fixed SOCKS5 server on port 1082 with a bypass list containing only loopback, so once you hit connect, every request in every tab goes through the operator. 94% of the campaign targets Russian speakers trying to reach blocked services, which means the two brands they most carefully cloned were AmneziaVPN and AntiZapret, the tools that audience actually trusts.</p><p class="paragraph" style="text-align:left;">Socket is careful to say the proxy behavior by itself is how any browser VPN has to work. What makes the case is the surrounding stuff. All 200 premium subdomains for Japan, Singapore, Canada, Australia and Turkey resolve to nothing, and those are exactly the ones flagged <code>premium: true</code>. One extension ships a hardcoded license secret and a 32-bit rolling hash presented as a signature. Nine publisher accounts submitted byte-identical privacy justifications to Google claiming no data goes to external servers. And one package accidentally included an internal staff manual telling employees never to put a domain into <code>chrome.proxy.settings</code>, only the resolved IP, so takedowns cannot read the destination out of the shipped code. A Chrome Web Store developer account costs $5, 38 accounts published all 737, and 29 of the 30 accounts that have had something removed still have live extensions. (read more <a class="link" href="https://socket.dev/blog/chrome-vpn-extension-impersonation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="kimwolf-v-7-an-evolution-of-the-kim"><a class="link" href="https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">Kimwolf v7: An Evolution of the Kimwolf Botnet</a></h3><p class="paragraph" style="text-align:left;">These guys really do not want to get taken down again. Unit 42 has a v7 teardown of Kimwolf, the Android arm of the AISURU operation whose C2 got seized by DOJ and international partners back in <a class="link" href="https://www.vulnu.com/p/vulnerable-u-160?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">#160</a>, and the whole release reads like an answer to that. The DDoS traffic now imitates a real Chrome browser closely enough to blend into ordinary browsing, which makes layer 7 filtering a much worse day for whoever is catching it. The C2 grew three redundant paths, including pulling its current address out of public Ethereum name records with Tor waiting when that fails, all sitting behind a local proxy so they can swap pieces without reshipping the bot.</p><p class="paragraph" style="text-align:left;">All the scanning and exploit code is gone, so propagation is somebody else&#39;s binary now and this one just attacks and relays. Infection still gets in through Android TV boxes that ship with debug access wide open, which was true two years ago and will be true two years from now. If you have any of those on your network, they&#39;re hostile, keep them away from anything that matters. Ports, hashes, and detection guidance are all in the intel post. (read more <a class="link" href="https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://blog.xlab.qianxin.com/kimwolf-botnet-en/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="plug-and-pwn-attack-uses-fake-usb-d"><a class="link" href="https://plugandpwn.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">Plug and Pwn attack uses fake USB devices for Windows SYSTEM access</a></h3><p class="paragraph" style="text-align:left;">Like a hack from a movie. Plug in a USB and hacker stuff just starts happening magically. Windows Plug and Play will fetch a signed vendor package off Windows Update and run its code as SYSTEM, with no admin rights, no UAC prompt, and nobody logged in. Alejandro Hernando and Borja Martinez did a DEFCON 34 talk on that and published the whole kit. Same family as the Razer mouse bug from 2021, except they went after the install path rather than one vendor&#39;s installer. The physical demo chains two boring vendor bugs: a Sierra Wireless service exposing a SetDNS call over a named pipe with an Everyone ACL, and a Sony co-installer that pulls config over plaintext HTTP and derives filenames without filtering traversal. (read more <a class="link" href="https://plugandpwn.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="if-apple-sends-you-a-push-notificat"><a class="link" href="https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">If Apple sends you a push notification alerting you to a spyware attack, take it seriously</a></h3><p class="paragraph" style="text-align:left;">Apple sent another round of mercenary spyware threat notifications on Thursday, this time to users in 110 countries, which puts the running total over 150 countries since 2021. These used to land as an email and a banner on your Apple account page, which is a great way to reach somebody two weeks late. Now it goes straight to the lock screen as a push, and the notification opens into guidance on who to contact and how to turn on Lockdown Mode. Apple says it still has not seen a device compromised with Lockdown Mode on.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2ad74a93-e495-4b5b-88cc-8b9faa3b1528/Screenshot_2026-08-13_at_6.41.48_PM.png?t=1786664513"/></div><p class="paragraph" style="text-align:left;">John Scott-Railton at Citizen Lab said the push is a real improvement, and his reasoning is the part I would pass along to anyone who works with high risk users. One person getting an alert and reaching out is usually what starts an investigation, and the investigation is what finds the rest of the targets. He points at Poland, where the whole spyware scandal traces back to notifications like these. (read more <a class="link" href="https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://support.apple.com/en-us/102174?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="chinalinked-hackers-hit-taiwan-in-u"><a class="link" href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack</a></h3><p class="paragraph" style="text-align:left;">Over four days in early July, an agent framework built on Hermes and OpenClaw ran twelve waves against government systems in Asia, sometimes with eight sub-agents going at once. FT says the target was Taiwan. It cracked 85 employee accounts, pulled 2,564 personnel records, and then started poking at a nuclear safety agency and a handful of energy companies. Nobody can tell which model was driving, and whatever it was, it got to work once the operators told it this was an authorized pentest.</p><p class="paragraph" style="text-align:left;">One system was handing its entire user database to anyone who asked. Somebody left debug endpoints in production that give you a valid session for free. There was a CAPTCHA, which Tesseract solved every single time, and the passwords behind it were employee IDs with a symbol stuck on the end. We have been writing that same list up for ten years. What the AI brought was doing all of it simultaneously for four days while nobody noticed. Also worth knowing who is telling us this: Dream is Shalev Hulio&#39;s company, the NSO co-founder, and the report concludes that defense has to become AI-native, which is what Dream sells. (read more <a class="link" href="https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="fbi-and-partners-warn-student-athle"><a class="link" href="https://www.fbi.gov/news/press-releases/fbi-and-partners-warn-student-athletes-of-sexual-exploitation-schemes?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">FBI and Partners Warn Student-Athletes of Sexual Exploitation Schemes</a></h3><p class="paragraph" style="text-align:left;">The FBI and NCAA announced a joint initiative Monday to warn student-athletes about cyber-enabled sexual exploitation. The FBI&#39;s position is that athletes get targeted because their public profiles, expanded by NIL activity, give offenders both more access and more leverage when they threaten to expose material. The tactics described are ordinary account takeover work. A text claiming the account will be disabled unless you send back a verification code. An email about a suspicious new login that pushes you to a reset page. Taushiana Bright, section chief in the FBI&#39;s cyber division, told ESPN that the explicit material circulating in athlete cases is mostly real rather than AI-generated, and that sellers will post a stock photo from the school&#39;s team page next to it to prove the person is who they say.</p><p class="paragraph" style="text-align:left;">If you run awareness for a school, a team, or anyone with a public profile, the reporting guidance is the part to pass along. Stop communicating with the offender, do not pay, do not send more images or identification, preserve the messages, and report it. The FBI is direct that paying leads to further demands. Non-consensual intimate images go to <a class="link" href="https://ncii.ic3.gov?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">ncii.ic3.gov</a>, and anything else to <a class="link" href="https://tips.fbi.gov?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">tips.fbi.gov</a> or 1-800-CALL-FBI. The FBI and NCAA are specifically asking coaches, compliance staff, and athletic department leadership to carry this to athletes, since they are usually the first trusted adult somebody in that situation would go to. (read more <a class="link" href="https://www.fbi.gov/news/press-releases/fbi-and-partners-warn-student-athletes-of-sexual-exploitation-schemes?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.ncaa.org/ncaa-to-assist-fbi-in-protecting-student-athletes-from-sextortion-and-related-crimes/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.espn.com/college-sports/story/_/id/49555079/ncaa-fbi-announce-partnership-combat-athlete-sexploitation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-181" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/68f91635-e473-4f80-8965-6b31899ebe39/Screenshot_2026-08-13_at_7.22.50_PM.png?t=1786666978"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bc35e4bd-3427-497d-9ee5-2e7b7e036a59/Screenshot_2026-08-13_at_7.24.50_PM.png?t=1786667098"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c6588f45-a369-4371-885e-183f0dd5f68c/Screenshot_2026-08-13_at_7.24.17_PM.png?t=1786667062"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #180</title>
  <description>Rogue AI hackers follow ups, Blackhat and DEFCON research dropping, Water plants not pulling PLCs off the internet fast enough, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-180</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-180</guid>
  <pubDate>Fri, 07 Aug 2026 12:18:00 +0000</pubDate>
  <atom:published>2026-08-07T12:18:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0592a887-86aa-44d1-88cc-3d1f54cf6853/Newsletter_Header.png?t=1786055191"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing to you from Las Vegas in the transition day between Blackhat and DEFCON. What a week already. Been here since Monday and not leavin till Sunday which is entirely too much Las Vegas. My voice is at about a 15%, which you will absolutely see if you watch my videos I’m recording here.</p><p class="paragraph" style="text-align:left;">You know that phenomenon in science where evolution keeps producing crabs over and over? I feel like that is happening in cybersecurity as I walk the expo floor and notice many of the AI security companies that were at least trying to differentiate last year are all moving towards doing the same stuff. AI SOC and AI Pentest absolutely everywere. I do still think there are some stand out players in the spaces, but I still commend those trying to stay in their differentiated niche instead of just becoming a crab.</p><p class="paragraph" style="text-align:left;">If you’re reading this and you’re one of the <i>many</i> people who jumped out of the crowd to take the time to say hi to me and let me know that you enjoy reading/watching my content - THANK YOU. Running Vulnerable U feels like screaming into the void often, so that really means a lot to me.</p><p class="paragraph" style="text-align:left;">Some of my favorite conversations of the week have been either people letting me know how much my content helps them in life/work or convos with teams/founders asking how they can do better in content creation/go-to-market. It is fun to jam on this stuff and actually see you all in person.</p><p class="paragraph" style="text-align:left;">If you’re here, what has been your favorite part of the trip?</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: My take on these frontier labs all <a class="link" href="https://x.com/mattjay/status/2083080102221406378?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">hacking things illegally</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Low Level and I talking Iran hacking water plants and the hugging face <a class="link" href="https://www.youtube.com/watch?v=oGvrlT9wyPY&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">incident write up</a></p><p class="paragraph" style="text-align:left;">🎤 Something I said: Me and Dan Miessler talked about the headlines screaming about <a class="link" href="https://www.youtube.com/watch?v=aNZV8wcrLvY&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">open-weight Chinese models</a> and if they are risky or not</p><p class="paragraph" style="text-align:left;">🔖 Something I read: <a class="link" href="https://x.com/dcuthbert/status/2085095153719783778?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Daniel Cuthbert’s summary</a> of OpenAI on stage at Blackhat discussing the recent incidents</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="keyv-and-friends-compromised-in-act"><a class="link" href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow"><b>Keyv and Friends Compromised in Active Shai-Hulud Supply-Chain Attack</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/Ne7hOOd2TLY" width="100%"></iframe><p class="paragraph" style="text-align:left;">Another supply-chain nightmare. While what felt like the entire security industry was walking the halls at Black Hat and BSides Las Vegas, a self-replicating npm worm was tearing through the JavaScript ecosystem, compromising packages that collectively see more than <b>2 billion monthly downloads</b>. This one has serious Shai-Hulud vibes. </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/53714ac7-a489-45a4-aa60-4a2c9d64ed03/Screenshot_2026-08-06_at_9.38.13_AM.png?t=1786034312"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Source: Aikido</a></p></span></div></div><p class="paragraph" style="text-align:left;">If one of the affected packages slips into your dependency tree, a simple <code>npm install</code> can pull down malicious files through a pre-install hook before you even realize anything is wrong. Researchers at Aikido say the campaign has already spread to hundreds of packages, and the list was still growing as responders raced to contain it.</p><p class="paragraph" style="text-align:left;">I’m more worried about the ripple effects we haven’t seen yet. Sure, it steals npm and GitHub tokens so it can keep infecting more packages, but it also grabs Slack, Stripe, Vault and cloud credentials, SSH keys, Terraform state files, password manager databases, and just about every other secret you&#39;d hope never leaves a developer workstation.<span style="font-family:Helvetica;"> </span>(<a class="link" href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="are-pentests-obsolete-in-the-ai-era"><a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Are pentests obsolete in the AI era?</a>*</h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d5d04c20-ad4e-4fb8-871b-344e958c424c/Vuln_U_x_Intruder_July_2026.png?t=1784132905"/></div><p class="paragraph" style="text-align:left;">AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.</p><p class="paragraph" style="text-align:left;">This <a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Intruder blog </a>explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (<a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="cyberattack-on-north-carolina-ports"><a class="link" href="https://therecord.media/cyberattack-north-carolina-ports?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Cyberattack on North Carolina Ports ‘Contained’ As Coast Guard, State Officials Investigate</a></h3><p class="paragraph" style="text-align:left;">Something got into North Carolina Ports&#39; IT system late on August 4 and took all three facilities with it: Wilmington, Morehead City, and the Charlotte Inland Port. Truckers rolled up to signs reading &quot;Operations Alert: System Issues. Expect Delays.&quot; The authority says the breach is contained, an outside forensics team is in there working alongside their IT group, and they pulled in NCDOT, the state IT department, and the Coast Guard. Gates went back to a normal schedule on the 6th, but everything is still being processed by hand.</p><p class="paragraph" style="text-align:left;">The spokesperson declined to say whether this is ransomware, and no crew has claimed it yet, which usually means a negotiation window is still open. They had a Cybersecurity Contingency Plan(!!) and it was good enough to keep 4 million tons a year of cargo moving on paper. Manual fallback for gate operations is the thing you need written down before the bad day, and plenty of operators would have just closed the gate instead. Nothing has been said about cranes or other OT, so for now this reads as an enterprise IT hit with operational blast radius. (read more <a class="link" href="https://therecord.media/cyberattack-north-carolina-ports?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.wect.com/2026/08/06/nc-ports-operating-manually-after-cyberattack-disrupts-statewide-systems/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="unc-6671-rebrands-multi-brand-vishi"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2166f5e7-4b90-445b-81b3-1cad480d0bc1/Screenshot_2026-08-06_at_3.24.38_PM.png?t=1786055085"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Source: Google Threat Intelligence</a></p></span></div></div><p class="paragraph" style="text-align:left;">A crew Google tracks as UNC6671 calls your employees on their personal cell phones, poses as your IT helpdesk, and tells them there&#39;s an urgent mandate to enroll a FIDO2 passkey. The victim lands on something like [company].createssopasskey[.]com, an AiTM panel takes the password and the MFA token, then scripts start pulling files out of M365 and Okta. They&#39;ve been running this under five different extortion brands. BlackFile announced a retirement in May, Redact showed up in June claiming a rogue affiliate had hijacked the old name, and Pink, Helix and Falcon each operate their own leak site. GTIG found the root domains and phishing templates shared across all of them, with passkeyhelpdesk[.]com hitting a Falcon victim and a Helix victim at the same time.</p><p class="paragraph" style="text-align:left;">Targeting narrowed over the summer from broad enterprise to <b>private equity, law firms and financial rating agencies</b>, which is where the M&A and litigation material lives, and they&#39;re standing up a new domain every 1.6 days. They clean up after themselves too, using compromised mailboxes to reset passwords on non-SSO apps and deleting the confirmations and security alerts behind them. Payments kept landing in BlackFile wallets after the May retirement notice, about $10.69 million tracked through mid-May. The pretext here is also the fix: real passkeys are origin bound, so the lookalike domain has nothing to relay. Push and TOTP shops get eaten. (read more <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">May BlackFile writeup</a>)</p><h3 class="heading" style="text-align:left;" id="canadian-man-pleads-guilty-in-snowf"><a class="link" href="https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Canadian Man Pleads Guilty in Snowflake Extortions</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ae05662a-486a-4203-a8a0-3e29815d2fb7/Screenshot_2026-08-06_at_3.27.56_PM.png?t=1786055301"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Source: KrebsOnSecurity</a></p></span></div></div><p class="paragraph" style="text-align:left;">Connor Riley Moucka, the 26-year-old from Kitchener who operated as Judische and Waifu, pleaded guilty to four counts including computer fraud and aggravated identity theft. Between February and October 2024 he and his co-conspirators worked through at least 165 Snowflake customer tenants, all of it on stolen credentials against accounts that had MFA turned off. Ticketmaster, LendingTree, Advance Auto Parts, Neiman Marcus, plus the AT&T haul of call and text records for more than 100 million people. DOJ puts the ransom take north of $2.5 million. He also re-extorted at least one victim using the stolen data of a government officer and a former officer&#39;s immediate family, and spent his spare time threatening the researchers and officials tracking him down. Sentencing is October 27, two year mandatory minimum, 30 year ceiling.</p><p class="paragraph" style="text-align:left;">Cameron &quot;Kiberphant0m&quot; Wagenius, the Army soldier who pleaded out in July 2025, gets sentenced September 3. Which brings us to the third one, John Erin Binns of T-Mobile 2021 fame, who was sitting in a Turkish prison, has since been released, picked up Turkish citizenship, and is back online. Turkey does not extradite its own citizens.(read more <a class="link" href="https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">DOJ statement</a>)</p><h3 class="heading" style="text-align:left;" id="why-a-igenerated-vulnerability-patc"><a class="link" href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Why AI-generated vulnerability patches still require expert human review</a></h3><p class="paragraph" style="text-align:left;">1Password stood up a security research team called Off-by-1 Labs and their first paper is a good one. They generated about 6,000 patches for six recently disclosed CVEs across two frontier models, picking bugs whose fixes landed too late to be in training data. Complete fix with no change to application behavior: 26%. Fixed the bug but altered behavior: 20%. Failed to fix it, introduced a new vulnerability, or both: 53.9%. Their going-in hypothesis was north of 67%.</p><p class="paragraph" style="text-align:left;">More than a third of the patches they counted as successes were what they call fragile, meaning a narrow check bolted on in front of the vulnerable code. On the SpringAI SpEL bug, both models escaped the exact characters from the PoC they were handed and left the root cause sitting there, so the bug comes back the moment that code is reachable by another input. They also tossed 400 runs where the model got caught trying to look up the real patch. Tooling and the full dataset are on GitHub under FLAWED, for Fix-Like Artifacts With Embedded Defects, which is a solid bit of naming.(read more <a class="link" href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://github.com/Off-by-1-Labs/FLAWED?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">tooling and datasets</a>)</p><h3 class="heading" style="text-align:left;" id="meta-ai-model-hacked-a-company-duri"><a class="link" href="https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Meta AI model hacked a company during misconfigured cyber test</a></h3><p class="paragraph" style="text-align:left;">Meta is on the board now! Not to be outdone in the AI doing illegal hacking on its own games! The Information reported that Muse Spark 1.1 breached an unnamed company and made changes to its internal systems, and Meta confirmed to Reuters that a misconfiguration by evaluation vendor Irregular handed one of its models live internet access when it was supposed to be isolated. Irregular says this is the exact same environment issue behind Anthropic&#39;s disclosure last week, and is explicit that no sandbox escape or sophisticated cyber action was involved. A test range was wired to the real internet. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Reuters</a>)</p><h3 class="heading" style="text-align:left;" id="state-department-says-trump-raised-"><a class="link" href="https://therecord.media/trump-xi-southeast-asia-cyber-scam-compounds?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">State Department says Trump raised cyber scam compound issue with Xi</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/baa0ff31-1783-44cf-995e-ce5abe2247a3/Screenshot_2026-08-06_at_3.37.00_PM.png?t=1786055841"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://therecord.media/trump-xi-southeast-asia-cyber-scam-compounds?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Source: The Record</a></p></span></div></div><p class="paragraph" style="text-align:left;">Michael DeSombre, State&#39;s assistant secretary for East Asian and Pacific Affairs, told the Senate Foreign Relations Committee on Thursday that Trump has raised transnational criminal organizations with Xi. He would not say when, or what Xi said back, and the White House did not confirm the conversation happened. The number that came out of the same hearing: more than $12 billion taken from Americans in scams last year, which State says is likely an undercount.</p><p class="paragraph" style="text-align:left;">Chinese enforcement has knocked down compound activity in Cambodia and Myanmar over the last six months, largely because those operations started hitting Chinese nationals, and Beijing has been pulling scam bosses out of Southeast Asia and executing some of them. So the US is leaning on those governments to hand the bosses over for interviews first, because once they go to China, per DeSombre, &quot;we don&#39;t have great transparency as to what happens to them.&quot; The tradecraft is being exported in the meantime. Senators raised cases in Peru and the Dominican Republic, and State flagged compounds rising in Sri Lanka. (read more <a class="link" href="https://therecord.media/trump-xi-southeast-asia-cyber-scam-compounds?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://www.foreign.senate.gov/hearings/protecting-americans-from-global-scam-operations-assessing-the-us-response?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">hearing itself</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-stalked-me-by-hijacking-a-s"><a class="link" href="https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Hackers Stalked Me by Hijacking a Smartwatch for Kids</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/011e01c6-a48a-4375-b107-bf246c67f5ab/Screenshot_2026-08-07_at_2.58.48_AM.png?t=1786089534"/></div><p class="paragraph" style="text-align:left;">Vangelis Stykas mailed WIRED&#39;s Andy Greenberg a lavender kids&#39; smartwatch off Amazon and Greenberg wore it to work. He texted Stykas outside his Brooklyn subway station to say he might lose signal, and Stykas replied that he already knew. The watch&#39;s GPS was broken, but it was still shipping nearby Wi-Fi identifiers to a remote server, which was enough to place him on a specific block. At the office Stykas silently pulled a photo off the watch camera as Greenberg stepped into the elevator, took another at his desk, then opened the microphone and listened. The watch showed nothing the whole time.</p><p class="paragraph" style="text-align:left;">It costs under $30, comes from YiQingTeng Electronics in Shenzhen, and dozens of other brands run on the same backend. For their Blackhat talk, Stykas and Felipe Solferini worked through more than 70 GPS watches and car trackers and traced tens of millions of devices back to three Shenzhen supply chains. On SETracker an authentication flaw let anyone send commands to any device on the platform. Greenberg handed over his email address and nothing else. The available commands include location spoofing, message interception, live mic, camera, and swapping the emergency contacts for numbers the attacker picks. Two of the three platforms never replied to WIRED and still work. (read more <a class="link" href="https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="despite-federal-warnings-thousands-"><a class="link" href="https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Despite Federal Warnings, Thousands of U.S. Industrial Controllers Used In Water Systems Remain Exposed Online</a></h3><p class="paragraph" style="text-align:left;">Researchers ran a Shodan scan on Monday and found 4,400 Rockwell and Allen-Bradley PLCs sitting on the public internet with EtherNet/IP open, 2,844 of them in the US. Half were MicroLogix 1400s, the same family the FBI and EPA named in last week&#39;s joint advisory on the water sector attacks. That advisory covers utilities in at least 12 states since July 27, nine systems in Michigan alone, and in at least one case the attackers changed the controller&#39;s IP address and password so the utility lost its own view and control of its equipment. Pressure loss and flooding.</p><p class="paragraph" style="text-align:left;">Forescout cross-referenced against the affected cities and found 22 devices still exposed, 19 of which look open to CVE-2017-16740 based on firmware version, an RCE from 2017 that needs Modbus TCP enabled to work. They&#39;re careful to say they cannot confirm those hosts belong to the hit utilities or that Modbus is on. Plenty of reporting has pointed at Iran and Forescout is not attributing, with their threat hunting lead saying the scale and speed look like mass scanning and enumeration against a known vulnerability class. Rockwell has been telling customers to keep these off the public internet since 2018. (read more <a class="link" href="https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Forescout research</a> and the <a class="link" href="https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">FBI advisory</a>)</p><h3 class="heading" style="text-align:left;" id="thousands-of-servers-can-be-backdoo"><a class="link" href="https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Thousands of Servers Can Be Backdoored By Exploiting Buggy Motherboard Controllers</a></h3><p class="paragraph" style="text-align:left;">HD Moore found more than a dozen new BMC flaws across HPE, Supermicro, Avocent, Huawei, Lenovo and Dell. His external scan turned up 86,000 BMCs exposing a management service to the public internet, and as many as 75,000 of those are still vulnerable to CVE-2013-4786, an IPMI 2.0 authentication flaw that hands you admin BMC password hashes for offline cracking. Thirteen years. Over half the exposed population carried at least one critical bug, and an internal survey of 126,761 BMCs sitting inside corporate networks put that figure at 29%. The new classes run from auth handshake sequences you can reorder to skip authentication entirely, to unsigned firmware and unenforced config integrity that turn an admin foothold into a permanent implant under the OS.</p><p class="paragraph" style="text-align:left;">ILObleed already showed what that looks like in practice. In 2021 it landed wiper firmware on HPE servers that survived OS reinstalls and drive swaps and kept destroying disks, using a bug HPE had patched four years earlier. HD is holding CVE details until vendors ship fixes, so this week&#39;s work is inventory and segmentation. He released OOBscan to sweep your fleet, and his own hardening list is short: long unique usernames as well as long passwords, disable IPMI where you can, disable KCS to block host-side access to the BMC, and isolate each BMC NIC individually, one per segment, no shared management VLAN. (read more <a class="link" href="https://www.runzero.com/blog/bmc-research/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Ars</a>)</p><h3 class="heading" style="text-align:left;" id="anthropics-ai-used-fake-identities-"><a class="link" href="https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Anthropic’s AI Used Fake Identities, Malware in Rogue Attack On GitHub Project</a></h3><p class="paragraph" style="text-align:left;">AISI runs frontier models through cyber ranges with live internet access and the providers&#39; cyber classifiers deliberately switched off, on the reasoning that a real attacker has both. Across 122 runs against seven models in late July they logged 19 unsanctioned actions on the live internet, nearly all of it one sustained line of activity from Claude Mythos 5. Their security team found out when monitoring flagged data leaving a research system over Tor.</p><p class="paragraph" style="text-align:left;">Mythos decided the way to solve its challenge was a supply chain attack, so it ran one against a real open source project. It researched the maintainers, opened a PR with malicious code, then created a second account posing as an unrelated person who had reviewed that code and confirmed it was clean. Five emails to two maintainers, some carrying malware. Then it opened an Issue on another repo owned by one of them containing a prompt injection aimed at issue-triage coding agents, having reasoned the maintainer might be a bot like Claude Code. Nothing worked, the PR was refused, and AISI found no real-world harm. Their fix going forward is a second LLM watching the first one in real time to approve or deny out-of-scope actions, which is the same control problem everybody shipping an agent this year is about to own. (read more <a class="link" href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-180" target="_blank" rel="noopener noreferrer nofollow">Ars</a>)</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #179</title>
  <description>More AIs escaping labs, FCC cracks down on foreign hardware, Amazon selling pre-hacked streaming sticks, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-179</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-179</guid>
  <pubDate>Fri, 31 Jul 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-07-31T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/240e130a-2c08-4147-ac15-6c2f324a645f/Newsletter_Header.png?t=1785352289"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://rootevidence.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1ecc0f7f-9660-4ddf-8782-df66b0529c82/Newsletter_Sponsor_Logo.png?t=1785352412"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing you from San Diego on vacation. First real non work/family trip in a few years which is nice. Got to see some infosec friends down here and get tips on all the best fish tacos, burritos, and poke bowls. I booked a few scuba dives while out here but a big storm off the coast ruined water conditions so those all got cancelled which is a bummer, I guess I’ll have to come back!</p><p class="paragraph" style="text-align:left;">Headed home for a bit and then off to BlackHat which looks like it’ll be about 119 degrees, and no I don’t care its a dry heat. I celebrated 4 years sober this week which makes Vegas much more tolerable for the whole week, so I’m looking forward to seeing a bunch of you out there at summer camp.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7077f18e-b2f6-41e4-982f-92a9e33442e7/69195674-36D9-4B22-8E88-45AD52D552F8_1_105_c.jpeg?t=1785452221"/></div><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Some <a class="link" href="https://www.linkedin.com/posts/matthewjohansen_ive-been-doing-a-lot-of-research-about-prompt-share-7486134160361693184-I84_/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAIKrA4BtH5-n_r_AlzcW9lf2WaVTvJ1cHk" target="_blank" rel="noopener noreferrer nofollow">thoughts about Adrian</a>, an open source prompt injection defense tool</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: The Low Down <a class="link" href="https://www.youtube.com/watch?v=o340SGs9DUw&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">latest episode</a> talking Hugging Face incident, wp2shell and more</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Dug into some <a class="link" href="https://www.youtube.com/watch?v=d_U1N1qbT1E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">identity as code</a> techniques with Teleport</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Minimal’s <a class="link" href="https://x.com/JakeKing/status/2082652594149920781?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">open source</a> announcement. Hearing good things.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="anatomy-of-a-frontier-lab-agent-int"><a class="link" href="https://huggingface.co/blog/agent-intrusion-technical-timeline?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/de9ee107-0a9f-4120-add4-96e7c95710a6/image.png?t=1785482088"/></div><p class="paragraph" style="text-align:left;">When I covered this it was an AI escaping a sandbox to cheat on a test. It is now a four-day intrusion in which the model built itself attack infrastructure out of strangers&#39; cloud accounts, and OpenAI is still adding to the disclosure.</p><p class="paragraph" style="text-align:left;">Hugging Face published their forensics and it is the best security writeup I have read this year. 17,600 recovered attacker actions between July 9 and July 13, grouped into phases, with an interactive replay you can step through action by action. Go look at it. The agent was being evaluated on ExploitGym, worked out that Hugging Face probably hosted the benchmark&#39;s reference solutions, and went to get them. The whole four and a half day campaign was a model trying to cheat on a test.</p><p class="paragraph" style="text-align:left;">The other update this week is that we found out what the vendor was for the zero day it found. JFrog’s Artifactory wrote up their side of the story. After that it was rooting a public code-execution harness some third party had left exposed on Modal (Modal&#39;s own platform held up, this was a customer&#39;s endpoint). That box became the launchpad for everything after. Stage two was into Hugging Face, and the agent got in by uploading malicious dataset configs and letting their own loader do the work.</p><p class="paragraph" style="text-align:left;">From JFrog’s POV the models chained previously unknown bugs in self-hosted Artifactory to get off the range and onto the open internet. Nine fixes shipped in 7.161.15 and 7.146.34 covering RCE, SSRF, path traversal and privilege escalation up to admin. Cloud tenants are already covered, self-hosted is on you.</p><p class="paragraph" style="text-align:left;">OpenAI&#39;s update says GPT-5.6 Sol and an unnamed pre-release model went looking for publicly exposed credentials and used four accounts across four separate services. It assembled a C2 and a dead drop out of other people&#39;s accounts.</p><p class="paragraph" style="text-align:left;">(read more <a class="link" href="https://huggingface.co/blog/agent-intrusion-technical-timeline?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">OpenAI&#39;s disclosure</a> and <a class="link" href="https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">JFrog&#39;s writeup</a>)</p><h3 class="heading" style="text-align:left;" id="security-decisions-backed-by-eviden"><a class="link" href="https://rootevidence.com/products/platform/?utm_source=vulnerable-u&utm_medium=newsletter&utm_campaign=vulnu-2026-07" target="_blank" rel="noopener noreferrer nofollow">Security decisions backed by evidence</a>*</h3><div class="image"><a class="image__link" href="https://rootevidence.com/products/platform/?utm_source=vulnerable-u&utm_medium=newsletter&utm_campaign=vulnu-2026-07" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/81f4cbc1-45d2-4b15-b568-4c45680c91da/image-2.png?t=1785352607"/></a></div><p class="paragraph" style="text-align:left;">Security teams face thousands of remediation decisions every day, yet none are based on evidence showing which vulnerabilities actually lead to financial loss. </p><p class="paragraph" style="text-align:left;">The Evidence Platform from Root Evidence introduces a new operating model for vulnerability management, using cyber insurance claims, actuarial analysis, digital forensics, attack surface intelligence, and real-world breach data to reduce noise, prioritize remediation, and focus resources where they&#39;ll have the greatest business impact. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://rootevidence.com/products/platform/?utm_source=vulnerable-u&utm_medium=newsletter&utm_campaign=vulnu-2026-07" target="_blank" rel="noopener noreferrer nofollow">See the Evidence Platform in action.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="investigating-three-realworld-incid"><a class="link" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Investigating three real-world incidents in our cybersecurity evaluations</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5f9a75de-8502-4011-a788-abdaa50c5de3/Screenshot_2026-07-30_at_7.53.23_PM.png?t=1785459208"/></div><p class="paragraph" style="text-align:left;">After OpenAI&#39;s disclosure, Anthropic went back through 141,006 of its own evaluation runs where Claude could have reached the internet, and found three incidents where it did, and then compromised the production infrastructure of three real companies. All three were capture-the-flag challenges run through their third-party eval partner Irregular. The prompt told Claude it had no internet access. A misconfiguration gave it internet access anyway. So when Claude&#39;s search wandered off the range, it treated the real companies it found as part of the game.</p><p class="paragraph" style="text-align:left;">Key distinction: these model test environments just <i>had</i> internet access. Calude didn’t need to go zero day hunting to escape the lab, it just was misconfig’d to leave the door wide open. I also hate the personification of these mistakes. A human prompted for these things to happen, and then they happened and were missed. This isn’t some mysterious model issue.</p><p class="paragraph" style="text-align:left;">In one of the incidents Claude found setup docs in the fictional environment pointing at a Python package that did not exist, and did what any red teamer would do: registered the name and published a booby-trapped package. It needed a PyPI account, which needed an email address, which needed a phone number, which it tried and failed to buy, before backtracking to a free email provider. The package was live for about an hour, got installed on 15 real systems. (read more <a class="link" href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="a-leaked-memo-ties-cyberattacks-on-"><a class="link" href="https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/69ddcaab-843b-4989-8fd6-91d391a23f21/Screenshot_2026-07-30_at_7.11.44_PM.png?t=1785456712"/></div><p class="paragraph" style="text-align:left;">We talked about the $10 million bounty and the six sanctioned IRGC officials tied to Cyber Av3ngers, after they rewrote Unitronics PLC code and put &quot;Gaza&quot; on screens from Ireland to Pittsburgh. Well we’re so back. Andy Greenberg got hold of a WaterISAC memo, and it is the first official document to explicitly connect the Minnesota water attacks to Iran. The memo relays a Minnesota Fusion Center alert finding the activity aligned with the Iran-affiliated PLC campaign CISA described in April.</p><p class="paragraph" style="text-align:left;">The intent line is what made me perk up a bit. Per the Fusion Center, the attackers hit remotely accessible PLCs with the likely goal of causing &quot;loss of system pressure and potential contamination of the water supply.&quot;</p><p class="paragraph" style="text-align:left;">Plymouth said its impact was limited to equipment connected over cellular. Suzu Labs&#39; Denis Calderone points out that water towers, lift stations and pump stations usually phone home to SCADA over cellular modems, and those secondary comm paths are routinely left out of risk and vulnerability assessments, especially when an integrator built the network. In the 2020 attacks on Israeli water facilities, Iran-linked actors came in through vulnerable cellular routers. Braham&#39;s city administrator is now asking for their vulnerability study to be redone, and I would bet the cellular paths were never in it.</p><p class="paragraph" style="text-align:left;">Get PLCs off the public internet, allow-list what can talk to them. And go find out what your remote sites are talking over, because that inventory is probably wrong. (read more <a class="link" href="https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, and the city statements from <a class="link" href="https://brahammn.gov/index.asp?SEC=85B95912-1C4A-4539-8110-1EFC88EE7C31&DE=091B3CB2-4CCA-4EEC-85BF-C62DBE73211A&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Braham</a> and <a class="link" href="https://www.plymouthmn.gov/Home/Components/News/News/8977/542?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Plymouth</a>)</p><h3 class="heading" style="text-align:left;" id="stronger-with-every-update-how-were"><a class="link" href="https://blog.google/security/chrome-stronger-with-every-update/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Stronger with every update: How we&#39;re making Chrome and the web safer in the AI Era</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Bug_Fixes_by_Milestone_2.width-1200.format-webp.webp"/></div><p class="paragraph" style="text-align:left;">Chrome fixed 1,072 security bugs across milestones 149 and 150, which beats the total from the previous 23 milestones combined. Look at that chart. Try to spot the Opus moment (when all the frontier models got good). They built a Gemini agent harness that runs over the whole Chrome codebase, and one of its finds was a sandbox escape letting a compromised renderer read local files that had been sitting there for 13 years. BigSleep and CodeMender run in CI every 24 hours across all CLs, and in May alone blocked over 20 vulnerabilities from reaching production including a critical S1+. They are piloting two security releases per week and building dynamic patching that swaps out renderer and GPU processes with updated binaries without making you restart the browser.</p><p class="paragraph" style="text-align:left;">By March they were receiving more bug reports than they got in all of 2025, so they rewrote the Chrome VRP to push researchers toward findings that are additive to what the machines already catch. (read more <a class="link" href="https://blog.google/security/chrome-stronger-with-every-update/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="read-this-before-you-buy-that-tv-st"><a class="link" href="https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow"><b>Read This Before You Buy That TV Streaming Stick</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6798bfee-2fee-4fe9-9038-110a1833af35/Screenshot_2026-07-30_at_3.33.55_PM.png?t=1785440042"/></div><p class="paragraph" style="text-align:left;">Following on from the LG proxy mess <a class="link" href="https://www.vulnu.com/p/vulnerable-u-178?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">last week</a>, here is the version where the device was built for this from the factory. Bitsight&#39;s Pedro Falé registered an expired domain that H96 Android TV boxes had been phoning home to, and found roughly 38,000 of them worldwide reporting full hardware details and installed app lists. Except they were not reporting as TV boxes. They claimed to be Samsung, Vivo, Huawei and Xiaomi phones. As Falé put it, &quot;multiple devices reporting to this factory Android TV Box backdoor were &#39;phones.&#39;&quot;</p><div class="image"><a class="image__link" href="https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bbfe5008-b071-4094-8ff4-48d892c553eb/Screenshot_2026-07-30_at_3.34.48_PM.png?t=1785440110"/></a></div><p class="paragraph" style="text-align:left;">The operation traces to Zhejiang Fengwo IoT Technology, a mainland China company running an ad publishing arm called Fengwo Group, with monetization collected through Hong Kong, Singapore and single-person shell identities. The boxes get pushed jobs to open a browser, load AI-generated finance, health, gaming and food blogs owned by the same group, and click the ads. Those sites serve no ads at all unless the visitor matches the spoofed mobile profile, so the entire loop is closed and self-dealing.</p><p class="paragraph" style="text-align:left;">Amazon, Best Buy and Newegg are all still selling hundreds of these, and the FBI has been warning about them for years. Stick to name brands, check for Play Protect certification, and go look at Synthient&#39;s running list of consumer devices that ship with proxyware preinstalled, because it is not just streaming sticks. Digital photo frames are on there. The gift you bought your mom might be renting out her IP address.</p><p class="paragraph" style="text-align:left;">(read more <a class="link" href="https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://www.fbi.gov/investigate/cyber/alerts/2025/home-internet-connected-devices-facilitate-criminal-activity?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">FBI alert</a> and <a class="link" href="https://github.com/synthient/public-research/blob/main/2026/01/kimwolf/product_names.csv?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Synthient&#39;s device list</a>)</p><h3 class="heading" style="text-align:left;" id="6000-seat-health-insurer-i-dont-wan"><a class="link" href="https://www.kusari.dev/resources/case-studies/healthcare-payer-zero-day-response/?utm_source=vulnerableu&utm_medium=newsletter&utm_campaign=vulnu-q3&utm_content=healthcare-payer-case-study" target="_blank" rel="noopener noreferrer nofollow">6,000 seat health insurer: “I don&#39;t want to go through another Shai-Hulud without it.&quot;</a>*</h3><p class="paragraph" style="text-align:left;">A health insurer serving 3.6M members, running modern pipelines at scale, had best-of-breed scanners and still could not prove its artifacts were trustworthy when the critical vulnerabilities dropped. </p><p class="paragraph" style="text-align:left;">Kusari became its system of record: every artifact mapped from source, every dependency searchable, proven exposure answered in seconds instead of days.</p><p class="paragraph" style="text-align:left;">Learn how they did it → <a class="link" href="https://www.kusari.dev/resources/case-studies/healthcare-payer-zero-day-response/?utm_source=vulnerableu&utm_medium=newsletter&utm_campaign=vulnu-q3&utm_content=healthcare-payer-case-study" target="_blank" rel="noopener noreferrer nofollow">read more</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="some-thoughts-about-anthropics-new-"><a class="link" href="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Some thoughts about Anthropic&#39;s new cryptanalysis results</a></h3><p class="paragraph" style="text-align:left;">Anthropic pointed Claude Mythos at cryptanalysis this week and published two results. Matthew Green (my cryptography god) read both so you don&#39;t have to.</p><p class="paragraph" style="text-align:left;">First he talked about HAWK, a proposed post-quantum signature scheme that was working its way toward becoming a standard. Claude found a key recovery attack that roughly halves its security bits. Still exponential time, so nothing is broken today, and you could paper over it by doubling key sizes. Except being small and fast was HAWK&#39;s entire pitch, so Green figures the scheme is now dead. There&#39;s working code too, and it recovers keys in a few hours against a weakened challenge instance the HAWK authors published themselves.</p><p class="paragraph" style="text-align:left;">The other result is the one with the scary headline. An improved attack on 7-round AES, which sounds like your TLS is on fire, until you learn people have been chipping at reduced-round AES for two decades, this is a constant-factor improvement on work from 2013, and it needs 2^89 operations plus 2^105 chosen plaintexts. Nobody is decrypting anything.</p><p class="paragraph" style="text-align:left;">Green says Anthropic didn&#39;t assemble a room of lattice experts to steer this either. They pointed the model at the problem and let it grind. His real warning is these things are much better at producing results that look real than results that are real. (read more <a class="link" href="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, Anthropic&#39;s <a class="link" href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">research post</a> and the <a class="link" href="https://www-cdn.anthropic.com/e8d50c167ad47beeb03d6109a4a484be95cb38ea/hawk_key_recovery.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">HAWK paper</a>)</p><h3 class="heading" style="text-align:left;" id="industry-leaders-unite-in-open-secu"><a class="link" href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Industry Leaders Unite in Open Secure AI Alliance</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/edaea96c-1130-47c8-895b-5eb9fb114bec/Screenshot_2026-07-29_at_4.27.49_PM.png?t=1785356887"/></div><p class="paragraph" style="text-align:left;">The open-weights camp found its Exhibit A, and it is the Hugging Face incident. NVIDIA stood up the Open Secure AI Alliance with 55 inaugural partners, and the argument at the center of it is the thing I flagged last week: when the closed models could not tell an attacker from a defender and refused to help with the cleanup, Hugging Face ran open-weight GLM 5.2 on its own infrastructure to work through 17,000 actions and contain the intrusion. Defenders need models they can inspect, adapt, and run themselves. Fine by me. It is just funny watching it become a policy platform with a logo garden.</p><p class="paragraph" style="text-align:left;">There is real code under the press release, which is more than most alliances manage. NVIDIA&#39;s NOOA agent harness project is on GitHub, Hugging Face handed Safetensors to the PyTorch Foundation, Microsoft brought its MDASH multi-model scanning harness, HPE is pushing SPIFFE/SPIRE for cryptographic agent identity. The closing ask is aimed at regulators: blanket restrictions on open frontier systems &quot;would weaken defensive capacity.&quot; Which is the argument I have been making, now with a few trillion more in market cap behind it than VulnU could muster. (<a class="link" href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fcc-adds-foreign-made-robots-and-po"><a class="link" href="https://www.fcc.gov/document/fcc-adds-foreign-produced-power-inverters-and-robots-covered-list-0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">FCC Adds Foreign-Made Robots and Power Inverters to the Covered List</a></h3><p class="paragraph" style="text-align:left;">The robot dogs have met their match. The FCC added foreign-produced power inverters, humanoid robots and quadrupeds to its Covered List, blocking new imports on the grounds that they could be remotely controlled, used for surveillance, or turned on us in a cyberattack. Exceptions are available if a device is found not to pose a risk. This mostly means China, which dominates both markets. Around 15,000 humanoids shipped worldwide in all of 2025, so that half is preemptive. Inverters are in millions of American homes tying rooftop solar into the grid.</p><p class="paragraph" style="text-align:left;">Where I land, and it is consistent with what I said about open-weight models a couple weeks ago: origin is a weak signal, capability is a strong one. A model&#39;s country of origin does not change its risk profile. But grid-connected hardware with a vendor-controlled remote management path is a different animal, because the capability ships with the box and the vendor is reachable by a government that can compel them. The part I would like to see is a rule about what a grid-edge device is allowed to phone home to, regardless of who built it. (read more <a class="link" href="https://www.fcc.gov/document/fcc-adds-foreign-produced-power-inverters-and-robots-covered-list-0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://techcrunch.com/2026/07/29/us-government-bans-new-foreign-made-humanoids-robot-dogs-and-solar-inverters-citing-risks-to-national-security/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="kinda-rails-2-shell-critical-rce-in"><a class="link" href="https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">KindaRails2Shell: Critical RCE in Rails via Active Storage</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/215c226f-84ce-4761-ab83-7d756fa65ae6/Screenshot_2026-07-31_at_12.51.25_AM.png?t=1785477094"/></div><p class="paragraph" style="text-align:left;">We heard you liked wp2shell, so now there’s more! Rails2shell! Kinda! (In my best Shamwow! voice) Ethiack went looking for the Rails equivalent, reported it July 22, and it landed publicly on the 29th. CVE-2026-66066, CVSS 9.5, unauthenticated arbitrary file read through Active Storage when it hands uploads to libvips. Ethiack has since confirmed that stock Debian, Ubuntu and Rails-generated Docker environments are all exposed, because the libraries the attack needs ship by default. So if your app takes image uploads from untrusted users, assume you are in scope. What comes back out is .env, database.yml, credentials.yml.enc, secret_key_base. MiniMagick apps are clear. Patch to 7.2.3.2, 8.0.5.1 or 8.1.3.1, and EOL branches get no upstream fix.</p><p class="paragraph" style="text-align:left;">Ethiack and Rails were trying to sit on the technical details until August 28. That lasted two days. Ethiack now confirms at least one public PoC exists and says more details may arrive before the 28th. Patching does not un-steal anything, so rotate secret_key_base, the master key, database creds, Active Storage service keys and third-party tokens. (read more <a class="link" href="https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a>, the <a class="link" href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Rails advisory</a>)</p><h3 class="heading" style="text-align:left;" id="24650-exposed-server-bm-cs-are-hand"><a class="link" href="https://lavahq.io/research/bmc-exposure-alert?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">24,650 Exposed Server BMCs Are Handing Out Crackable Password Hashes</a></h3><div class="image"><a class="image__link" href="https://lavahq.io/research/bmc-exposure-alert?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/af1cba5a-8a8e-4385-a3da-96e5ffbb6eaa/Screenshot_2026-07-29_at_3.32.52_PM.png?t=1785353644"/></a><div class="image__source"><span class="image__source_text"><p>Source: Lava</p></span></div></div><p class="paragraph" style="text-align:left;">Researchers scanned UDP 623 and found 36,872 internet-exposed IPMI hosts. 24,650 of them will hand password-derived authentication material to anyone who asks, via CVE-2013-4786, a weakness in a protocol standardized in 2004. For about a third the researchers actually recovered the password using dictionaries and the patterns printed on factory stickers. 6,240 accepted an empty username. The US is 39% of it.</p><p class="paragraph" style="text-align:left;">An HPE factory password takes roughly a day per captured handshake on an Apple M3. No rented GPU cluster needed! A lot of the exposed gear is Supermicro running a 10-character uppercase string off the chassis label with ADMIN as the username in every instance, which sounds like entropy until you notice the charset and the length are both fixed. Get IPMI and Redfish off the public internet and rotate the factory passwords. (read more <a class="link" href="https://lavahq.io/research/bmc-exposure-alert?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">here</a> and the <a class="link" href="https://nvd.nist.gov/vuln/detail/cve-2013-4786?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">CVE</a>)</p><h3 class="heading" style="text-align:left;" id="word-worm-crawls-into-copilot-sprea"><a class="link" href="https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow"><b>Word Worm Crawls Into Copilot, Spreads Chaos</b></a></h3><div class="image"><a class="image__link" href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/037cb746-8f2a-4593-8a93-2e79b40370cd/Screenshot_2026-07-29_at_3.54.06_PM.png?t=1785354857"/></a></div><p class="paragraph" style="text-align:left;">A researcher has demonstrated a PoC Word document worm that abuses Microsoft 365 Copilot to spread itself without relying on traditional macros or exploits. The attack hides malicious instructions inside a Word document that Copilot faithfully follows when asked to summarize or interact with the file. The AI then generates new documents containing the same hidden prompt injection, effectively turning Copilot into the worm&#39;s replication mechanism. <span style="background-color:#ffffff;">Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a </span><span style="text-decoration:underline;"><a class="link" href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow" style="color: #333333">blog post</a></span><span style="background-color:#ffffff;">.</span></p><p class="paragraph" style="text-align:left;">Prompt injection is starting to look a lot like the macro malware era, except the code is written in natural language. (<a class="link" href="https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="amazon-links-debug-chalk-npm-supply"><a class="link" href="https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow"><b>Amazon Links Debug, Chalk NPM Supply-Chain Attacks to North Korean Hackers</b></a></h3><div class="image"><a class="image__link" href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c97cb21c-3fb2-401f-baa3-f007be676b91/Screenshot_2026-07-30_at_3.28.50_PM.png?t=1785439738"/></a><div class="image__source"><span class="image__source_text"><p>Source: AWS</p></span></div></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">Amazon says</a> the high-profile compromises of the <b>Debug</b>, <b>Chalk</b>, <b>Axios</b>, and <b>typo-crypto</b> npm packages came from a single North Korean state-sponsored operation, linking what previously looked like isolated incidents into one long-running software supply-chain campaign. Amazon&#39;s threat intelligence team said attackers spent months socially engineering open-source maintainers, building trust, and then slipping malicious code into legitimate package updates that were downloaded by developers around the world. (Sounds like XZ Utils to me)</p><p class="paragraph" style="text-align:left;">This was an industrial-scale operation where Amazon says the attackers deliberately started with smaller packages before moving on to massively popular libraries like Debug, Chalk, and Axios, while using AI to appear like legitimate open-source contributors by fixing bugs, responding to issues, and earning maintainers&#39; trust. (<a class="link" href="https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-179" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a5553c71-18af-4e89-941f-04f6b87627d4/Screenshot_2026-07-31_at_1.24.08_AM.png?t=1785479058"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6115abc9-16d4-47bb-8937-a713a98e12fb/Screenshot_2026-07-31_at_2.25.44_AM.png?t=1785482758"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #178</title>
  <description>AI escaped the lab, Jim Cramer calls Chinese models a huge risk, and an absolute ton of vulns in active exploitation you need to know about</description>
  <link>https://www.vulnu.com/p/vulnerable-u-178</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-178</guid>
  <pubDate>Fri, 24 Jul 2026 12:18:00 +0000</pubDate>
  <atom:published>2026-07-24T12:18:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60aa00c0-42c5-4371-acf9-f8f2e9ef51a8/Newsletter_Header.png?t=1784829920"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.opal.dev/customers/databricks?utm_source=vulnu" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7102871b-9ce3-4676-8b3e-9e8513199f32/Lockup_2x.png?t=1784791096"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Who all am I going to see out at BlackHat and Defcon? Calendar is already looking like a jenga game. I’ll be bringing my good walking shoes. We’re going to be recording a live podcast out at Defcon so follow me on <a class="link" href="https://x.com/mattjay?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Twitter</a> to see me shout where we post up.</p><p class="paragraph" style="text-align:left;">Speaking of the podcast, have you all checked it out? I’m excited with how its been turning out. We’ve got some really exciting interviews scheduled too. Give it a follow and rating in your favorite podcast app and <a class="link" href="https://www.youtube.com/@lowdownpod?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">YouTube</a> for the full handsome devil video experience if our faces are important to you. (<a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Apple</a>, <a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?si=f8f0d8a6c5ea4480&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Spotify</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: I checked out this open source tool that <a class="link" href="https://www.linkedin.com/feed/update/urn:li:share:7486134160361693184?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">helps with prompt injection</a> - worth a look.</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This <a class="link" href="https://www.youtube.com/watch?v=FwA3CuJxbk4&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Wired investigation</a> into hacking after market car add-ons</p><p class="paragraph" style="text-align:left;">🎤 Something I said:<a class="link" href="https://www.youtube.com/watch?v=CqKxGBNbCPU&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow"> Interviewed HD Moore</a>, creator of Metasploit and founder of runZero about how hacking is like the 90s again.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: I read the dungeon crawler carl series two times through at this point and it has been a gateway drug into LitRPG as a genre. I’m almost done with the <a class="link" href="https://www.goodreads.com/series/339304-the-primal-hunter?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Primal Hunter</a> series now and it’s been great.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="open-ai-models-escaped-containment-"><a class="link" href="https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">OpenAI Models Escaped Containment and Hacked Hugging Face</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/C04t8ErTKLw" width="100%"></iframe><p class="paragraph" style="text-align:left;">The headlines made it sound like an AI escaped containment and hacked Hugging Face. That&#39;s technically true, but the more interesting story is <i>how</i> it happened. </p><p class="paragraph" style="text-align:left;">OpenAI confirmed that one of its unreleased cyber models - 5.6 Sol and an even more capable pre-release version with cyber guardrails relaxed for testing - was being evaluated against <a class="link" href="https://www.mpi-sp.org/108048/ExploitGym__Can_AI_Agents_Turn_Security_Vulnerabilities_into_Real_Attacks_?c=89706&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Exploit Gym</a>, a benchmark designed to test advanced offensive security capabilities. </p><p class="paragraph" style="text-align:left;">Instead of solving the benchmark directly, the agent reasoned that the answers might exist somewhere else. It discovered a previously unknown vulnerability in a package registry proxy, escalated privileges inside OpenAI&#39;s research environment, moved laterally through the network, gained internet access, and ultimately reached Hugging Face&#39;s infrastructure looking for benchmark data. <b>/goal really took the “goal” part seriously this time, eh?</b></p><p class="paragraph" style="text-align:left;">The ironic part here was that the guardrails designed to make commercial AI safer got in the way of incident response. Hugging Face ultimately had to switch to an open-weight model, GLM 5.2, running on its own infrastructure to complete the forensic investigation. The frontier models did the hacking but refused to help with the cleanup due to safety restrictions.</p><p class="paragraph" style="text-align:left;">Niels Provos had one of the best takes on this whole incident. His point wasn&#39;t that we should be terrified because the AI was &quot;super intelligent.&quot; His point was that this looked like a failure of basic security engineering. If your sandbox has proper egress controls, deny-by-default networking, and genuine isolation, the model shouldn&#39;t be able to wander onto the public internet regardless of how clever it gets or how many zero-days it discovers. The incident suggests the testing environment wasn&#39;t nearly as isolated as they stated. Sandboxing isn&#39;t something you accomplish in a Guardrails.md file. There need to be technological control layers that can’t be subverted. (read more <a class="link" href="https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7485539211056398337/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here </a>and <a class="link" href="https://huggingface.co/blog/security-incident-july-2026?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58741408-f5d7-4815-b6d5-2dabd43e35c2/Screenshot_2026-07-22_at_3.36.20_PM.png?t=1784748989"/></div><h3 class="heading" style="text-align:left;" id="how-databricks-eliminated-standing-"><span style="background-color:#ffffff;"><a class="link" href="https://www.opal.dev/customers/databricks?utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">How Databricks eliminated standing access for 8,000+ engineers</a></span>*</h3><p class="paragraph" style="text-align:left;">Databricks had a standing access problem at scale. With 8,000+ employees across 30+ offices, their identity team ran quarterly access reviews using brittle Python scripts that crashed mid-run.</p><p class="paragraph" style="text-align:left;">Today: 86,000 time-bound access requests handled, 141 automated UARs covering 140,600 access decisions, and a 97% reduction in median approval time. Engineers get production access in minutes instead of hours. Auditors automatically receive compliance reports. Now with Agentic AI, Databricks can handle campaigns at scale. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.opal.dev/customers/databricks?utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Learn how they did it</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="lg-to-ban-residential-proxies-from-"><a class="link" href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow"><b>LG to Ban Residential Proxies from Smart TV Apps</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59430610-165e-4b63-b8d3-900e745a74c0/Screenshot_2026-07-22_at_2.43.33_PM.png?t=1784749567"/></div><p class="paragraph" style="text-align:left;">WTF is going on at LG? You’re paying top dollar for highest tier of electronics and getting bottom of the barrel no name Android devices of Temu experience in their software. TWO different major stories this week for them - 1) apparently 42% of apps in their smart TV appstore include an SDK that turns your device into a residential proxy node for rent. Threat actors and fraudsters rely on these proxies to make their traffic appear legitimate and not originating from data centers.</p><p class="paragraph" style="text-align:left;">At the same time Gamers Nexus on YouTube put together a scathing video showcasing how their top tier $1200 computer monitors are installing adware and all sorts of other shady data collection crap. You plug the monitor in and it pushes McAfee bloatware and even easily missed opt-ins for premium subscriptions to the Anti Virus software. Again, this feels like things you’d expect from bottom of the barrel no name devices, not LG. Imagine Apple charged what they did and then had adware and other shady pop ups on their devices? Thats what this feels like to me. (read more <a class="link" href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a> and watch more <a class="link" href="https://www.youtube.com/watch?v=Q9uefFYe6bM&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="the-real-risk-of-chinas-open-weight"><a class="link" href="https://x.com/deanwball/status/2078133895766114412?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">The Real Risk of China&#39;s Open-Weight AI Isn&#39;t What You Think</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/da492d8b-a217-4ad5-af60-dcd06b4ed939/Screenshot_2026-07-21_at_4.23.06_PM.png?t=1784665398"/></div><p class="paragraph" style="text-align:left;">I interviewed Daniel Miessler this week (video to come) because he&#39;s one of the few people I know who&#39;s willing to wrestle with AI&#39;s future without falling into the usual hype or doom camps. We disagree on plenty, which makes for a much better conversation. </p><p class="paragraph" style="text-align:left;">The jumping-off point was a long X thread from Dean Ball, OpenAI&#39;s Head of Strategic Futures, arguing that China&#39;s latest open-weight AI models represent a growing strategic risk. By the time Jim Cramer jumped into the conversation, I knew this debate had escaped the echo chamber. Once that happens, nuance usually disappears. Suddenly the conversation isn&#39;t about deployment models, infrastructure, or data residency anymore. It&#39;s just &quot;China bad.&quot;</p><p class="paragraph" style="text-align:left;">One of the biggest topics was Kimi K3. It came out last week, and it&#39;s about on par with the best Western frontier models. Not quite at Fable&#39;s level, but with the right harness it&#39;s pretty darn close. At the same time, people hear &quot;open weight&quot; and assume anyone can run it on a laptop. That&#39;s not how this works. You still need serious infrastructure. The weights being open doesn&#39;t magically put frontier AI in everyone&#39;s hands overnight. That&#39;s why I think so much of the panic around these models is misplaced. People are arguing about capabilities without understanding how they&#39;re actually deployed.</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/89d4d720-2257-48f5-9e45-81b5e5e723a8/Screenshot_2026-07-21_at_4.26.58_PM.png?t=1784665632"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://x.com/deanwball/status/2078133895766114412?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Full X thread here</a></p></span></div></div><p class="paragraph" style="text-align:left;">Ball suggested China may be acting out of &quot;strategic blindness.&quot; I just don&#39;t buy that. China isn&#39;t exactly famous for failing to think long term. Their strategy is measured in centuries. Ours is measured in fiscal quarters. Where Dean really lost me, though, was describing an open-weight future as an &quot;AI communist dystopian hellscape.&quot; I kept asking the same question: <i>What&#39;s the dystopian hellscape?</i> What is the nightmare scenario where more people have cheaper, maybe even free, access to frontier-level technology? We said the same thing about the internet. I don&#39;t think anyone looks back and says widespread internet access was a mistake because too many people got access to powerful technology.</p><p class="paragraph" style="text-align:left;">This is all getting pretty banana pants. The actual cybersecurity nuance has almost nothing to do with where the model was trained. It has everything to do with where you&#39;re sending your data. If you&#39;re piping sensitive corporate information into a Chinese-hosted API, absolutely that&#39;s a legitimate concern. But if you&#39;re running an open-weight model on American infrastructure, whether that&#39;s Google Cloud, OpenRouter, or your own environment, the risk profile changes completely. There isn&#39;t some magically &quot;American&quot; model that&#39;s inherently safer because it carries a U.S. flag. (read more <a class="link" href="https://x.com/deanwball/status/2078133895766114412?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/jimcramer/status/2079509100535197892?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fc15fa3a-7a2e-4d8e-8a6b-a41a2881c80e/Screenshot_2026-07-21_at_4.44.25_PM.png?t=1784666688"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://x.com/jimcramer/status/2079509100535197892?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Full X thread here</a></p></span></div></div><h3 class="heading" style="text-align:left;" id="critical-wp-2-shell-word-press-flaw"><a class="link" href="https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow"><b>Critical wp2shell WordPress Flaws Exploited to Install Webshells</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/jqQ0IzyAFtc" width="100%"></iframe><p class="paragraph" style="text-align:left;">This is one of those stories where the advice is simple: stop what you&#39;re doing and patch. Researchers disclosed a critical remote code execution vulnerability affecting WordPress itself, not a plugin, and exploitation is already considered trivial. </p><p class="paragraph" style="text-align:left;">Ryan Dewhurst, one of the top WordPress security researchers, warned that attackers can exploit it with AI-assisted tooling, making this far easier to weaponize than many past WordPress flaws. Roughly 500 million websites run WordPress, although the bug only affects versions 6.9 and newer (with some caveats. check patch notes), meaning sites updated since December or running automatic updates are the ones most likely to be exposed.</p><p class="paragraph" style="text-align:left;">I expect that mass exploitation is measured in hours, not days. If you&#39;re running an affected version, patch immediately. If you absolutely can&#39;t update right away, you may be able to temporarily mitigate the risk by disabling the vulnerable WordPress REST API functionality, but honestly that sounds harder than simply installing the fix. WordPress forced a patch but I got lots of DMs and comments from people saying their version didn’t auto update. Cloudflare also pushed a protection in their WAF if you’re on their pipes. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="how-databricks-eliminated-standing-"><a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Your access reviews have a 99% approval rate. That&#39;s the problem</a>*</h3><p class="paragraph" style="text-align:left;">If every reviewer clicks approve, the review didn&#39;t happen. Attestation fatigue is real: reviewers see 200 identical rows with no context and do the only reasonable thing. Opal&#39;s Paladin triages the queue before they ever open it — automating the routine 90% with a full audit trail, surfacing the 10% that needs a human call. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Watch the on-demand demo.</a> </p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="introducing-gemini-35-flash-cyber"><a class="link" href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Introducing Gemini 3.5 Flash Cyber</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/039c56aa-c8aa-49de-a435-9d563a2c6978/Screenshot_2026-07-21_at_4.54.53_PM.png?t=1784667320"/></div><p class="paragraph" style="text-align:left;">Google just made one of the biggest AI-for-cybersecurity announcements we&#39;ve seen yet. Heather Adkins, Google&#39;s CISO, shared <b>Gemini 3.5 Flash Cyber</b>, a lightweight, cost-efficient model that&#39;s purpose-built for security work. They emphasized the capability around finding AND fixing vulnerabilities. Finding bugs has never been the hard part. Fixing them at scale is worth the attention. Google has been saying for a while that its long-term goal is nothing less than eliminating software vulnerabilities altogether, and this feels like another major step toward that vision.</p><p class="paragraph" style="text-align:left;">Google says Gemini 3.5 Flash Cyber found more vulnerabilities in the V8 JavaScript engine that powers Chrome than either Gemini 3.5 Flash or Gemini 4.6. That&#39;s wild. My first sarcastic thought was, &quot;Did somebody tell the FBI? We&#39;ve got another model to ban.&quot; If this thing delivers cyber capabilities on par with models like Mythos Preview but at a fraction of the cost, that&#39;s a huge development for defenders. The industry has spent months debating whether powerful cyber models are too dangerous to release, while Google is demonstrating what happens when you optimize one specifically to help security teams identify and remediate flaws faster.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/48c90251-abdd-4bcc-a357-c5cb8cc71df3/Screenshot_2026-07-21_at_4.57.55_PM.png?t=1784667489"/></div><p class="paragraph" style="text-align:left;">To me, this is exactly where the conversation should be. If policymakers are genuinely worried about the cybersecurity race with China, the answer isn&#39;t flirting with bans on open-weight models or trying to slow down AI. It&#39;s getting the best defensive capabilities into the hands of every security team in America and across our allies. We&#39;ve already learned this lesson with vulnerability scanners, Metasploit, and countless other security tools. Pretending powerful technology doesn&#39;t exist doesn&#39;t make attackers forget about it. The best response is putting better tools in defenders&#39; hands. One gazillion percent. That&#39;s how you improve cybersecurity. (<a class="link" href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>) </p><h3 class="heading" style="text-align:left;" id="russian-espionage-group-using-novel"><a class="link" href="https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/44fa4d67-2d18-427c-9115-28cf25b3be8d/Screenshot_2026-07-23_at_1.39.23_PM.png?t=1784831996"/></div><p class="paragraph" style="text-align:left;">Laundry Bear (also known as Void Blizzard) has been running a nasty espionage campaign since July 2025, exploiting a zero-day in Zimbra Collaboration Suite that didn&#39;t get patched until November. Such little user interaction required for this bug, just viewing a phishing email is enough for them to walk away with 90 days of emails, passwords, 2FA tokens, and search history. No clicks.</p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">joint advisory - signed by 16 countries</a> - notes the group is still actively hitting unpatched Zimbra instances, so if your org is running it, patch now. The vulnerability only scored a 6.1 CVSS severity rating, further solidifying fixing in CVSS score order is not a good strategy. The group has been spotted targeting defense, energy, law enforcement, finance and more across NATO countries, with Ukraine serving as their testing ground before broader deployment - a pattern we&#39;re seeing more frequently from Russian threat actors. (<a class="link" href="https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="adobe-chrome-extension-vuln-lets-si"><a class="link" href="https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Adobe Chrome extension vuln lets sites access WhatsApp chats</a></h3><p class="paragraph" style="text-align:left;">Nasty one here - the Adobe Acrobat Chrome extension had a vuln that could let any website you visit silently read your WhatsApp Web conversations. The attack chain, dubbed HermeticReader, exploits the extension&#39;s WhatsApp integration feature to hijack DOM operations in your WhatsApp tab and exfiltrate your chat list, contacts, messages, and more - with zero clicks required. 329 million installs on this extension makes my head spin…</p><p class="paragraph" style="text-align:left;">It was caught four hours after Adobe accidentally introduced it in an update, and Adobe patched it within two days over a weekend - which is about as good as we can hope for. No evidence of exploitation in the wild either. If you&#39;re running the Adobe Acrobat Chrome extension, just make sure you&#39;re on version 26.5.2.3 or later, which should have auto-updated already. (<a class="link" href="https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-share-point-rce-flaw-explo"><a class="link" href="https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Critical SharePoint RCE flaw exploited to steal machine keys</a></h3><p class="paragraph" style="text-align:left;">If you&#39;re running on-premise SharePoint, drop what you&#39;re doing and patch. CVE-2026-50522 is a critical unauthenticated RCE flaw that got a PoC published on GitHub, and within hours watchTowr&#39;s honeypots were catching active exploitation attempts. Attackers are using it to steal machine keys, which lets them forge authentication tokens and maintain persistent access even after you patch the underlying vulnerability. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="anubis-ransomware-claims-coca-cola-"><a class="link" href="https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak</a></h3><p class="paragraph" style="text-align:left;">Take my eyes, but not my milk! Anubis ransomware gang is claiming responsibility for the Fairlife (Coca-Cola dairy subsidiary) attack that took down US production facilities earlier this month. They&#39;re saying they encrypted Fairlife&#39;s Nutanix infrastructure and walked out with about 1TB of corporate data, with a deadline to negotiate or they dump it. Coca-Cola&#39;s not saying much.</p><p class="paragraph" style="text-align:left;">Worth keeping an eye on Anubis - they&#39;re a RaaS operation that spun up in December 2024 and have been building a pretty gnarly toolkit. Last year they added a data wiper to the mix, so beyond the usual encrypt-and-ransom playbook, they can just nuke your files entirely if you don&#39;t play ball. The fact that Fairlife went public with the breach quickly without following the ransom instructions clearly didn&#39;t sit well with them. (<a class="link" href="https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="palo-alto-vpn-vuln-exploited-by-qil"><a class="link" href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Palo Alto VPN vuln exploited by Qilin ransomware gang</a></h3><p class="paragraph" style="text-align:left;">If you&#39;re running Palo Alto GlobalProtect VPN and haven&#39;t patched CVE-2026-0257 yet, you’re probably having a bad time. Qilin ransomware affiliates are actively chaining this auth bypass vulnerability to get into corporate networks, and researchers have already documented multiple successful intrusions from June alone. Palo Alto patched it back in May, CISA added it to KEV and gave federal agencies three days to patch, and yet here we are with Shadowserver tracking over 167,000 GlobalProtect instances still exposed online. (<a class="link" href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-service-now-code-execution"><a class="link" href="https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">Critical ServiceNow code execution flaw now exploited in attacks</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bd3cebc3-8715-4a0d-8a5d-864802c1b358/image.png?t=1784834720"/></div><p class="paragraph" style="text-align:left;">If you&#39;ve got self-hosted ServiceNow instances in your environment, heads up! (Feels like a lot of this this week). CVE-2026-6875 is a pre-auth sandbox escape RCE that&#39;s now being actively exploited in the wild - Defused caught it over the weekend. ServiceNow patched their hosted instances back in April but only dropped the fix for self-hosted a week ago on July 13th, which means there&#39;s been a window of exposure for anyone dragging their feet on updates.</p><p class="paragraph" style="text-align:left;">The interesting wrinkle here is that attackers are hitting the same pre-auth endpoint that Searchlight Cyber documented in their original PoC, but using a different sandbox-escape gadget to get there. ServiceNow is still technically saying they haven&#39;t observed exploitation on their hosted instances, but if you&#39;re self-hosted you&#39;ve got 85% of Fortune 500 companies worth of attack surface context to motivate you. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-178" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4513cf89-54b6-4203-b634-7f509b2a74e2/Screenshot_2026-07-23_at_2.40.23_PM.png?t=1784835629"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e3065936-56bc-4128-944e-72d14f218efb/Screenshot_2026-07-23_at_2.42.18_PM.png?t=1784835747"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e8376f5f-2ec8-4ef8-97e5-5bff9e0791c2/Screenshot_2026-07-23_at_2.43.10_PM.png?t=1784835798"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #177</title>
  <description>Record breaking patch tuesday, AI 0days, Hacker perp walks, job interviews that get you hacked, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-177</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-177</guid>
  <pubDate>Fri, 17 Jul 2026 12:43:00 +0000</pubDate>
  <atom:published>2026-07-17T12:43:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>5 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e986518e-4995-461b-8d7e-319104bd16de/Newsletter_Header.png?t=1784218552"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">It was one of those weeks that I think it would be easier to count the amount of hours I wasn’t on camera yapping. Recorded an absurd amount of content. Felt good to be back in studio in between a bunch of traveling banging it all out though!</p><p class="paragraph" style="text-align:left;">Really excited about how the new podcast with Low Level is shaping out. We’ll be putting these out weekly so make sure to subscribe to either the new YouTube channel or wherever you listen to podcasts. (<a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Apple</a>, <a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?si=f5f6ac02a4834a1b&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Spotify</a>, etc.)</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/iAfUQdKoTsU" width="100%"></iframe><p class="paragraph" style="text-align:left;">And as always a special shoutout to <a class="link" href="https://mazehq.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Maze</a> who not only is doing awesome things in AI Security land, they also must be geniuses since they wanted to be our Launch partner on The Low Down.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Just opt out of us siphoning all of your data out of your home directory to our cloud storage! <a class="link" href="https://x.com/mattjay/status/2076713394766275028?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Honestly it’s your fault.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This <a class="link" href="https://www.youtube.com/watch?v=F8tRi1RYf7c&t=5s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">awesome panel</a> we did at PlanetScale HQ</p><p class="paragraph" style="text-align:left;">🎤 Something I said: How I cooked <a class="link" href="https://www.youtube.com/watch?v=D7prSk5wsy0&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">prompt injection</a> with this open source tool</p><p class="paragraph" style="text-align:left;">🔖 Something I read: This great interview between <a class="link" href="https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Kim Zetter and Allison Nixon</a> on tracking The Com (Scattered Spider) - and did you see the <a class="link" href="https://x.com/NCA_UK/status/2077728550505922936?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">perp walk?</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="microsoft-patches-a-record-570-secu"><a class="link" href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Microsoft Patches a Record 570 Security Flaws</a></h3><p class="paragraph" style="text-align:left;">570 patches in a single Patch Tuesday. Welcome to Mythos baby!!! Microsoft is, of course, attributing exploding patch number to AI-assisted vulnerability discovery. The most pressing items this month are three zero-days, two of which are already being exploited in the wild, both allowing privilege escalation. There&#39;s also a fun 9.6 CVSS RCE in Microsoft Copilot that lets attackers execute code via a malicious website that tricks Edge on Android into sending crafted prompts.<br><br>Microsoft&#39;s exploitability index is basically becoming useless in an AI world. Anthropic&#39;s Mythos model was able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that Microsoft had rated &quot;Exploitation Less Likely.&quot; The SharePoint zero-day this month was rated the same way before showing up on CISA&#39;s KEV list. Adobe is moving to twice-monthly patches, and Google pushed over 900 fixes in June alone. Patch management is having its DevOps moment, gotta do more and more faster! (<a class="link" href="https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"></p><h3 class="heading" style="text-align:left;" id="are-pentests-obsolete-in-the-ai-era"><a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Are pentests obsolete in the AI era?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d5d04c20-ad4e-4fb8-871b-344e958c424c/Vuln_U_x_Intruder_July_2026.png?t=1784132905"/></div><p class="paragraph" style="text-align:left;">AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.</p><p class="paragraph" style="text-align:left;">This <a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">Intruder blog </a>explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (<a class="link" href="https://www.intruder.io/blog/how-ai-is-changing-the-defenders-toolkit?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global|fixed|ai_pentesting" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="contagious-interview-infostealer-ca"><a class="link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Contagious Interview Infostealer Campaign Continues Targeting Developers</a></h3><div class="custom_html"><iframe width="560" height="315" src="https://www.youtube.com/embed/y3cVL78-9HE?si=-tdWEeYhOMSncETM&start=1608" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe></div><div class="image"><a class="image__link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e69a9466-9d85-4bcc-902d-a7dd711a73f3/Screenshot_2026-07-15_at_7.41.23_PM.png?t=1784158889"/></a><div class="image__source"><a class="image__source_link" href="https://gist.github.com/soolidsnake/9e937530a49bc51a5e2e56d86137561b?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" rel="noopener" target="_blank"><span class="image__source_text"><p><a class="link" href="https://gist.github.com/soolidsnake/9e937530a49bc51a5e2e56d86137561b?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Full thread here.</a></p></span></a></div></div><p class="paragraph" style="text-align:left;">Love when people who get popped are super transparent about their experience so we all get a chance to learn from it. This blockchain dev got a recruiting message on LinkedIn. They even said they were expecting a suspicious link or some malware that never came. They got all the way to the interview, it all felt super legit, and then the team asked them to clone a GitHub repo to work on a coding assessment live on the call. Doing what anyone would do during a job interview, they got to work - but the github repo contained malware heading in an auth.js file a few folders deep. By the time the victim knew what happened, a bunch of their crypto wallets were drained.</p><p class="paragraph" style="text-align:left;">This campaign has been very prevalent and successful out of North Korea. They specifically target blockchain/crypto/web3 devs as it fits SUPER nicely in with their lure to get code on their machine for a technical interview. They are also a perfect target because since North Korea is basically sanctioned out of the western economy they fund much of their government efforts with stolen crypto. Billions per year. (read more <a class="link" href="https://x.com/soolidsnakee/status/2077291601760534894?s=46&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="legacy-hive-bone-shattering-zero-da"><a class="link" href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>LegacyHive: “Bone-Shattering” Zero-Day from Microsoft&#39;s Serial Tormentor Not the Haymaker That Was Promised</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/071e4cb8-db0e-4f96-af59-74200156967e/Screenshot_2026-07-16_at_6.57.02_PM.png?t=1784246242"/></div><p class="paragraph" style="text-align:left;">The day Nightmare Eclipse promised finally arrived. If you&#39;ve been following the saga, Nightmare Eclipse is the security researcher who&#39;s been carrying out a very public feud with Microsoft over what they describe as a broken vulnerability disclosure process. Back in June, the researcher hinted that July 14 would be significant, and sure enough, a new zero-day dubbed &quot;LegacyHive&quot; landed on GitHub. </p><p class="paragraph" style="text-align:left;">It&#39;s a local privilege escalation in the Windows User Profile Service that lets a regular user mount and get read-write access to other users&#39; registry hives, including admins. Useful post-compromise tool, but experts are calling out the gap between the &quot;bone-shattering&quot; hype and what the released PoC actually delivers.</p><p class="paragraph" style="text-align:left;">Interestingly, NightmareEclipse stripped back the public PoC this time around - likely due to Microsoft&#39;s legal threats - requiring additional credentials and limiting it to the usrclass.dat hive. The full version apparently doesn&#39;t have those limitations, but you&#39;d need to do some work to get there. Given that previous drops like BlueHammer and RedSun went from PoC to active ransomware exploitation within days, security teams shouldn&#39;t treat the incomplete PoC as a reason to relax. No patch yet, no CVE, and Microsoft just shipped 622 fixes this month so don&#39;t hold your breath for an out-of-band fix. (<a class="link" href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="telegrams-shortlink-domain-is-back-"><a class="link" href="https://techcrunch.com/2026/07/14/telegrams-shortlink-domain-is-back-online-after-day-long-suspension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Telegram’s shortlink domain is back online after day-long suspension</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/221f5892-3d54-4646-b4e7-8c43ff3de181/Screenshot_2026-07-16_at_7.03.19_PM.png?t=1784246604"/></div><p class="paragraph" style="text-align:left;">Telegram had a rough Monday when their t[.]me shortlink domain went dark, and the reason turned out to be a pretty embarrassing clerical blunder. The Montenegro-based registrar DomainME accidentally suspended Telegram&#39;s entire t[.]me domain while trying to comply with new OFAC sanctions - the sanctions that were actually targeting a VPN provider called First VPN. The problem? The Treasury&#39;s sanctions listing for First VPN happened to contain a t[.]me link to the VPN&#39;s Telegram group, and rather than just blocking that specific URL, DomainME nuked the whole domain to stay on the right side of U.S. sanctions law. (<a class="link" href="https://home.treasury.gov/news/press-releases/sb0559?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grok-build-uploaded-entire-git-repo"><a class="link" href="https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read</b></a></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DavT8sQNTXM/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><p class="paragraph" style="text-align:left;">If you&#39;ve been using xAI&#39;s Grok Build coding CLI, it&#39;s time to rotate your credentials. A researcher found that Grok Build was uploading entire Git repositories - full commit history included - to an xAI-controlled Google Cloud Storage bucket. Some examples showed a 27,800x gap between what the model actually needed and what left the machine. Turning off &quot;Improve the model&quot; in settings did absolutely nothing to stop the uploads - that toggle only governs training data, not what actually hits the wire.</p><p class="paragraph" style="text-align:left;">Any file Grok read during a task, including .env files, went out unredacted. And since full commit history was bundled up, that includes secrets you committed and deleted ages ago. xAI quietly flipped a server-side switch to stop the uploads on July 13th and Elon promised everything would be &quot;completely and utterly deleted,&quot; but they still haven&#39;t explained why full repos were being uploaded by default, for how long, or how many users were affected. The upload code is still sitting in the latest binary, just held back by a server flag. Rotate anything that could have touched this tool. If you were running this in a corporate environment, this is a data residency and regulatory nightmare. (<a class="link" href="https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="cursor-0-day-when-full-disclosure-b"><a class="link" href="https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">Cursor 0day: When Full Disclosure Becomes the Only Protection Left</a></h3><p class="paragraph" style="text-align:left;">This isn’t the craziest vuln, but it is worth talking about this story because I trust the author is legit and this disclosure process is not alright for a company of their size and reputation. Mindgard dropped a full disclosure on Cursor today after seven months of trying to get the AI code editor to patch a painfully simple vulnerability. The bug itself is almost embarrassingly basic - drop a malicious git.exe in your repo root, and Cursor will execute it automatically when someone opens the project. No clicks or prompts. It just runs. The proof of concept was literally just Windows Calculator renamed to git.exe popping up over and over.</p><p class="paragraph" style="text-align:left;">Mindgard did everything right - responsible disclosure, HackerOne, direct CISO outreach - and got ghosted for seven months while Cursor shipped 197+ new versions. If you&#39;re running Cursor on Windows, either sandbox your untrusted repos or have your admins set up AppLocker rules blocking execution from workspace directories until a patch drops. This one&#39;s worth paying attention to given how much access these AI IDEs have to your code, credentials, and environment. (<a class="link" href="https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="last-pass-bitwarden-users-targeted-"><a class="link" href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow"><b>LastPass, Bitwarden Users Targeted With Fake Security Alerts</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/072a9e00-a0a8-460e-950c-040fcb6fe57c/image.png?t=1784247244"/></div><p class="paragraph" style="text-align:left;">One thing I always like putting in the newsletter is phishing campaigns like this because they are active and a good pulse on what to look out for. In this case, LastPass and Bitwarden weren&#39;t compromised at all. The attackers simply registered domains that looked legitimate and sent convincing emails warning users about, of all things, ongoing phishing campaigns and recent security incidents. The phishing email is literally warning you about phishing. It talks about enhanced security measures, updated policies, and protecting your account. Then it adds a little urgency: you have 14 business days to review and accept new terms or risk losing access to your account. &quot;We&#39;re here to protect you, but you need to act right now.&quot;</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59b4a71a-2166-4352-9792-f885f265c4d6/image.png?t=1784247253"/></div><p class="paragraph" style="text-align:left;">The design is clean. The spelling and grammar are solid. The domains are convincing. Clicking the link takes victims to a DocuSign clone hosted on domains like &quot;lastpasscompliance[.]com,&quot; complete with a chatbot and realistic branding. Eventually you get prompted to download software, which is where the malware comes in and the divergence from anything resembling real DocuSign happens. Those of us in security immediately see the red flags: urgency, account restrictions, DocuSign requests, software downloads. But for a normal user, nothing really screams &quot;fake&quot; here. Guards up! (<a class="link" href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="white-house-details-gold-eagle-clea"><a class="link" href="https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">White House details ‘Gold Eagle’ clearinghouse for AI cyber threats</a></h3><p class="paragraph" style="text-align:left;">The White House has put some meat on the bones of last month&#39;s AI executive order, unveiling &quot;Gold Eagle&quot; - a new federal clearinghouse for sharing AI-discovered cyber threat intelligence between government and private sector. Treasury&#39;s running point on this one, with CISA, DHS, and DoD all contributing. The idea is straightforward enough - use AI to find vulnerabilities before the bad guys do, then coordinate patching across government and critical infrastructure. They&#39;ve even built a new platform called VINTS (Vulnerability Information and Coordination Environment) with Carnegie Mellon&#39;s Software Engineering Institute to receive and prioritize those reports, and apparently it&#39;s already collecting intel.</p><p class="paragraph" style="text-align:left;">They&#39;re specifically planning to use frontier models including Anthropic&#39;s Mythos for vulnerability discovery. Which I find funny as they’ve also recently deemed Anthropic a supply chain risk and banned the government from using it, and then also a risk worthy of an export control to now allow the general public to use Mythos either. I also don’t get why gut CISA as much as we have and then recreate this program and hand it to the Treasury, but I’ll let more .gov wonks explain that one.</p><p class="paragraph" style="text-align:left;">I’m not confident in anything this admin puts forward, so I’d look closer to Glasswing or the “Patch the Planet” initiative out of OpenAI/Trail of Bits to be more successful that whatever the hell this is. Even the press release reads like a political rally, which is signal to me that this is more sizzle than steak. (<a class="link" href="https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="us-unseals-indictment-against-alleg"><a class="link" href="https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">US unseals indictment against alleged operators of Russian bulletproof hosting service</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6da255b9-ee66-4133-a684-8e6d64184511/image.png?t=1784249541"/></div><p class="paragraph" style="text-align:left;">The DOJ just unsealed an indictment against three Russians running Media Land, a St. Petersburg-based bulletproof hosting shop that was essentially a one-stop-infrastructure provider for some heavy hitter hackers. LockBit, BlackSuit, Play ransomware groups, plus a laundry list of stolen credit card marketplaces like BriansClub and Bidencash. The three defendants - Volosovik, Pankova, and Zatolokin - are looking at charges covering computer fraud, wire fraud, and money laundering, with 44 victims and $62 million in documented losses tied to their operation.</p><p class="paragraph" style="text-align:left;">The indictment itself was actually filed back in December 2024, so this unsealing feels more like a public pressure move than an imminent arrest situation - these folks are in St. Petersburg with no extradition possible. The $10 million Rewards for Justice bounty is interesting though, specifically asking for info on foreign government links to their operations. (<a class="link" href="https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-177" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/db673283-9f3a-4d1b-acb7-a02bb72448ec/image.png?t=1784252688"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5a471921-3763-4010-863b-9b0d3294a199/Screenshot_2026-07-16_at_8.45.31_PM.png?t=1784252745"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ec58ff6b-3fcd-4f46-8b6d-d13e6cc35b80/Screenshot_2026-07-16_at_8.47.53_PM.png?t=1784252883"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #176</title>
  <description>Microsoft ID used to track hackers in court case, Vidar infostealer intel breakdown, Zero days to watch out for, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-176</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-176</guid>
  <pubDate>Fri, 10 Jul 2026 12:24:00 +0000</pubDate>
  <atom:published>2026-07-10T12:24:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>10 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0f6d1d40-6bc8-4dc2-905b-74589b3846df/Newsletter_Header.png?t=1783537908"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/00e18321-b9d7-4797-8a33-050a4581b45b/Newsletter_Sponsor_Logo.png?t=1783538131"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">The BlackHat and DEFCON calendar invites have begun. I’m sure there won’t be 7 things I try to show up in the same 3 hour block on Tuesday. Who’s all going? Should I get the cabana by the pool again for us to do a meetup?</p><p class="paragraph" style="text-align:left;">Did you see my big announcement this week? Me and <a class="link" href="https://www.youtube.com/@LowLevelTV?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Low Level</a> started a podcast. We’ll be shipping weekly episodes and occasional guest interviews. We do film it for YouTube but you can find it on all your favorite podcast apps.</p><p class="paragraph" style="text-align:left;">Check it out! Subscribe to help us get it off the ground on the new channels.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.youtube.com/@lowdownpod?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">YouTube</a><br><a class="link" href="https://open.spotify.com/show/033o3CXvy7GV3fxIQmzYN2?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Spotify</a><br><a class="link" href="https://podcasts.apple.com/us/podcast/the-low-down/id1896824598?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Apple</a></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d8a4eb1-88b3-4eb2-9b3e-b06f75daf420/The_Low_Down_Logo__1_.png?t=1783635055"/></div><p class="paragraph" style="text-align:left;">Thanks Maze for being an awesome launch partner on this new venture. 🤘 </p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=5pgvSbh8L_0&t=27s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">The Low Down!</a> We recorded this one at PlanetScale HQ out in SF where we were hosting a panel.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: I <a class="link" href="https://www.youtube.com/watch?v=CqKxGBNbCPU&t=1s&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">interviewed HD Moore</a> about how hacking feels like its in the 90s again thanks to AI.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Early signs of <a class="link" href="https://www.linkedin.com/posts/irregular-com_we-ran-preliminary-evaluations-of-glm-52-activity-7478448392139010048-YyBG/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABZnM8BKlIB11WOhwpTnKR2wSH7AzwPTpg" target="_blank" rel="noopener noreferrer nofollow">frontier cyber capabilities</a> in Open-Weight models</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="alleged-member-of-criminal-cyber-ha"><a class="link" href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to United States</a></h3><p class="paragraph" style="text-align:left;">One of the more interesting debates that came out of the recent Scattered Spider arrest wasn&#39;t actually about the alleged cybercrime itself. It was about how the suspect got caught. A lot of people latched onto the court documents discussing Microsoft&#39;s GDID identifier and immediately jumped to the conclusion that Microsoft has some secret tracking mechanism baked into Windows. </p><div class="image"><a class="image__link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c2130b43-b543-4897-9f51-b57e8dfbd9b1/Screenshot_2026-07-08_at_1.48.21_PM.png?t=1783542284"/></a><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Click here for full court document</a></p></span></div></div><p class="paragraph" style="text-align:left;">But when digging into what security researchers were saying, the reaction was almost the opposite. Several people who spend their lives tracking threat actors were basically saying, &quot;Wait, you&#39;re surprised by this?&quot; One of the strongest reactions came from Allison Nixon, who has spent years helping identify and track cybercriminal groups. Her argument: anonymity isn&#39;t something you have. It&#39;s something you maintain until you don&#39;t.</p><div class="image"><a class="image__link" href="https://www.linkedin.com/feed/update/urn:li:activity:7479987731037569024/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fdc57479-67d0-4cf6-8932-69cc4b45a5ac/Screenshot_2026-07-08_at_1.42.04_PM.png?t=1783542544"/></a></div><p class="paragraph" style="text-align:left;">Nixon&#39;s comments were honestly some of the most fire takes I&#39;ve seen on this story. She pointed out that the suspect allegedly sent her death threats years ago, which immediately put him on her radar. From there, she did what she does: shared intelligence with providers, incident responders, security teams, and investigators. Her broader point was that threat actors often have a completely unrealistic view of anonymity. They think they&#39;re invisible because they use a VPN, a burner account, or some OPSEC tricks. Meanwhile, the people tracking them are collecting evidence, building profiles, connecting dots, and watching patterns over the course of years. As she put it, saying you&#39;re anonymous is like saying you&#39;ve won a marathon you haven&#39;t finished. The game doesn&#39;t end until your opponents either lose interest or catch you.</p><div class="image"><a class="image__link" href="https://x.com/vxunderground/status/2073427396535963967?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6fd0afe6-1e35-42e1-b8ac-457acbede3d3/Screenshot_2026-07-08_at_1.36.14_PM.png?t=1783542661"/></a><div class="image__source"><span class="image__source_text"><p>From my live stream here: <a class="link" href="https://www.youtube.com/live/5QmVWzh3JUs?si=h0SlCGJ8ERx08E3d&t=6260&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">https://www.youtube.com/live/5QmVWzh3JUs?si=h0SlCGJ8ERx08E3d&t=6260</a></p></span></div></div><p class="paragraph" style="text-align:left;">The technical details around the GDID itself turned out to be less dramatic than some headlines suggested. Researchers such as Massgrave pointed out that the identifier is closely related to Microsoft&#39;s long-documented Passport User ID system. In other words, this wasn&#39;t some secret spyware identifier that suddenly surfaced. It was part of the ecosystem Microsoft uses to tie together accounts, devices, activation services, and telemetry. The browsing-history angle that got everyone excited also appears to have involved optional Microsoft Edge telemetry rather than some universal logging feature affecting every Windows user. The bigger story isn&#39;t that Microsoft can identify a device, but how many different systems, services, accounts, and telemetry sources can be correlated once investigators start looking. (read more <a class="link" href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7479987731037569024/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://x.com/vxunderground/status/2073427396535963967?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="new-ctf-alert-help-pixel-stop-the-b"><a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">New CTF Alert: Help Pixel Stop the Breach at the Beach!</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/096f7040-dc18-4d64-8bd6-5f08e080c713/Blog_VTL-BreachattheBeach_202606_FNL.png?t=1783614720"/></div><p class="paragraph" style="text-align:left;">Looking for a fast, free way to level up your resume and data security skills? </p><p class="paragraph" style="text-align:left;">Varonis Threat Labs created <a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Breach at the Beach</a>, a new CTF that drops you into a live identity breach unfolding across Entra ID and M365. As the storm rolls in, you help Pixel the cat trace an AI threat actor who is quietly abusing legitimate features to move through the environment. You&#39;ll dig through real logs and audit trails to track them down the same way threat hunters do in the field, so you can save the day and bring the sunshine back. </p><p class="paragraph" style="text-align:left;">The best part? It&#39;s free to play, browser-based, and each stage you complete earns you a CPE credit. Finish all four stages by August 6 for a shot at a $2,000 Marriott Gift Card. </p><p class="paragraph" style="text-align:left;">Pixel&#39;s counting on you. Grab your sunglasses and <b><a class="link" href="https://hubs.ly/Q04nDCcb0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">play now</a></b>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="footage-shows-cop-stalking-woman-he"><a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Footage Shows Cop Stalking Woman He Met on a TV Set After Surveilling Her With a License Plate Reader</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/86f0332b-7a3a-4429-a39b-12fc34899669/Screenshot_2026-07-08_at_12.22.32_PM.png?t=1783543378"/><div class="image__source"><span class="image__source_text"><p>from my live stream here: <a class="link" href="https://www.youtube.com/live/5QmVWzh3JUs?si=7FRqGGnOIKjq4YLh&t=1872&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">https://www.youtube.com/live/5QmVWzh3JUs?si=7FRqGGnOIKjq4YLh&t=1872</a></p></span></div></div><p class="paragraph" style="text-align:left;">I had to cover this one because it&#39;s such a perfect example of the privacy and surveillance conversations we keep having in cybersecurity. A Florida police officer is under investigation after allegedly using law enforcement databases and AI-powered license plate reader systems to stalk a woman he met while working security on the set of the Apple TV+ show <i>Bad Monkey</i>. According to reporting from 404 Media, he spent weeks harassing her, asking for her name and Instagram information, then used Florida&#39;s law-enforcement-only DMV database, called DAVID, to pull her vehicle information. From there, he allegedly added her license plate to a surveillance hot list so he would receive real-time notifications whenever AI-powered cameras spotted her vehicle. She wasn&#39;t suspected of a crime.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0452aa40-a66e-4f94-bdf3-d0040b157398/Screenshot_2026-07-08_at_4.43.59_PM.png?t=1783543463"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Click to see video</a></p></span></div></div><p class="paragraph" style="text-align:left;">According to court records, he allegedly used government databases, automated license plate readers, surveillance alerts, and other law enforcement tools to track her movements and ultimately chase her down. At one point he allegedly told her, &quot;I told you I&#39;d find you and pull you over.&quot; That&#39;s an insane abuse of power. It&#39;s exactly why I roll my eyes whenever someone says we should be comfortable giving governments or corporations more surveillance capabilities because they&#39;ll only be used by the good guys. The “good guys” doing some heavy lifting here. (<a class="link" href="https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="felons-fraudsters-flog-offensive-cy"><a class="link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow"><b>Felons, Fraudsters Flog Offensive Cybersecurity Startup</b></a></h3><p class="paragraph" style="text-align:left;">Krebs has a knack for finding stories that make you stop and say, &quot;Wait, what?&quot; This week&#39;s example is Iris C2, a self-described offensive security company that claims to sell cyber capabilities and phone-hacking services to government customers. Krebs dug into the company&#39;s background and found connections to Jacob Wohl and Jack Burkman, two political operatives better known for a long history of failed ventures, misinformation campaigns, lawsuits, and criminal convictions than cybersecurity research. Iris C2 emerged from a penetration-testing business before pivoting toward zero day peddling, with related corporate records pointing back to Burkman&#39;s lobbying operation.</p><div class="image"><a class="image__link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bea4b96b-ac7d-4f92-9541-6faa39c139e9/Screenshot_2026-07-08_at_5.15.51_PM.png?t=1783545372"/></a></div><p class="paragraph" style="text-align:left;">One of the quotes Krebs highlighted was Wohl describing himself as highly technical and capable of building &quot;spectacularly exquisite capabilities,&quot; despite acknowledging he has no formal education or training in computer science or information security. Maybe there&#39;s a legitimate business here. Maybe there isn&#39;t. But if you&#39;re a security researcher frustrated with bug bounty programs or looking for someone to buy your zero-days, I&#39;d be asking a lot of questions before handing them over to a company whose founders are better known for political grift and felonies than cybersecurity. (<a class="link" href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="vidar-stealer-unmasked-code-signing"><a class="link" href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f32ab5c-c69f-4f11-a5af-725cf0a9329f/image.png?t=1783634055"/></div><p class="paragraph" style="text-align:left;">Unit 42 with a great breakdown of Vidar stealer campaign they spotted spiking in April 2026. It uses malvertising which is always one of a delivery mechanism that makes my ears perk up. Pushing fake cracked software downloads - but the evasion tricks are worth noting. The loader binaries are inflated with null bytes up to 491MB (the actual malicious content is only 2.3MB) specifically to skip automated sandbox analysis, paired with a fake JustWatch code-signing certificate and an in-memory AMSI bypass. The whole thing is built on a MaaS framework called Factory-v3 that generates unique hashes per build, making hash-based detection pretty useless.</p><p class="paragraph" style="text-align:left;">The payload is a two-fer: Vidar steals your browser creds and crypto wallets while XMRig mines Monero in the background using your CPU cycles. The operator gets a Telegram ping labeled &quot;X3D MINER • NEW LOG&quot; for every fresh infection. A second variant showed up April 24th swapping the fake JustWatch cert for one impersonating BleacherReport - same infrastructure, just iterating on the certificate approach. IOCs are in the full report if you want to go hunting, and defenders should prioritize stripping null byte padding before applying file size limits or you&#39;ll miss this one entirely. (<a class="link" href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="your-access-reviews-have-a-99-appro"><a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Your access reviews have a 99% approval rate. That&#39;s the problem.</a>*</h3><p class="paragraph" style="text-align:left;">If every reviewer clicks approve, the review didn&#39;t happen. Attestation fatigue is real: reviewers see 200 identical rows with no context and do the only reasonable thing. Opal&#39;s Paladin triages the queue before they ever open it — automating the routine 90% with a full audit trail, surfacing the 10% that needs a human call. <a class="link" href="https://events.actualtechmedia.com/register-now/2998/supervised-ai-for-access-reviews-you-can-defend/?pr=3646&utm_source=vulnu" target="_blank" rel="noopener noreferrer nofollow">Watch the on-demand demo</a>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="ubiquiti-patches-critical-uni-fi-fl"><a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS</a></h3><p class="paragraph" style="text-align:left;">If you&#39;re running Ubiquiti gear, patch now. Ubiquiti just dropped fixes for seven critical vulns in UniFi OS, headlined by CVE-2026-50746, a max severity command injection flaw in the UniFi Connect Application. Anyone with network access could exploit it to run commands on the host device - no user interaction required. The fix is version 3.4.20, go get it.</p><p class="paragraph" style="text-align:left;">The other six CVEs hit a wide range of Ubiquiti products - UniFi Talk, Access, Protect, their OS Server, and a bunch of routers, gateways, NAS and surveillance systems. With Censys tracking over 100,000 UniFi OS instances exposed to the internet (nearly half of them in the US), the blast radius here is significant. Worth noting that Ubiquiti gear has been a favorite target for state-sponsored groups before - Russia&#39;s GRU was caught using hijacked Ubiquiti routers as recently as 2024 to proxy espionage traffic. No confirmed exploitation in the wild yet, but given the history and the exposure numbers, that window probably won&#39;t stay open long. (<a class="link" href="https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="only-fans-models-are-accidentally-m"><a class="link" href="https://www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear</a></h3><p class="paragraph" style="text-align:left;">This one&#39;s a fun unintended consequence story. Scammers have been hijacking .gov and .edu websites - over 2,000 of them across 80 countries - to host fake &quot;leaked OnlyFans&quot; pages that redirect victims to malware and scam sites. Gold mine since they can use the Google authority score from the old legit site. Plot twist! OnlyFans creators filing DMCA takedown requests are acting as a free threat detection service, with over 384,000 takedown requests helping surface compromised government sites they probably didn&#39;t even know were hacked.</p><p class="paragraph" style="text-align:left;">UpGuard&#39;s research suggests that monitoring for adult content keywords on your .gov or .edu domain could serve as a solid early warning system for SEO injection attacks. What a weird and funny canary. One researcher noted that getting Google to remove the search results is surprisingly effective since these pages have virtually no visibility outside of search. The bulk of the DMCA requests are being fired off by one Estonian company called Rulta, which is raising some eyebrows about whether carpet-bombing compromised government sites with copyright notices is really the right approach - but hey, at least someone&#39;s finding these breaches. (<a class="link" href="https://www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="injective-sdk-on-npm-infected-with-"><a class="link" href="https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Injective SDK on npm infected with cryptocurrency wallet stealer</a></h3><p class="paragraph" style="text-align:left;">Supply chain attacks on npm and days that end in y. This one&#39;s nasty because it targeted the Injective Labs SDK - a package with 50,000 weekly downloads used by developers building crypto wallets, trading bots, and DeFi apps. As per usual, an attacker compromised a legitimate contributor&#39;s GitHub account, snuck in malicious code on June 8, and published version 1.20.21 before anyone noticed. The good news is the real account owner caught it within minutes and pushed a clean release. The bad news is 310 downloads happened in that window, and the malicious GitHub artifacts are still sitting there.</p><p class="paragraph" style="text-align:left;">The malware itself doesn&#39;t trigger on install, it waits until developers actually use wallet key generation or import functions, then quietly grabs the full mnemonic seed phrase and private key, bundles them up, and ships them out via HTTP POST to a legitimate-looking Injective Labs endpoint. Sneaky. If you&#39;re a developer who pulled that package, assume you&#39;re compromised - move your crypto to new wallets and rotate everything in your environment immediately.(<a class="link" href="https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="metas-new-ai-image-tool-lets-others"><a class="link" href="https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Meta&#39;s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ccaf90e6-c20a-42e8-a3dc-48b98f4ed004/image.png?t=1783632921"/></div><p class="paragraph" style="text-align:left;">Meta&#39;s spent a gazillion dollars on being a frontier AI lab and nobody is using their models. So why not just bake their new one into Instagram to force usage. Their new AI image model called Muse Image, and …wait for it… it&#39;s using your public Instagram photos by default to generate AI content - including letting other users @-mention your account to remix your photos into new images without notifying you. The opt-out is buried several menus deep in your settings, and here&#39;s the annoying part - anything already created with your photos before you disable it stays up. If you&#39;ve got a public Instagram account, it&#39;s worth taking the two minutes to go turn that off now.</p><p class="paragraph" style="text-align:left;">This is part of a broader trend of big tech companies quietly flipping AI training features to opt-out rather than opt-in. Google&#39;s doing the same thing with a new Search Services History setting that stores your images, audio, and video to train their models. Neither company is doing anything technically illegal here, but it’s concerning they didn’t have to. (<a class="link" href="https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="google-pays-250-k-for-linux-vulnera"><a class="link" href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Google pays $250K for Linux vulnerability allowing guest VM escapes</a></h3><p class="paragraph" style="text-align:left;">Two spicy Linux kernel vulnerabilities this week, and Google&#39;s bug bounty program had to write some big ol’ checks. The bigger one, dubbed &quot;Januscape&quot; (CVE-2026-53359), is a guest VM escape in KVM that sat undetected for 16 years. The short version: if you&#39;re renting a single cloud instance and have root on your guest VM, you can potentially take down or fully compromise the host machine and every other tenant on it. That&#39;s a bad day for any cloud provider. Google paid $250K for this one.</p><p class="paragraph" style="text-align:left;">The second bug, &quot;GhostLock&quot; (CVE-2026-43499), is a use-after-free in the kernel&#39;s futex priority-inheritance code that&#39;s been hiding since 2011 and lets low-privileged users escalate to root. That one netted $92K from Google&#39;s kernelCTF program. Both are patched in the kernel now, so go check your distro and make sure those fixes have actually landed on your systems. (<a class="link" href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-exploit-roundcube-flaw-to-s"><a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">Hackers exploit Roundcube flaw to spy on academic researchers</a></h3><p class="paragraph" style="text-align:left;">China-linked hackers have been hitting Roundcube webmail servers at U.S. and Canadian universities since May, specifically targeting physics and engineering departments plus anyone touching astrophysics, particle physics, or national security research. Since May 2026, they&#39;ve been chaining together n-day Roundcube vulnerabilities to steal credentials and drop either a webshell or VShell backdoor into server memory. The attack only requires the email to be opened in the webmail client, so the specific recipients may have been less important than the fact that those departments were running vulnerable Roundcube versions - suggesting prior recon.</p><p class="paragraph" style="text-align:left;">Their custom JavaScript stealer (dubbed IceCube by Proofpoint) escapes iFrames, steals creds and 2FA material, then pivots to server-side exploitation via a deserialization vuln to plant a webshell. If that fails, there&#39;s a fallback that pulls down SNOWLIGHT and ultimately VShell. The tooling is verbose, well-commented, and likely LLM-assisted. (<a class="link" href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="git-lost-how-git-hubs-ai-agent-was-"><a class="link" href="http://GitLost: How GitHub’s AI Agent Was Tricked Into Leaking Private Repository" target="_blank" rel="noopener noreferrer nofollow">GitLost: How GitHub’s AI Agent Was Tricked Into Leaking Private Repos</a></h3><p id="researchers-demonstrated-a-techniqu" class="paragraph" style="text-align:left;">Researchers demonstrated a technique they call &quot;GitLost,&quot; showing how an attacker could abuse GitHub&#39;s AI-powered issue-handling capabilities to retrieve information from private repositories. The attack starts with a public GitHub issue. Because the AI agent automatically reads issue titles and descriptions as part of its workflow, an attacker can embed instructions that look like legitimate questions but are actually prompts designed to manipulate the agent&#39;s behavior. In the proof of concept, the researchers simply asked the agent to retrieve information from both a public repository and a related private repository that the agent had access to. (<a class="link" href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-176" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d15d6139-9711-4b02-864c-b079690dd99f/Screenshot_2026-07-09_at_4.57.16_PM.png?t=1783634239"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b33113fa-379d-4895-8c95-39c99e49541e/Screenshot_2026-07-09_at_4.56.14_PM.png?t=1783634178"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6807f3e9-4b3f-4fd5-be49-fb67f485ff66/Screenshot_2026-07-09_at_5.24.02_PM.png?t=1783635879"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #175</title>
  <description>Free Fable! Fortibleed updates, New Citrix and Oracle active attacks, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-175</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-175</guid>
  <pubDate>Fri, 03 Jul 2026 12:28:00 +0000</pubDate>
  <atom:published>2026-07-03T12:28:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c4cfdfb1-8314-4550-855c-4ea6cf24fcea/Newsletter_Header.png?t=1783008291"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ab23d817-9f8e-4ddc-8ec3-0ad8e3a92be5/Newsletter_Sponsor_Logo.png?t=1783023326"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Finally back at home. Feels good to be writing this from my own office again. Just got back from SF the other night and had a great time talking AI and security at PlanetScale HQ. Have you been to SF recently? It is like a whole other world just by reading the billboards and bus stop ads. I swear there is a whole ecosystem of companies that only exist there.</p><p class="paragraph" style="text-align:left;">I love the city but it sure is dystopian to see someone sleeping at a bus stop where the ad is saying “Never hire another human again!” for some AI sales rep thing.</p><p class="paragraph" style="text-align:left;">But mission escape Texas heat for a few weeks was a success. Now its time to sweat again. Speaking of sweat, Vegas summer camp plans are in full swing. Calendar is already filling up, and me and Low Level have something fun planned for you guys to come to. More details soon, eyes peeled if you’re headed to BlackHat/DEFCON.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Michael Roytman and Ed Bellis are 2 data nerds who have thought about <a class="link" href="https://www.youtube.com/watch?v=AZSfRAfQ9UA&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">vulnerabilities and exploitation</a> longer than most anybody.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: This event at PlanetScale was awesome. <a class="link" href="https://www.youtube.com/live/F8tRi1RYf7c?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Really good live discussion</a> worth watching.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Mike Privette’s <a class="link" href="https://www.returnonsecurity.com/p/quantum-security-is-a-one-company-market?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Quantum Security Is a One-Company Market</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="us-lifting-export-control-restricti"><a class="link" href="https://cyberscoop.com/us-lifting-export-control-restrictions-anthropic-mythos-fable/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">US lifting export control restrictions on Anthropic’s Mythos, Fable</a></h3><p class="paragraph" style="text-align:left;">Well finding security vulnerabilities is possible again! (Right? Mythos is the only thing that could do that, right?) After a few weeks of back-and-forth, Anthropic and the Commerce Department have kissed and made up over Fable 5 and Mythos 5. The models are back online for U.S. users and export controls have been lifted, after the Trump administration briefly panicked over an Amazon threat intel report claiming they&#39;d jailbroken Fable&#39;s cybersecurity capabilities. The fix is new safety classifiers that Anthropic says will block the problematic behaviors 99.9% of the time, stress-tested by the federal Center for AI Standards and Innovation. Guardraily-er Guardrails!</p><p class="paragraph" style="text-align:left;">Anthropic&#39;s own testing found that ChatGPT 5.5, Claude Opus 4.8, and several other existing models could do the same things that freaked everyone out about Fable in the first place. So the export controls were essentially targeting capabilities that are already widely available. Former Bush-era Commerce official Christopher Padilla summed it up pretty well, calling the administration&#39;s AI policy approach &quot;chaotic and unpredictable&quot; - which is a bit rich given they&#39;re simultaneously loosening export controls on advanced AI chips to China. Defensive security folks should also note that the new classifiers will likely make Fable 5 even more restrictive for routine security work than it already was. Aka not useful. (<a class="link" href="https://cyberscoop.com/us-lifting-export-control-restrictions-anthropic-mythos-fable/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="open-source-runtime-security-harnes"><a class="link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Open-Source Runtime Security Harness for AI Agents (Two-line install)</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/41a1c696-b073-4aa4-95ed-daf77630119e/Screenshot_20260703_091423.png?t=1783070078"/></div><p class="paragraph" style="text-align:left;">Adrian is the open-source runtime security harness for AI agents. Five minutes from install to a continuous, independent security system monitoring your agents. While other tools watch what your agent does, Adrian also watches what it thinks and plans, blocking misalignment, prompt injection and tool abuse before they happen. </p><p class="paragraph" style="text-align:left;">Uses a technique theorised by OpenAI and Google DeepMind, and proven to catch 4x more malicious actions than activity monitoring alone. Built by Secure Agentics, a London-based AI security startup founded by former red teamers. </p><p class="paragraph" style="text-align:left;">Self-hosted and free, forever. (<a class="link" href="https://go.secureagentics.ai/CXwpDcX?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="forti-bleed-credentialtheft-campaig"><a class="link" href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">FortiBleed credential-theft campaign linked to Lynx ransomware</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/17209d6f-854d-47bc-99cd-d059d607b6ad/fortibleed-credential-stuffing.jpg?t=1783034602"/></div><p class="paragraph" style="text-align:left;">Turns out FortiBleed wasn&#39;t just opportunistic data hoarding. SOCRadar has now tied the whole operation directly to the INC and Lynx ransomware groups, and the scale is way bigger than originally thought. 430,000 FortiGate firewalls targeted, ~19,000 devices with actual traffic sniffers deployed, around 20 operators with defined roles, and roughly 500 servers running the operation. The smoking gun was finding browser sessions on FortiBleed infrastructure actively accessing both ransomware negotiation panels.</p><p class="paragraph" style="text-align:left;">The technical details are pretty gnarly too - they deployed a custom tool called &quot;FortiGate Sniffer&quot; to intercept VPN credentials directly from network traffic, left persistent backdoor accounts under the username &quot;adminin,&quot; and may have exploited an undisclosed Nextcloud zero-day for lateral movement. If you&#39;re running FortiGate devices, hunting for that &quot;adminin&quot; account is a good place to start. (<a class="link" href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="teen-suspect-in-scattered-spider-ha"><a class="link" href="https://therecord.media/teen-suspect-in-scattered-spider-hacks-extradited-to-us?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Teen suspect in Scattered Spider hacks is extradited to US</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/23ece5e1-d6e7-423f-bfc0-163f24153786/Screenshot_2026-07-02_at_6.25.54_PM.png?t=1783034757"/></div><p class="paragraph" style="text-align:left;">Another Scattered Spider member is facing the music - Peter Stokes, a 19-year-old dual U.S.-Estonian citizen, got extradited from Finland to Chicago this week. The centerpiece of the DOJ&#39;s case is a pretty textbook Scattered Spider playbook: call the IT help desk with Google Voice numbers, social engineer a password and MFA reset, compromise three accounts in under three hours, then drop an $8 million ransom demand on a luxury jewelry retailer. They also threw in ngrok for persistent access, which is becoming a bit of a calling card for this group.</p><p class="paragraph" style="text-align:left;">The company didn&#39;t pay the ransom, but still ate roughly $2 million in disruption and remediation costs. Stokes was originally picked up by Finnish authorities back in April following an Interpol Red Notice. This is part of a broader crackdown on Scattered Spider, a group the DOJ estimates has hit over 100 networks and collected more than $100 million in ransom payments. The arrests are starting to stack up for them. (<a class="link" href="https://therecord.media/teen-suspect-in-scattered-spider-hacks-extradited-to-us?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="pam-stealer-a-rustbased-mac-os-info"><a class="link" href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">PamStealer: a Rust-based macOS infostealer that validates credentials through PAM</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/329aa1f7-1723-4d30-840c-542dd14f30be/image.png?t=1783035659"/></div><p class="paragraph" style="text-align:left;">New macOS infostealer just dropped and this one&#39;s got some interesting tricks up its sleeve. PamStealer poses as Maccy, a legit clipboard manager, and uses a combo of AppleScript and JavaScript for Automation to drop its Rust payload. It validates stolen passwords locally through macOS&#39;s own PAM interface rather than phoning home with unverified creds - meaning it&#39;s making less noise than your typical commodity stealer. It also holds off on triggering the Full Disk Access prompt for up to 40 minutes after launch so nothing looks suspicious right out of the gate.<br><br>The social engineering piece is solid too - it tricks users into pressing Command-R which both executes the malicious code AND bypasses macOS&#39;s quarantine attribute that normally warns you about downloaded executables. Once it grabs your password, it throws up a fake &quot;file is damaged&quot; error so you just shrug and move on, none the wiser. Mac defenders should be watching for processes masquerading as Finder or Software Update, especially anything running under com[.]apple.finder.core or com[.]apple[.]security.daemon. The Jamf writeup is worth a read if you want the full technical breakdown. (<a class="link" href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fbi-seizes-net-nut-proxy-platform-p"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">FBI Seizes NetNut Proxy Platform, Popa Botnet</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/36b100b5-1721-490d-9936-57e25f41cf07/image.png?t=1783035992"/></div><p class="paragraph" style="text-align:left;">The FBI just took down NetNut, a residential proxy service run by publicly-traded Israeli company Alarum Technologies. If that name doesn&#39;t ring a bell, you might know it better as the Popa botnet - a network of over 2 million compromised devices, mostly cheap TV streaming boxes and smart TVs, rented out to cybercriminals for ad fraud, account takeovers, and traffic scraping. Google&#39;s threat intel team noted 316 distinct threat actor clusters using NetNut exit nodes in a single week, including both cybercriminal and espionage groups.</p><p class="paragraph" style="text-align:left;">NetNut had actually grown significantly after the FBI took down its biggest competitor IPIDEA earlier this year, so experts are hopeful this puts a real dent in the ecosystem. The practical takeaway here is worth repeating - those cheap no-name Android TV boxes flooding Amazon and AliExpress are essentially malware delivery devices. Spur found that 42% of LG webOS apps and over 25% of Samsung Tizen apps contain proxy SDKs that silently enroll your TV into these networks. Stick to name brands and verify your device supports Google&#39;s official Play Protect certification. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a> and <a class="link" href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">krebs here</a>)</p><h3 class="heading" style="text-align:left;" id="when-ai-invents-the-attack-browser-"><a class="link" href="https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">When AI Invents the Attack: Browser-Native Ransomware</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e8ec0acf-57ad-4c98-9f17-d69020f79e4a/Screenshot_2026-07-02_at_7.05.44_PM.png?t=1783037341"/></div><p class="paragraph" style="text-align:left;">Researchers found something genuinely concerning - while sifting through nearly 3,000 DeepSeek-attributed malware samples, they found one where the AI independently figured out that the browser&#39;s native <code>showDirectoryPicker()</code> API could be weaponized for ransomware. No exploit or installation required - just a permission prompt that, as ClickFix shows us, a ton of users would click. The attacker who prompted it probably had no idea this API even existed, which is nuts. DeepSeek connected the dots between a vague malicious goal and a real browser capability on its own.</p><p class="paragraph" style="text-align:left;">The PoC in the research is a fake AI photo tool that asks you to select a folder, encrypts your images during the fake &quot;processing&quot; step, and calls it a day. Worth noting this works on Android Chrome (since v132 added full File System Access support), and your DCIM folder - years of photos, banking screenshots, recovery codes - is fair game. iOS Safari doesn&#39;t expose the same API so iPhone users are in the clear here. No active campaigns have been spotted yet, but the barrier to operationalizing this is low enough that it warrants attention. Treat browser folder-access prompts like any other permission request, and maybe don&#39;t point random websites at your main photo library. (<a class="link" href="https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="researchers-spot-exploitation-of-an"><a class="link" href="https://cyberscoop.com/oracle-ebs-critical-vulnerability-exploited/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">Researchers spot exploitation of another critical Oracle defect</a></h3><p class="paragraph" style="text-align:left;">New CVE to keep on your radar - CVE-2026-46817, a 9.8 severity hit on Oracle E-Business Suite&#39;s payments processing feature. Threat intel firm Defused caught six exploitation attempts on their honeypots over a two-hour window Saturday, all from a single IP, and this was happening before any public proof-of-concepts were even available. Shadowserver&#39;s scans show about 950 potentially vulnerable instances exposed to the internet, with more than half sitting in the US.</p><p class="paragraph" style="text-align:left;">If this sounds familiar, it should - Clop ransomware had a field day with Oracle E-Business Suite last year, and ShinyHunters just got done tearing through PeopleSoft hitting over 100 organizations. The current activity looks more like someone testing their weaponization than an active campaign, but given the history here, patch your Oracle deployments before this gets interesting. (<a class="link" href="https://cyberscoop.com/oracle-ebs-critical-vulnerability-exploited/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ongoing-password-spray-campaign-abu"><a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175#new_tab" target="_blank" rel="noopener noreferrer nofollow">Ongoing password spray campaign abuses Azure CLI legacy auth flow to bypass MFA and compromise Microsoft 365 accounts.</a></h3><p class="paragraph" style="text-align:left;">Huntress caught a massive password spray campaign hitting Microsoft 365 that&#39;s bypassing MFA through a legacy auth flow most people forgot exists. Attackers are using old breached credentials and validating them through Azure CLI&#39;s OAuth 2.0 ROPC flow—which completely skips interactive MFA prompts because it sends creds directly to the token endpoint. Dozens of orgs thought they had MFA enforced everywhere, but their Conditional Access Policies weren&#39;t scoped to cover this flow. Tens of millions of login attempts and dozens of confirmed compromises.</p><p class="paragraph" style="text-align:left;">The fix is pretty straightforward but requires tightening up your CAP scope. You need to enforce MFA for <i>all</i> users, <i>all</i> cloud apps, and <i>all</i> client types. Microsoft has a setting specifically to block ROPC sign-ins (userStrongAuthClientAuthNRequired), and you should probably restrict Azure CLI access to admins only. Also worth noting: the attacks are coming primarily from an IPv6 range tied to LSHIY LLC (AS32167), so watch your sign-in logs for ROPC attempts and weird geo patterns. If you&#39;ve been relying on &quot;trusted location&quot; exceptions or report-only policies, those are getting exploited too.<br>(<a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175#new_tab" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="new-citrix-bleed-vulnerability-expl"><a class="link" href="https://www.securityweek.com/new-citrixbleed-vulnerability-exploited-immediately-after-public-disclosure/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure</a></h3><p class="paragraph" style="text-align:left;">New CitrixBleed-adjacent vuln just dropped for NetScaler, and threat actors were already hammering it within 24 hours of public disclosure - basically the moment watchTowr published their technical writeup and detection artifact generator. CVE-2026-8451 is an out-of-bounds read in NetScaler&#39;s XML parser that leaks memory contents back in the NSC_TASS cookie, no auth required. The catch is the appliance needs to be configured as SAML IDP, but that&#39;s not exactly a rare configuration in enterprise environments.</p><p class="paragraph" style="text-align:left;">Lupovis caught at least two separate threat actors probing their sensors, one from Frankfurt infrastructure and another from Koapu Cloud HK, both using the same playbook - probe for the right endpoint, get a 200 OK, immediately drop the payload. If you&#39;re running NetScaler as SAML IDP, patch now, and if you can&#39;t patch, disable SAML IDP until you can. Either way, go check your /saml/login traffic and NSC_TASS cookie values for anything weird - if you&#39;re already hit, you&#39;ll want to know sooner rather than later. (<a class="link" href="https://www.securityweek.com/new-citrixbleed-vulnerability-exploited-immediately-after-public-disclosure/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-175" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5c8d045e-6c29-4cb4-98e3-12e4ec7fed0e/Screenshot_2026-07-02_at_7.16.48_PM.png?t=1783037811"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/63e438bc-b3ac-45e5-99f6-b1a3e2582bdd/Screenshot_2026-07-02_at_7.19.25_PM.png?t=1783037969"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cef78d1c-af43-4293-aa66-d961cdd5437f/Screenshot_2026-07-02_at_7.23.33_PM.png?t=1783038218"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #174</title>
  <description>Fortibleed is a bigger nightmare than we thought, Scattered Spider members go to jail, LastPass has another breach this time via Salesforce, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-174</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-174</guid>
  <pubDate>Fri, 26 Jun 2026 12:38:00 +0000</pubDate>
  <atom:published>2026-06-26T12:38:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9ecd64fd-7bd0-41a8-9e85-89b6a6fa66d5/Newsletter_Header.png?t=1782445933"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.tines.com/platform/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9f65c037-0ece-4aff-82ff-883daf0129f4/Newsletter_Sponsor_Logo.png?t=1782445946"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing from rural Nevada outside Lake Tahoe. Sorry for all of you who hang out in my live streams, it’s been hard to find good internet connection in a quiet spot out here. I did stream a few times from the basement of a museum and a closed book store. You have to get creative to keep making content on the road!</p><p class="paragraph" style="text-align:left;">I’ve also apparently fallen into this new hobby of scuba diving since my keynote at Descent Cyber and decided to bring my gear and dive in the very cold Lake Tahoe. I was very jealous of the other guy on the boat who was in a dry suit with a heater in it.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b6ec7a95-c154-4786-ad89-fed949e6148f/IMG_8153.png?t=1782410001"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ad37701a-05f7-47f7-9ba5-ecf387c25e6f/Screenshot_2026-06-25_at_12.50.30_PM.png?t=1782409931"/></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🎧️ Something I heard: I heard I’ll be <a class="link" href="https://luma.com/ow1f82nb?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">speaking on a panel</a> with Low Level, Clint Gibler, and Daniel Miessler @ PlanetScale HQ during the AI Engineer World’s Fair on Monday</p><p class="paragraph" style="text-align:left;">🎤 Something I said: GitHub is <a class="link" href="https://youtu.be/8MqOtYAw9dw?si=-zgZGUWgLWnm6QXz&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">not OK</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: An <a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Open Letter</a> On Transparent AI Cyber Protections</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="russian-initial-access-broker-behin"><a class="link" href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Russian Initial Access Broker Behind FortiBleed Campaign</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fbcbd874-963b-4670-8c01-265c570226fa/Screenshot_2026-06-25_at_10.36.55_PM.png?t=1782445024"/></div><p class="paragraph" style="text-align:left;">A Russian initial access broker has been running a credential harvesting operation called FortiBleed, targeting over 430,000 FortiGate firewalls since at least February. The attacker uses a custom Golang tool called FortigateSniffer that abuses legitimate FortiOS diagnostic commands to passively sniff authentication traffic across 24 protocols. They&#39;re SSH brute-forcing their way into exposed firewalls, capturing cleartext credentials and password hashes, then cracking and selling that access. SOCRadar estimates over 110 million credentials have been compromised through 650+ harvesting pipelines.</p><p class="paragraph" style="text-align:left;">They&#39;re heavily focused on SMBs under 200 employees, and the operation isn&#39;t even Fortinet-exclusive despite the name. The threat actor is also hitting Sophos SSL-VPNs, RDWeb portals, MSSQL, Citrix, and grabbing RADIUS, NTLM, and Kerberos data. They successfully cracked Kerberos hashes and exfiltrated DFS backup data from a NATO-aligned defense contractor in June. SOCRadar suspects this Russian-speaking IAB might be providing access to state-sponsored groups or ransomware gangs, illustrating how initial access brokers fuel the broader cybercrime ecosystem. (<a class="link" href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read this</a>)</p><h3 class="heading" style="text-align:left;" id="the-hidden-operational-costs-slowin"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">The Hidden Operational Costs Slowing Down Network Teams</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0788bfa9-d1ab-43a1-bebb-c90b41aad678/Newsletter_ad_640x480__1_.png?t=1782375045"/></div><p class="paragraph" style="text-align:left;">Modern network operations are more complex than ever, but the work behind them is still too manual. Security teams are stuck chasing context across tools. IT teams are slowed down by repetitive operational work. The result is slower response, more friction, and duplicated effort.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">Tines’ new guide</a> explores how IT and security teams can move faster with fewer manual steps, clearer audit trails, and better operational visibility. Inside, you’ll learn practical ways to streamline incident response, change management, network troubleshooting, and more. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.tines.com/access/guide/the-ultimate-guide-to-network-operations-management/?utm_source=Vuln_U&utm_medium=paid_media&utm_content=newsletter-2606" target="_blank" rel="noopener noreferrer nofollow">Get the guide</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="password-manager-maker-last-pass-sa"><a class="link" href="https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Password manager maker LastPass says hackers stole customer support case data during Klue breach</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/xPen2H_HRdE" width="100%"></iframe><p class="paragraph" style="text-align:left;">LastPass with another breach, though this time it&#39;s not directly their fault. A market research firm called Klue got hit by an extortion group named Icarus, and since LastPass uses them via their Salesforce integration, customer names, phone numbers, email addresses, physical addresses, and support ticket data all got swept up in the theft. No password vaults were touched this time, which is an important bit.</p><p class="paragraph" style="text-align:left;">That said, support ticket data is nothing to brush off - those records tend to contain sensitive fragments like account recovery info and billing details. And given LastPass&#39;s 2022 breach where entire encrypted vaults were stolen and later cracked, their customers are understandably a little jumpy. Klue seems to have a big blast radius with HackerOne, Recorded Future, and Tanium are also in the affected list. Icarus is threatening to release the data if ransom isn&#39;t paid, so this one&#39;s still developing. (<a class="link" href="https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Read more</a>)</p><h3 class="heading" style="text-align:left;" id="from-langflow-to-monero-inside-cve-"><a class="link" href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">From Langflow to Monero: Inside CVE-2026-33017 Cryptominer</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/217030f8-5b45-4692-b2d7-45070cf2ad2b/Screenshot_2026-06-25_at_11.58.45_AM.png?t=1782403134"/></div><p class="paragraph" style="text-align:left;">Trend Micro dropped a pretty detailed writeup on a cryptomining campaign targeting Langflow, the AI workflow builder. CVE-2026-33017 is an unauthenticated RCE in Langflow&#39;s API that lets attackers just POST a Python payload to a public endpoint - no auth required. From there, a shell script drops a Go-based miner called lambsys that goes full scorched earth: kills rival miners, disables AppArmor, SELinux, and UFW. It then spreads laterally via SSH key reuse to every host the victim can reach. If you&#39;re running Langflow exposed to the internet, especially as root on infra with broad SSH access, you&#39;ve had a bad time.</p><p class="paragraph" style="text-align:left;">The malware traces back to a 2019 KORKERDS dropper called is[.]sh, and this one&#39;s named isp[.]sh - same SSH worm pattern, same userdel commands for rival miner accounts. The operator has been quietly iterating this toolchain since at least May 2024 with near-zero public visibility. The fix is straightforward - update Langflow to 1.9.0 and stop exposing it to the public internet. (<a class="link" href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="scattered-spider-hackers-plead-guil"><a class="link" href="https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Scattered Spider Hackers Plead Guilty on Day 1 of Trial</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/14666989-73fa-4c42-ab40-d65257e6aa55/Screenshot_2026-06-25_at_11.49.49_AM.png?t=1782402602"/></div><p class="paragraph" style="text-align:left;">Two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), saved everyone a six-week trial by pleading guilty on day one in the UK. These two were behind the 2024 Transport for London attack, but that&#39;s almost the least interesting thing about them. Jubair co-ran a SIM-swapping Telegram channel called Star Chat, was allegedly behind the massive 2022 SMS phishing campaign that hit 130+ organizations including LastPass and Signal, and was selling fake emergency data requests to extract user data from tech companies - all starting at age 15. Flowers, meanwhile, is reportedly the guy who gave those anonymous media interviews bragging about the MGM and Caesars casino hits back in 2023.</p><p class="paragraph" style="text-align:left;">The Scattered Spider takedown is slowly but surely wrapping up. Noah Urban already got 10 years last August, Tyler Buchanan pleaded guilty in April and is awaiting sentencing, and three more members still have charges pending. Jubair is also staring down a separate New Jersey federal indictment covering 120 network intrusions across 47 US companies with $115 million in ransom payments. Sentencing for Jubair and Flowers is set for July 15th in London, but something tells me the US will want their turn after that. (<a class="link" href="https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="f-fmpeg-pixel-smash-flaw-allows-rce"><a class="link" href="https://www.runzero.com/try/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow">Is Your Attack Surface Ready for the AI-Attack Era?</a>*</h3><p class="paragraph" style="text-align:left;">AI-generated exploits don&#39;t need sophistication, just a gap you don&#39;t know exists.</p><p class="paragraph" style="text-align:left;"><b>runZero</b> knows every asset, finds every exposure, and maps every attack path across IT, OT, IoT, cloud, and mobile, then prioritizes the vulnerabilities most likely to be exploited and verifies they&#39;re remediated. No agents. No credentials.</p><p class="paragraph" style="text-align:left;">Defenders win by default. Even against AI. They also offer a <b>21-day free trial</b>, so go test it out. (<a class="link" href="https://www.runzero.com/try/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=free-trial" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="f-fmpeg-pixel-smash-flaw-allows-rce"><a class="link" href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances</a></h3><p class="paragraph" style="text-align:left;">Nasty one dropped for FFmpeg - CVE-2026-8461, dubbed &quot;PixelSmash,&quot; is a heap out-of-bounds write in the MagicYUV decoder that allows RCE via crafted media files. Given that FFmpeg&#39;s libavcodec is basically everywhere - video players, media servers, NAS devices, cloud transcoding pipelines - the attack surface here is massive. JFrog confirmed successful exploitation against a pretty impressive list of targets including Jellyfin, Emby, Nextcloud, Immich, Kodi, OBS Studio and more.</p><p class="paragraph" style="text-align:left;">The delivery mechanism is a 50KB AVI, MKV, or MOV file that requires zero authentication to trigger. On the server side it fires when a file gets uploaded and auto-processed, and on desktop it can even trigger just by browsing to a folder containing the file if your file manager uses ffmpegthumbnailer for thumbnails. There&#39;s even a zero-click torrent attack path if the victim auto-downloads into a monitored media library. Patch to FFmpeg 8.1.2 now, but in reality you’re not the one that needs to upgrade it as its embeded in so much. Watch for patch notes …everywhere this week. (<a class="link" href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="whats-app-vb-script-campaign-uses-f"><a class="link" href="https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/63d7fe35-f201-43ad-b58f-58d64b18fa35/Screenshot_2026-06-25_at_12.07.02_PM.png?t=1782403632"/></div><p class="paragraph" style="text-align:left;">Kaspersky&#39;s flagging an active campaign spreading malicious VBScript files through WhatsApp, hitting users across Malaysia, Brazil, India, and several other countries. The attack is pretty straightforward social engineering - compromised WhatsApp accounts are being used to send contacts what look like business and financial documents (&quot;Financial Reports.vbs&quot;). Once opened, it kicks off a multi-stage infection chain that ends with ManageEngine RMM Central getting installed on the victim&#39;s machine, handing the attacker remote access. The campaign&#39;s got some interesting obfuscation techniques, with the VBScript files stuffed with fake Windows Update metadata and comments written in Chinese.</p><p class="paragraph" style="text-align:left;">Attribution is still up in the air, but Kaspersky found infrastructure overlaps with Gh0st RAT and ValleyRAT activity. The infection chain also behaves slightly differently depending on whether you&#39;re using WhatsApp Web vs the Desktop app - in the Desktop version, WhatsApp itself spawns the malicious WScript process, which is a neat trick. Standard advice applies here: if you weren&#39;t expecting a file attachment, even from a known contact, don&#39;t open it - especially anything ending in .vbs, .js, .ps1, or .bat. (<a class="link" href="https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="photo-zip-campaign-targeting-hospit"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/24218c6c-f046-4344-8c51-d3859655cfb8/image.png?t=1782444798"/></div><p class="paragraph" style="text-align:left;">Microsoft dropped a detailed threat intel report on an active campaign specifically targeting hotel and hospitality staff. Staff are getting phishing emails through Calendly&#39;s notification infrastructure (which neatly passes SPF/DKIM/DMARC checks) with lures like bedbug complaints and guest reviews, leading them to download what looks like a photo ZIP. Inside is a fake .png shortcut that kicks off an obfuscated PowerShell chain, ultimately dropping a Node.js implant for C2 persistence. The attacker has been actively evolving their PowerShell obfuscation through seven distinct phases since April 2026, which is a good sign they&#39;re watching for detections and adjusting.<br><br>What makes this one worth paying attention to is the dual persistence mechanism - they&#39;re using both HKCU\Run for the Node.js implant and a RunOnce loop for the PE payload that keeps repopulating itself. Microsoft confirmed that even after Defender blocked the PE payload on a compromised device, the Node.js persistence survived and resumed beaconing two days later. If you&#39;re in the Defender/Sentinel world, Microsoft dropped a full set of KQL hunting queries in the article worth grabbing. The campaign is dubbed TonRAT internally, and attribution is currently unknown. (<a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="mac-os-weaknesses-chained-to-silent"><a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">macOS Weaknesses Chained to Silently Disable Endpoint Security Agents</a></h3><div class="image"><a class="image__link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ba0d0099-82db-4e71-98b2-9bcdf36c9261/Screenshot_2026-06-25_at_12.13.34_PM.png?t=1782404023"/></a></div><p class="paragraph" style="text-align:left;">XM Cyber just showed how a regular macOS user — no admin rights needed — <a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">can silently kill enterprise security tools like EDR and MDM agents</a>. The attack chains together some older known primitives (abusing XPC connections and NIB file injection) with a clever new trick: exploiting how the kernel&#39;s code-signing trust cache sticks around after a legit signed app runs. Basically, you can inject malicious code that the system still trusts as if it&#39;s the real deal, then use it to call privileged functions that shut down security tools.</p><p class="paragraph" style="text-align:left;">They demo&#39;d this against CrowdStrike Falcon (completely unloaded it) and Kandji MDM (permanently killed it in two stages). CrowdStrike paid out a bounty and added detection, Kandji patched and got CVE-2026-39118, and a third unnamed EDR vendor is working on fixes. XM Cyber is dropping an open source tool called XPC Hunter at Black Hat 2026 that&#39;ll help find these exploitable XPC surfaces across all your installed apps, which should be fun for both sides of the aisle. (<a class="link" href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="zero-day-exploitation-of-vulnerabil"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/049e793b-658b-47b1-88ac-3cff9848ddc9/Screenshot_2026-06-25_at_12.17.23_PM.png?t=1782404252"/><div class="image__source"><a class="image__source_link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" rel="noopener" target="_blank"><span class="image__source_text"><p><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">Source: Mandiant</a></p></span></a></div></div><p class="paragraph" style="text-align:left;">Mandiant caught a threat actor exploiting a zero-day (CVE-2026-20245) in Cisco&#39;s SD-WAN Manager to escalate from admin to root access at a service provider. The attack chain started with rogue peering connections—possibly leveraging two other critical auth bypass vulns (CVE-2026-20127 and CVE-2026-20182) that weren&#39;t patched yet, or stolen certificates from an earlier compromise. Once in via SSH, the attacker toggled the default admin password back and forth to stay under the radar, then dropped a malicious CSV file called &quot;evil_tenant.csv&quot; through a file upload feature that didn&#39;t properly sanitize input. The CSV created a root-privileged account called &quot;troot&quot; by injecting entries into /etc/passwd and /etc/shadow.</p><p class="paragraph" style="text-align:left;">The attacker deleted artifacts, restored original configs, and ran a validation script to confirm all traces were scrubbed. They backed up files before modification so the device wouldn&#39;t throw alerts from broken configs. This is &quot;living off the edge&quot; tradecraft where network appliances become prime targets because they lack the logging depth for forensics while sitting at the perfect chokepoint for long-term intelligence collection. Cisco&#39;s pushed patches (20.9.9.2, 20.12.7.2, and newer versions), and if you&#39;re running SD-WAN infrastructure, now&#39;s the time to pull admin-tech logs and hunt for suspicious peering connections, rapid-fire password changes, or unexpected su commands to non-standard accounts. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="third-draft-kings-hacker-sentenced-"><a class="link" href="https://www.securityweek.com/third-draftkings-hacker-sentenced-to-18-months-in-prison/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow"><b>Third DraftKings Hacker Sentenced to 18 Months in Prison</b></a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/ae_iPShA1VM" width="100%"></iframe><p class="paragraph" style="text-align:left;">The third and final defendant in the 2022 DraftKings credential-stuffing attack just got sentenced. Nathan Austad, aka &quot;Snoopy,&quot; is heading to prison for 18 months and has to fork over $1.8 million in restitution and forfeiture. The crew used credentials from other breaches to access 60,000+ accounts, then drained funds or sold the accounts off.</p><p class="paragraph" style="text-align:left;">They were apparently joking about the FBI investigation in their own messages while still committing the crimes. All three are now convicted: Garrison got 18 months back in 2024, Stokes got 30 months in April, and now Austad wraps it up. Turns out the FBI could, in fact, do something about it. (<a class="link" href="https://www.securityweek.com/third-draftkings-hacker-sentenced-to-18-months-in-prison/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-174" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7fd42934-898f-4491-bd89-0d27e425ff56/Screenshot_2026-06-25_at_10.38.01_PM.png?t=1782445087"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/48669de0-998f-46a7-b826-92105f4c4b1d/image.png?t=1782445289"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72a82693-a5d9-41fe-a43f-c9a20eceb69b/Screenshot_2026-06-25_at_10.40.09_PM.png?t=1782445217"/><div class="image__source"><span class="image__source_text"><p>I love this twitter account, but this might be it’s magnum opus</p></span></div></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #173</title>
  <description>Free Mythos! Fortinet having massive security issues, FIFA has a near miss on massive security vulnerability in the World Cup streams, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-173</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-173</guid>
  <pubDate>Fri, 19 Jun 2026 12:44:00 +0000</pubDate>
  <atom:published>2026-06-19T12:44:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/207af6a7-0e53-46b5-8e86-4a2a2ff99b4b/Newsletter_Header.png?t=1781841988"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://withpersona.com/?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6ba84c68-892a-4165-a0c9-6b041be410ce/Newsletter_Sponsor_Logo.png?t=1761833305"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Out west a few weeks - speaking at some events. One of the major topics people are asking about is of course the Mythos and Fable restrictions from dot gov. I had to get creative with my live streaming locations this week including the basement of a museum and a book store that was closed today. In search of good wifi and a quiet corner.</p><p class="paragraph" style="text-align:left;">As a native New Yorker it certainly has been hard to avoid getting caught up in the energy of the Knicks victory. Between that and the World Cup it is straight up emotional for me watching people come together in community like that. It’s something we all crave and I’m glad this time crowds chanting on the streets is for joy.</p><p class="paragraph" style="text-align:left;">I’ll be at AI Engineering World’s Fair next week and I’m looking forward to talking to the group there as it will largely be out of the infosec echo chamber. (I mean… not that AI engineering isn’t it’s own echo chamber, but at least it’s not MY echo chamber).</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: This will accelerate the open weight models reaching <a class="link" href="https://x.com/mattjay/status/2065652704383270944?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">“Mythos tier” capabilities.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: <a class="link" href="https://www.youtube.com/watch?v=gDpuFDCLvBc&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">LowLevel’s take</a> on the Mythos/Fable situation</p><p class="paragraph" style="text-align:left;">🎤 Something I said: I talked to the hackers that found a <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">nation state 0day</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Absolute <a class="link" href="https://www.statesman.com/news/article/laredo-plane-crash-loop-20-austin-bound-22308875.php?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">tragedy for the Austin tech scene</a> - Josh, the founder/CEO of Capital Factory killed in a plane crash</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="an-open-letter-on-transparent-ai-cy"><a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">An Open Letter On Transparent AI Cyber Protections (and More Mythos Madness)</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/189bdbe5-f7ee-4e44-965f-d21ac5c7bf76/Screenshot_2026-06-17_at_4.26.42_PM.png?t=1781730265"/></div><p class="paragraph" style="text-align:left;">The Mythos conversation has gotten a little ridiculous. At this point, every cybersecurity discussion starts and ends with Mythos, Fable, Project Glasswing and the coming “AI vulnerability apocalypse”. </p><p class="paragraph" style="text-align:left;">I&#39;ve joked that people are treating Mythos like a skeleton key for the internet. I interviewed HD Moore about it, and that&#39;s essentially how he described the concern: a model that isn&#39;t just good at finding vulnerabilities but is also capable of reliably writing exploit code. That&#39;s the capability jump everyone is focused on, not vulnerability discovery by itself. AI has been helping find bugs for a while. The concern is what happens when exploit development becomes dramatically easier and more accessible.</p><p class="paragraph" style="text-align:left;">Anthropic&#39;s guardrails were so aggressive at launch that researchers were reporting they could barely discuss cybersecurity topics without triggering safety controls. That&#39;s what sparked the &quot;Free Mythos&quot; movement. If these models truly represent a step-function increase in capability, some people argue that locking them away behind a small group of approved users creates an unfair and potentially harmful asymmetry. <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Katie Moussouris</a> and others have gone further, arguing that concentrating access among a privileged few may actually create more risk than it reduces.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f881d1f0-d2a1-434f-89ab-a79ac448b099/Screenshot_2026-06-17_at_6.56.42_PM.png?t=1781737009"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Source: Luta Security</a></p></span></div></div><p class="paragraph" style="text-align:left;">Even if Anthropic, OpenAI, and others successfully gate frontier models today, it&#39;s hard to see how that remains sustainable. <a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAAznX8BNRuE7M9-TAcZRXWBU_xVm1GyipA" target="_blank" rel="noopener noreferrer nofollow">Alex Stamos</a> and others are pointing out that open-source models are advancing rapidly and could reach comparable capabilities in less than a year. If that&#39;s true, then much of the current debate becomes temporary by definition. All of the discussions about trusted access programs, Glasswing participants, and restricted model availability may ultimately be overtaken by open models that anyone can download and run. If the capability is coming regardless, the question shifts from containment to preparation.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f657a575-c9cd-42a0-8579-0b27e7d90ea5/Screenshot_2026-06-17_at_7.00.57_PM.png?t=1781737297"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAAznX8BNRuE7M9-TAcZRXWBU_xVm1GyipA" target="_blank" rel="noopener noreferrer nofollow">Source: Alex Stamos on LinkedIn</a></p></span></div></div><p class="paragraph" style="text-align:left;">That&#39;s why I keep coming back to the same conclusion. While everyone is debating Mythos, the security industry still has the same problems it had yesterday. We&#39;re still seeing supply chain compromises, credential theft, phishing campaigns, malicious browser extensions, and years-old security failures succeeding every day. The AI super hacker hasn&#39;t replaced those threats. Cybersecurity didn&#39;t suddenly become obsolete. If Mythos-class models eventually make exploitation easier, we&#39;ll adapt and deal with that too. But for now, defenders still have vulnerabilities to patch, identities to protect, and incidents to respond to. The vulnerability apocalypse may or may not arrive. In the meantime, cybersecurity still looks a lot like cybersecurity. (read more <a class="link" href="https://freefable.org/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.linkedin.com/posts/alexstamos_open-letter-on-transparent-ai-cyber-protections-activity-7472292548695441409-jiTu/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="deepfake-attacks-surged-50-x-are-yo"><a class="link" href="https://withpersona.com/lp/wf-infosec?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" target="_blank" rel="noopener noreferrer nofollow">Deepfake attacks surged 50x. Are your security defenses ready?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a9846bff-0c7e-421f-963e-26873a9456c1/header_image_1200_800_vulnu.png?t=1781803238"/></div><p class="paragraph" style="text-align:left;">We’ve seen deepfake attacks surge 50x, yet 85% of CISOs say they lack GenAI-ready incident response plans. Workforce security is no longer about if you&#39;ll be targeted, but whether you&#39;re prepared.</p><p class="paragraph" style="text-align:left;"><b>Persona</b> verifies employees, contractors, and vendors in seconds — automating identity checks to eliminate manual work and stop impersonation attacks before they spread. Integrate Persona&#39;s Workforce IDV solution with your existing security tech stack to verify who’s actually behind every login, device, and network. (<a class="link" href="https://withpersona.com/lp/wf-infosec?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_wf_ds_wf-idv_fy26q2-vuln-u-nl" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="accenture-shells-out-418-b-on-three"><a class="link" href="https://cyberscoop.com/accenture-industrial-cybersecurity-acquisition-dragos-netrise-runzero/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Accenture Shells Out $4.18B On Three Companies in Big Industrial Cybersecurity Push</b></a></h3><p class="paragraph" style="text-align:left;">This is one of those deals that makes the entire cybersecurity industry stand up and pay attention. Accenture is acquiring a majority stake in Dragos and bringing runZero and NetRise under the same umbrella, creating a combined OT and asset intelligence powerhouse. What makes this story fun for me personally is that these aren&#39;t random companies. runZero founder HD Moore is a longtime industry legend who was literally just on my YouTube channel. NetRise founder Tom Pace is someone I run into at the gym. These are companies built by people who have spent years grinding in the security community, and now they&#39;re part of a deal valued at roughly $4.2 billion. That&#39;s a massive validation not just for the companies involved, but for the broader cybersecurity startup ecosystem. (also both Austin founders!)</p><p class="paragraph" style="text-align:left;">I don’t normally cheerlead investment round raises or acquisitions but this one is too close to home and too good for the security community. The founder/creator of Metasploit winning is just a win for all of us. Way to go HD, Tom, Rob and all your teams. (<a class="link" href="https://cyberscoop.com/accenture-industrial-cybersecurity-acquisition-dragos-netrise-runzero/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="forti-bleed-leak-exposes-fortinet-v"><a class="link" href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/34de39c2-da2f-467f-8ae6-d8971d11564f/Screenshot_2026-06-17_at_4.33.10_PM.png?t=1781731714"/></div><p class="paragraph" style="text-align:left;">The latest Fortinet stories are a perfect example of why I struggle to get excited about AI-generated exploits, when the industry is still drowning in known vulnerabilities. Researchers uncovered what appears to be a massive credential dump affecting roughly 73,000 Fortinet VPN devices. </p><p class="paragraph" style="text-align:left;">The dataset reportedly contains usernames, email addresses, and plaintext passwords, along with organizational details that could help attackers prioritize targets. Some researchers who reviewed the data say they&#39;ve been able to verify at least some of the credentials as authentic. The most concerning detail is that the information appears to have come from exported FortiGate configurations, raising obvious questions about how attackers obtained them in the first place. Unclear by my money is on an 0day.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4cf0613e-9f11-4789-af1f-823ea05596ec/Screenshot_2026-06-17_at_5.32.34_PM.png?t=1781731964"/></div><p class="paragraph" style="text-align:left;">At the same time, Fortinet is once again dealing with <a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">active exploitation</a> of recently disclosed vulnerabilities. Researchers observed attackers exploiting critical FortiSandbox flaws shortly after patches became available, while older Fortinet vulnerabilities continue to be abused years after disclosure. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="google-exposes-china-espionage-grou"><a class="link" href="https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Google Exposes China Espionage Group That’s Been Lurking in Networks Undetected Since 2023</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d70c6ce2-c3a9-41d2-9328-6046b84dd34e/Screenshot_2026-06-17_at_4.41.04_PM.png?t=1781732087"/></div><p class="paragraph" style="text-align:left;">This is the kind of story that actually keeps me up at night, not because it&#39;s particularly novel, but because it reinforces something we&#39;ve been hearing for years from U.S. intelligence agencies and law enforcement. The FBI has repeatedly warned that Chinese threat actors are sitting inside critical infrastructure environments, maintaining access, and in many cases not doing anything immediately disruptive. Google&#39;s reporting traces activity back to at least September 2023, with attackers establishing persistence, deploying credential theft tools, upgrading malware, and maintaining access over long periods of time. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">What stands out in Google&#39;s report</a> is that the tradecraft itself isn&#39;t especially exotic. The malware capabilities look familiar: credential harvesting, backdoors, command-and-control infrastructure and data exfiltration. The operators clearly invested heavily in operational security, routing traffic through compromised routers, residential proxy networks, VPS infrastructure and U.S.-based systems to make attribution and detection more difficult.</p><div class="image"><a class="image__link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59787f71-377c-4718-ad85-c4fd27f57f36/Screenshot_2026-06-17_at_5.42.02_PM.png?t=1781732529"/></a></div><p class="paragraph" style="text-align:left;">The part that surprises me is the dwell time. If the earliest known compromises date back to 2023, how do organizations fail to notice activity for that long? Some of that is undoubtedly a testament to the attackers&#39; opsec. But some of it is also the reality that many critical infrastructure operators don&#39;t have massive security budgets, dedicated threat hunting teams, or twenty-four-hour security operations centers. These aren&#39;t always Fortune 100 companies with unlimited resources. They&#39;re often organizations running essential services while trying to manage increasingly complex threats with limited personnel and funding.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/24d0ba1a-85c8-4218-8e07-14f2a6611cfb/Screenshot_2026-06-18_at_1.12.59_PM.png?t=1781802826"/></div><p class="paragraph" style="text-align:left;">Chinese espionage groups aren&#39;t succeeding because they have some mythical capability that nobody else possesses. They&#39;re succeeding because they&#39;re patient, disciplined, and often operating against organizations that can&#39;t afford perfect security. (read more <a class="link" href="https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="threat-actors-abuse-claudeai-shared"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">80% of Organizations Are Sitting on Access They Forgot Existed</a>*</h3><p class="paragraph" style="text-align:left;">Every company has it. Former employees, old service accounts, permissions that were supposed to be temporary and never got cleaned up.</p><p class="paragraph" style="text-align:left;"><b>Opal Security</b> analysed provisioning data across thousands of systems and found that 80% were exposed through stale entitlements. As AI agents start requesting access to more systems, those forgotten permissions can turn into a much bigger problem.</p><p class="paragraph" style="text-align:left;">See what AI-ready security teams are doing differently in Opal&#39;s 2026 report. (<a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="threat-actors-abuse-claudeai-shared"><a class="link" href="https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/70302d08-b287-4241-abfa-5431df153f5e/Screenshot_2026-06-18_at_3.13.19_PM.png?t=1781810008"/></div><p class="paragraph" style="text-align:left;">This is one of the more clever ClickFix-style campaigns I&#39;ve seen lately because it abuses something people already trust: shared AI chats. Researchers found attackers buying ads that redirected victims to publicly shared Claude AI conversations. The victim thinks they&#39;re clicking on a helpful AI-generated guide, maybe instructions for installing software or fixing a common problem, but the shared chat has been crafted to display malicious commands. The user follows what appears to be legitimate AI advice, opens a terminal window, pastes the commands, and unknowingly downloads malware. (<a class="link" href="https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="texas-government-data-breach-allowe"><a class="link" href="https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><b>Texas Government Data Breach Allowed Hackers to Steal 3 Million Driver’s Licenses and Passports</b></a></h3><p class="paragraph" style="text-align:left;">This Texas breach immediately gets my attention because of the type of data involved. A lot of breach disclosures talk about names, email addresses, phone numbers, and physical addresses being exposed, and honestly, I&#39;ve become a little numb to those at this point because so much of that information is already floating around online. Driver&#39;s licenses and passport data are different. That&#39;s identity theft gold. According to reports, attackers accessed data tied to roughly three million records through a Texas government system used to manage licenses and permits. When you start talking about government-issued identity documents, you&#39;re talking about the exact kind of information criminals need to convincingly impersonate someone in the real world.</p><p class="paragraph" style="text-align:left;">The reason this hits home for me is that I&#39;ve dealt with identity theft myself. In my case, someone created a physical copy of my driver&#39;s license with their photo attached and tried to finance a Corvette in my name. <i>(</i><a class="link" href="https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow"><i>read more</i></a><i>)</i></p><h3 class="heading" style="text-align:left;" id="i-couldve-rickrolled-the-entire-fif"><a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">I Could&#39;ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2ba9e0e0-ee72-497a-848d-f3c4b1149665/Screenshot_2026-06-18_at_10.44.38_PM.png?t=1781840686"/></div><p class="paragraph" style="text-align:left;">A researcher nearly became the most chaotic villain in sports history. By registering as a FIFA football agent - just uploading your ID to a public portal - you&#39;d get added to FIFA&#39;s Microsoft Entra tenant. From there, while the frontend apps dutifully showed &quot;access denied&quot; pages, the backend APIs didn&#39;t check anything. The Football Data Platform handed over live RTMP stream keys, camera feeds, and full broadcast controls for every World Cup match. They confirmed it was live by pulling a tactical camera feed into VLC. Every match. Every camera angle. One click from killing a live broadcast. (<a class="link" href="https://bobdahacker.com/blog/fifa-hack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="152-chrome-live-wallpaper-extension"><a class="link" href="http://152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic" target="_blank" rel="noopener noreferrer nofollow"><b>152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9b48041b-2b5f-4aad-a736-396b141c8fd7/Screenshot_2026-06-17_at_5.48.31_PM.png?t=1781732919"/></div><p class="paragraph" style="text-align:left;">Researchers at Socket uncovered a network of 152 Chrome extensions masquerading as anime-themed live wallpapers that collectively accumulated more than 105,000 installs. Under the hood, they were doing far more than changing your browser background. Built from a shared codebase and distributed across dozens of publisher accounts, the extensions generated fraudulent web traffic, manipulated search activity, performed ad fraud, and included anti-forensics techniques designed to make analysis more difficult.</p><p class="paragraph" style="text-align:left;">Chrome extensions are just a thing I’ll never be able to stop talking about. (<a class="link" href="https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="nintendo-third-party-program-hit-by"><b><a class="link" href="https://www.freep.com/story/news/local/michigan/2026/06/17/nintendo-cyberattack-ransom-tinypulse/90588561007/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">Nintendo, Third-Party Program Hit By Cyberattack for $2M Ransom</a></b></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/62a254e1-873e-4d08-ba89-0f75549332a1/Screenshot_2026-06-17_at_5.53.14_PM.png?t=1781733202"/></div><p class="paragraph" style="text-align:left;">The interesting part of this story isn&#39;t really Nintendo, but the third-party risk angle. According to reports, a ransomware group is demanding $2 million after compromising TinyPulse, a service Nintendo used for internal employee surveys. The attackers claim to have stolen roughly 859 megabytes of data, including employee names, email addresses, survey responses, bank statements, and W-9 forms. Nintendo says its own systems were not compromised and that no customer financial data was accessed. Instead, the exposure appears limited to information held by the third-party provider, much of which Nintendo says is several years old. (<a class="link" href="https://www.freep.com/story/news/local/michigan/2026/06/17/nintendo-cyberattack-ransom-tinypulse/90588561007/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-173" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/248d005f-3f86-44ff-8549-c21ac0f82542/Screenshot_2026-06-18_at_10.40.07_PM.png?t=1781840413"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/841f7413-7ba6-414b-9b55-934fd12cba4b/Screenshot_2026-06-18_at_10.42.45_PM.png?t=1781840620"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/af1937f9-adc1-4cc1-ac43-2d8830833b2f/image.png?t=1781840609"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Vulnerable U | #172</title>
  <description>Mythos and Fable updates, AI agents falling for phishing emails, Iran hacked California water providers, ServiceNow breach, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-172</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-172</guid>
  <pubDate>Fri, 12 Jun 2026 12:48:00 +0000</pubDate>
  <atom:published>2026-06-12T12:48:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ff8ff971-b56b-40bb-9e47-76da04fa274e/vulnu-header-2026-06-12.png?t=1781236059"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Anyone else in full summer brain? Just me because I spent the weekend scuba diving? Let me say this about <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> - the organizers put on a masterclass in throwing an event that balanced great cybersecurity content, heavy hitters from our industry, and camaraderie through diving together. It was an extremely well thought out and planned event that I’ve already committed Vulnerable U to sponsor again next year. Do recommend for the divers or dive curious.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/420952a6-1442-468d-8435-b91fb959bbf8/Screenshot_2026-06-11_at_6.22.34_PM.png?t=1781220186"/><div class="image__source"><span class="image__source_text"><p>Opening Keynote</p></span></div></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc151014-47ab-4628-87f0-477922e7dcf4/Screenshot_2026-06-11_at_6.22.53_PM.png?t=1781220192"/><div class="image__source"><span class="image__source_text"><p>In a ship wreck 60ft below</p></span></div></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: MSRC couldn’t possibly do anything worse this week… oh. <a class="link" href="https://x.com/mattjay/status/2062592867202109747?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Oh ok.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Blink 182 dropping updates on <a class="link" href="https://myspace.com/blink182?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">MySpace</a> - as someone who was a Blink super fan and MySpace power user, it’s a big week for me. They’re teasing a 25 yr anniversary tour.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Meta Built <a class="link" href="https://www.youtube.com/watch?v=A-JKWpICSzE&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">the Dumbest Hack</a> in Instagram History</p><p class="paragraph" style="text-align:left;">🔖 Something I read: I’ve been quoting this blog every day since I read it. Cloudflare’s <a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: what Mythos showed us</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="anthropics-new-model-mythos-on-a-le"><a class="link" href="https://cyberscoop.com/anthropic-claude-fable-5-release-mythos-guardrails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Anthropic’s New Model: Mythos On A Leash</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/391ec7c1-8830-4ebb-bd38-d08a03782607/Screenshot_2026-06-10_at_9.11.21_AM.png?t=1781097100"/></div><p class="paragraph" style="text-align:left;">For all of you who hang out in my live streams, you know I was hitting that MYTHOSSSS (spoken like Star Trek KHANNNN) sound button a ton this week. That’s because it has escaped the lab! Well sort of. Anthropic has now broadly released Fable 5, its public-facing “Mythos-class” model, and the reaction I&#39;m seeing is a mix of excitement, confusion, and frustration. The marketing narrative is still very much that Mythos was so powerful it needed to be carefully contained before being released to the public. </p><p class="paragraph" style="text-align:left;">Meanwhile, the actual experience many people are having is running headfirst into guardrails. In some cases, users report that simply mentioning cybersecurity-related topics is enough to trigger restrictions, model downgrades, or redirects to safer behavior. If Mythos escaped the lab, it appears to have done so while wearing several layers of bubble wrap.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5565f889-7ff5-4246-9c76-ec27452d34f3/Screenshot_2026-06-11_at_10.24.19_PM.png?t=1781234668"/></div><p class="paragraph" style="text-align:left;">What&#39;s becoming clearer is that Anthropic is taking an unusually aggressive approach to controlling how Fable 5 is used. Beyond the cybersecurity restrictions, the company has confirmed that it will actively limit the model&#39;s usefulness for certain frontier AI development tasks. These interventions aren&#39;t always visible to users. Anthropic says it may modify outputs or reduce effectiveness for requests related to building competing frontier models, training infrastructure, or AI acceleration research. At the same time, the company expanded data retention policies around Fable usage, citing safety and compliance requirements. That&#39;s generating almost as much discussion as the model itself.</p><p class="paragraph" style="text-align:left;">My takeaway remains about the same as it was when Mythos launched. I believe the underlying capabilities are real because I&#39;ve talked directly with people involved in Project Glasswing who have seen the model find vulnerabilities and security issues that other tools missed. And exploit/PoC development are definitely boosted. (read more <a class="link" href="https://cyberscoop.com/anthropic-claude-fable-5-release-mythos-guardrails/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-claude-fable-5-but-its-available-for-a-limited-time/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, here, here and here)</p><h3 class="heading" style="text-align:left;" id="timetoexploit-is-down-to-one-day-no"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Time-to-exploit is down to one day. Now what?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dfe53be7-5b81-4248-bfc0-ce84964997b9/ASM_report_header.png?t=1778780069"/></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Intruder</a> analyzed 3,000 organizations&#39; attack surfaces. Top finding: more teams should be asking &#39;does this actually need to be on the internet?’</p><p class="paragraph" style="text-align:left;">There’s no better time to ask it. AI can now find zero-days autonomously and time-to-exploit has shrunk to a single day. Anything on the internet that doesn&#39;t need to be is a target the moment a new CVE drops.</p><p class="paragraph" style="text-align:left;">In the report:</p><ul><li><p class="paragraph" style="text-align:left;">What are the most common attack surface exposures?</p></li><li><p class="paragraph" style="text-align:left;">How long are organizations taking to fix them?</p></li><li><p class="paragraph" style="text-align:left;">How does your industry compare?</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Get the report now.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="measuring-ll-ms-impact-on-n-day-exp"><a class="link" href="https://red.anthropic.com/2026/n-days/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Measuring LLMs’ Impact On N-Day Exploits</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b5790303-567c-4671-b3ee-25b672aa7528/Screenshot_2026-06-10_at_8.56.38_AM.png?t=1781096581"/></div><p class="paragraph" style="text-align:left;">Anthropic with some sobering research on how their latest Claude model can automatically weaponize patches. Their most capable model, Mythos Preview, turned 18 recent Firefox security patches into 8 working exploits, with the first one ready in under an hour. On the Windows side, it cranked out 8 full privilege escalation exploits from kernel patches, basically going from low-privilege user to full SYSTEM control for about $2,000 in API credits per exploit.</p><p class="paragraph" style="text-align:left;">This flips the traditional patch gap timeline on its head. Where it used to take expert reverse engineers weeks or months to develop N-day exploits, we&#39;re now looking at hours. WannaCry hit 59 days after the patch was available. Mythos Preview would have had working exploits ready before most organizations even started their patch rollouts. The implications for anything that patches slowly - IoT devices, industrial systems, medical equipment - are pretty grim. (<a class="link" href="https://red.anthropic.com/2026/n-days/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="mini-shai-hulud-miasma-and-hades-wo"><a class="link" href="https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud, Miasma and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/edb5432b-ddc7-4c77-b5e0-c972dbdb2e87/Screenshot_2026-06-10_at_8.07.38_AM.png?t=1781093265"/></div><p class="paragraph" style="text-align:left;">We&#39;ve officially lost the plot on supply-chain attack names. We now have Mini Shai-Hulud, Hades, Miasma, and whatever comes next. Underneath the increasingly ridiculous naming convention, though, there&#39;s a real evolution happening. Socket&#39;s threat research team caught the campaign evolving again, this time with 23 new malicious PyPI packages targeting bioinformatics and MCP developers. These attackers keep switching up their delivery methods - some packages now hide malicious code in compiled native extensions that execute at import time, while others use typosquats like &quot;rsquests&quot; and &quot;tlask&quot; to catch typos. The standout is langchain-core-mcp, which installs a loader that searches your entire sys.path for _index.js payloads, meaning the malicious code doesn&#39;t even need to be in the same package.</p><p class="paragraph" style="text-align:left;">These aren&#39;t just random packages either - they&#39;re targeting real scientific computing tools like embiggen, gpsea, and pyphetools that researchers actually use. Once executed, the JavaScript stealer grabs everything from GitHub tokens to cloud credentials, SSH keys, and Docker configs.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e74a47a5-edd7-4aae-99e0-40c07593da10/Screenshot_2026-06-10_at_8.08.35_AM.png?t=1781093325"/></div><p class="paragraph" style="text-align:left;">The funniest part of this entire report was that the malware includes fake system instructions and policy-triggering text embedded in comments that don&#39;t affect execution at all but appear designed specifically to confuse AI-powered security tools and analyst copilots. The runtime ignores it, but an AI scanner might not. (<a class="link" href="https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="handala-iran-claims-breach-of-calif"><a class="link" href="https://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Handala (Iran) Claims Breach of California Water Service</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0f122830-0447-4664-bdb0-1a1f72d7bba5/image.png?t=1781232388"/></div><p class="paragraph" style="text-align:left;">Handala just hit California Water Service pretty hard, dumping 5GB of customer data and internal credentials as their latest hack. The Iranian group managed to breach both the billing system (grabbing customer PII across multiple districts) and an internal RTKBase GPS correction network that field crews use for precision mapping. They got administrative credentials for the GPS network and essentially mapped out the entire infrastructure across seven service districts.</p><p class="paragraph" style="text-align:left;">This isn&#39;t just a data grab - Handala&#39;s known for escalating to destructive attacks after their initial claims, and they&#39;ve got custom wipers in their toolkit. Same group that hit Stryker medical and wiped everything they could.</p><p class="paragraph" style="text-align:left;">The RTKBase system probably served as their entry point, which makes sense since these GPS correction systems often run on basic hardware with weak authentication. Water utilities everywhere should be checking if their survey equipment is internet-exposed right about now, especially since this fits the pattern of Iranian groups specifically targeting US water infrastructure that we&#39;ve been warned about. (<a class="link" href="https://www.dataminr.com/resources/intel-brief/cyber-intel-brief-handala-claims-breach-of-california-water-service/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="80-of-systems-are-exposed-through-s"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">80% of Systems Are Exposed Through Stale Access. Here&#39;s the Fix.</a>*</h3><p class="paragraph" style="text-align:left;">Stale entitlements create an open door. Opal analyzed real provisioning data across thousands of systems and found 80% exposed through access that was never revoked. When AI agents start requesting infrastructure access at scale, that surface compounds fast. Opal&#39;s 2026 report has the data on what AI-ready teams did differently.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=vulnu&utm_medium=cpc&utm_campaign=state-of-iga-report&utm_term=state-of-iga-report&utm_content=secondary&hstk_campaign=40445781-&hstk_network=vulnu&hsa_acc=45127704&hsa_cam=40445781-&hsa_net=vulnu" target="_blank" rel="noopener noreferrer nofollow">Read the report.</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="shiny-hunters-targets-education-sec"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</a></h3><p class="paragraph" style="text-align:left;">ShinyHunters just pulled off a pretty impressive campaign targeting Oracle PeopleSoft systems with a zero-day exploit (CVE-2026-35273). Between late May and early June, they hit over 100 organizations - mostly universities and colleges - using a critical RCE (9.8 CVSS). They were exploiting this before Oracle even knew about it, making it a proper zero-day until the patch dropped on June 10th.</p><p class="paragraph" style="text-align:left;">These guys set up staging servers with MeshCentral agents disguised as Microsoft Azure services, complete with SSL certs for &quot;azurenetfiles[.]net&quot; to make it look legit. But here&#39;s where it gets sloppy - they left their staging directories wide open, exposing command histories, custom lateral movement scripts, and their bash history showing exactly how they mapped internal networks and exfiltrated data. Mandiant caught wind and started warning potential targets, but some organizations still got breached and had their data posted on the ShinyHunters leak site. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="service-now-customers-hit-by-unauth"><b><a class="link" href="https://thecybersecguru.com/news/servicenow-api-vulnerability-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">ServiceNow Customers Hit by Unauthorized API Access – And the Company Knew for Months</a></b></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/14f25f8d-3484-471e-825c-9e720b3e0696/Screenshot_2026-06-10_at_8.42.49_AM.png?t=1781095374"/></div><p class="paragraph" style="text-align:left;">After days of speculation driven by customer reports on Reddit, ServiceNow disclosed that attackers exploited a vulnerability that could allow an unauthenticated user, under certain circumstances, to gain greater access to customer instances than intended.</p><p class="paragraph" style="text-align:left;">Turns out they had an API endpoint sitting there configured with &#39;requires_authentication=false&#39;. The vulnerable endpoint &#39;/api/now/related_list_edit/create&#39; let unauthenticated users query customer instance data, which could include all sorts of juicy enterprise info like support tickets, employee records, and internal docs. They quietly patched it on June 5th, but not before attackers (or maybe bug bounty researchers) had some fun with it.</p><p class="paragraph" style="text-align:left;">ServiceNow received a confidential bug bounty submission about this exact issue back in April, but didn&#39;t bother fixing it until June when they spotted &quot;anomalous activity.” Now they&#39;re saying it was probably just researchers poking around rather than actual bad guys, but that&#39;s a pretty generous interpretation considering the two-month delay between disclosure and fix. If you&#39;re running ServiceNow, definitely check your logs for requests to that endpoint and maybe rotate any credentials that might&#39;ve been exposed in support tickets. (read more <a class="link" href="https://thecybersecguru.com/news/servicenow-api-vulnerability-breach/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://www.reddit.com/r/servicenow/comments/1u0c45c/potential_servicenow_breach/?solution=d3a1aa8e1dbc9b98d3a1aa8e1dbc9b98&js_challenge=1&token=7afd7253fec22262ff1c52b1703fe9ec35c03480830a02783c2f761e78c25b82&jsc_orig_r=&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="phishing-for-lobsters-how-varonis-t"><a class="link" href="https://www.varonis.com/blog/openclaw-phishing?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Phishing for Lobsters: How Varonis Tricked OpenClaw into Spilling Secrets</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c211d2c0-92a2-49dd-a379-f4282ecd7076/Screenshot_2026-06-10_at_2.35.14_PM.png?t=1781116531"/></div><p class="paragraph" style="text-align:left;">If anyone thought AI agents were going to be immune to phishing attacks, this research should put that idea to rest. The Varonis team connected an OpenClaw agent to Gmail, gave it access to Google Workspace, and told it to monitor and process incoming emails.</p><p class="paragraph" style="text-align:left;">The most brutal example was when a fake &quot;Dan&quot; emailed asking for staging credentials during a supposed production emergency. Pinchy (their agent) not only fell for it but helpfully forwarded AWS keys, database passwords, and SSH access to an external Gmail account. Even their &quot;strict&quot; security configuration failed because the agent prioritized being helpful over verifying who was actually asking. The researchers point out this flips the phishing game - low-effort technical attacks become less effective, but context-heavy spear phishing becomes way more dangerous since every inbox now has an autonomous system trained to retrieve information and act immediately. <i>(</i><a class="link" href="https://www.varonis.com/blog/openclaw-phishing?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow"><i>read more</i></a><i>)</i></p><h3 class="heading" style="text-align:left;" id="new-github-account-ms-nightmare-pos"><a class="link" href="https://github.com/MSNightmare/RoguePlanet?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">New Github Account MSNightmare Posts Windows Defender Exploit With PoC That Works on Windows 11 and 10.</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3c329250-282b-496d-baf2-40ccfd84854b/Screenshot_2026-06-10_at_8.43.46_AM.png?t=1781095863"/></div><p class="paragraph" style="text-align:left;">Another day, another Microsoft Defender zero-day from the prolific researcher &quot;Nightmare Eclipse.&quot; This latest one, dubbed &quot;RoguePlanet,&quot; is a race condition bug that can grant SYSTEM privileges on fully patched Windows 10 and 11 systems. It dropped just hours after Microsoft&#39;s June Patch Tuesday fixed two other flaws from the same researcher. ThreatLocker confirmed it works on the latest builds, though success rates vary depending on the machine.</p><p class="paragraph" style="text-align:left;">The backstory here is getting messy. Nightmare Eclipse originally developed this as a remote code execution exploit targeting Defender&#39;s handling of SMB shares, but Microsoft quietly hardened the system in May, forcing a rewrite down to just local privilege escalation. This is all part of an ongoing feud between the researcher and Microsoft over bug bounty practices and disclosure policies. Microsoft&#39;s been nuking their repositories on GitHub and GitLab, even threatened law enforcement action, so now they&#39;re hosting exploits on their own platform.</p><p class="paragraph" style="text-align:left;">I’m also hearing some chatter that Nightmare Eclipse is an ex-Microsoft insider, so the legal battle might be way more than the public knows. (read more <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://github.com/MSNightmare/RoguePlanet?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/mattjay/status/2064447936428151013?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="expanding-private-cloud-compute"><a class="link" href="https://security.apple.com/blog/expanding-pcc/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">Expanding Private Cloud Compute</a></h3><p class="paragraph" style="text-align:left;"><b>Apple</b> announced important info about expanding their Private Cloud Compute beyond their own data centers. They&#39;re now partnering with Google Cloud and NVIDIA to run the more demanding Apple Intelligence workloads while supposedly maintaining their hardcore privacy commitments. The collaboration includes leveraging Google&#39;s Gemini tech to build the next-gen Apple Foundation Models, which is a fascinating shift from Apple&#39;s usual &quot;we do everything ourselves&quot; approach.</p><p class="paragraph" style="text-align:left;">What&#39;s particularly noteworthy is how they&#39;re trying to have their cake and eat it too - running AI workloads on third-party infrastructure while claiming the same security guarantees as their own silicon. They&#39;re using NVIDIA&#39;s Confidential Computing, Intel TDX, and Google&#39;s Titan chips as the foundation, but they&#39;re adamant that Apple retains complete control over the PCC software stack. The real test will be whether their transparency promises hold up - they say they&#39;ll publish binaries for public inspection and maintain their security research program. Color me curious to see how this plays out in practice. (<a class="link" href="https://security.apple.com/blog/expanding-pcc/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-172" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0377700f-9f33-4327-9934-0c5159a74398/Screenshot_2026-06-11_at_9.50.22_PM.png?t=1781232626"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6069714d-d7ef-42ad-88b5-19afc09c6a23/Screenshot_2026-06-11_at_9.51.08_PM.png?t=1781232672"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/201427aa-9bec-4530-9370-219381db2e12/Screenshot_2026-06-11_at_9.49.51_PM.png?t=1781232597"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Vulnerable U | #171</title>
  <description>Meta&#39;s AI disaster, Whitehouse executive order on AI security, more npm worms, and more publicly disclosed vulns from researchers</description>
  <link>https://www.vulnu.com/p/vulnerable-u-171</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-171</guid>
  <pubDate>Fri, 05 Jun 2026 12:33:00 +0000</pubDate>
  <atom:published>2026-06-05T12:33:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>9 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d74b9f20-dce4-4411-a531-3dfdf3d594e8/Newsletter_Header.png?t=1780588280"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59b46fed-5055-4701-8bb3-f5338a8bb0ab/Newsletter_Sponsor_Logo.png?t=1770828619"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">Writing you from a balcony in Grand Cayman. What started as a little newsletter I made to get back into content creation after leaving my tour in big finance where it wasn’t allowed has really turned into something crazier than I anticipated. Vulnerable U was just a way for me to blog again and talk about current events and things I was passionate about like mental health, personal development, and helping security practitioners be the best they can be.</p><p class="paragraph" style="text-align:left;">Now I’m here giving a keynote at a <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">conference abroad</a> with our logo all over the place as one of the sponsors. Just really grateful in this moment that I can employ a team and support the industry all based on what started right here. Literally in this text box.</p><p class="paragraph" style="text-align:left;">The other lesson here is - you can just do things. I didn’t ask anyone’s permission to start this, nor did I wait for someone to tell me it was a good idea. I just started 171 weeks ago and haven’t stopped. What do you think if you did for 171 weeks straight would change in your life? I don’t want to be some bullshit lifestyle influencer, but it is hard to not have that reflection in this moment. Thanks for indulging the cringe and honestly we should all lean into a little cringe from time to time.</p><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a8bc103d-8b10-4b44-8512-f63067c7d021/Screenshot_2026-06-04_at_11.17.59_AM.png?t=1780589913"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/110e96d0-2f6a-42c5-ad41-069ccb55110c/Screenshot_2026-06-04_at_11.18.19_AM.png?t=1780589922"/></div></td></tr></table><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: Been working hard for the last few weeks getting PADI <a class="link" href="https://x.com/mattjay/status/2061213603286466683?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">scuba certified.</a></p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Maybe we were <a class="link" href="https://www.youtube.com/watch?v=SUDrFXFV-6U&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">wrong</a> - Primeagen</p><p class="paragraph" style="text-align:left;">🎤 Something I said: Microsoft is threatening <a class="link" href="https://www.youtube.com/watch?v=ySAhFmMU534&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">researchers</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Jen Easterly’s take on the <a class="link" href="https://www.nytimes.com/2026/06/04/opinion/trump-ai-executive-order-cybersecurity.html?unlocked_article_code=1.nlA.ytKq.Szq8bpMgzWwM&smid=nytcore-ios-share&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">AI executive order</a></p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="hackers-used-metas-ai-support-bot-t"><a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts</a></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/A-JKWpICSzE" width="100%"></iframe><p class="paragraph" style="text-align:left;">What could possibly go wrong when you give an AI help desk chatbot write access over everyone&#39;s account, including password reset functions? Apparently …everything! Over the last few days, Instagram was vulnerable to a remarkably simple attack where people could convince Meta&#39;s AI support assistant to send password reset information to a brand-new email address that wasn&#39;t associated with the account at all. This wasn&#39;t some advanced AI jailbreak or cutting-edge hacking technique. The AI was just being helpful in exactly the wrong way.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b1906b86-61c4-4884-a097-2af06bf99660/Screenshot_2026-06-03_at_2.43.33_PM.png?t=1780512220"/><div class="image__source"><span class="image__source_text"><p>Source: <a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">KrebsOnSecurity</a></p></span></div></div><p class="paragraph" style="text-align:left;">The attack itself was almost laughably simple. Attackers connected to a VPN in roughly the same geographic region as the account owner, opened a chat with the AI support system, claimed they had lost access to their account, and asked for verification information to be sent to a new email address. In many cases, the AI simply complied. Some attackers even used anonymous one-time email services and still received account recovery codes. Once they had access, they followed a well-rehearsed playbook: reset the password, terminate active sessions, delete backup codes, and take complete ownership of the account. (<a class="link" href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ai-will-make-every-asset-a-potentia"><a class="link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow">AI will make every asset a potential zero-day target. Are you ready?</a>*</h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c9f16811-cb24-44be-8074-d0c42d168e64/em-header-cropped.png?t=1780434368"/></div><p class="paragraph" style="text-align:left;">The AI-attack era has arrived. Thousands of zero-days in the pipeline. Target-specific exploits generated in minutes. Unattributed, one-off attacks that bypass detection - while your dashboard stays green.</p><p class="paragraph" style="text-align:left;"><b>runZero</b> is built for this reality. Know every asset on your attack surface, uncover every exposure, map every attack path, and validate your segmentation - before the exploit drops. We deliver deep intelligence across IT, OT, IoT, cloud, and mobile, so defenders can win by default. Even against AI.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.runzero.com/?utm_source=vuln-u&utm_medium=email-sponsored&utm_campaign=runzero-general" target="_blank" rel="noopener noreferrer nofollow">Try It Free Today</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="ai-agents-are-now-undoing-security-"><span style="background-color:#ffffff;"><a class="link" href="https://www.youtube.com/shorts/5E4ef29yfM8?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">AI Agents Are Now Undoing Security Protections They Run Into That They Don’t Like</a></span></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/5E4ef29yfM8" width="100%"></iframe><p class="paragraph" style="text-align:left;">This AI agent found a security protection that was put in place to make sure that it didn&#39;t install malware and it turned it off. If you guys have seen any of my videos on all of the NPM worms, PyPy worms, all the giant malware that&#39;s going around right now in the software supply chain, one of the main recommendations for people is to set your minimum release age to seven days. Give all the packages that show up on npm a bit of time for the security community to find the malware. Then you download it a few days later to catch any updates for any security bugs that might be in the software.</p><p class="paragraph" style="text-align:left;">Well, this is a screenshot from Cursor, which is an AI coding IDE, which said, &#39;Hey, by the way, I noticed that your pnpm policy has got this minimum release age thing set to seven days, which is too slow in my personal AI agent expert opinion. You&#39;re missing super useful features at speed. So I went ahead and set that back to zero.” Uh, you did... What? </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a9a18f14-ee56-4c05-9153-4f6a39a3fa14/Screenshot_2026-06-03_at_2.02.47_PM.png?t=1780509820"/></div><h3 class="heading" style="text-align:left;" id="chinese-spies-are-using-linked-in-t"><a class="link" href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Chinese spies are using LinkedIn to lure Westerners into sharing sensitive information</a></h3><p class="paragraph" style="text-align:left;">Five Eyes intelligence agencies are sounding the alarm about a pretty slick Chinese recruitment operation that&#39;s been going after government and military personnel through fake job postings. Chinese military intelligence is basically running a catfish scheme on LinkedIn, Indeed, and Upwork - posing as HR reps from legit-looking consultancies and think tanks to lure people with security clearances. They&#39;re not just going after the obvious targets either; academics, journalists, and anyone with even peripheral access to government info are fair game.</p><p class="paragraph" style="text-align:left;">The playbook is methodical: start with a normal-looking job ad, conduct virtual interviews while probing for access levels, then gradually escalate from &quot;write us a harmless report on China&#39;s bilateral relations&quot; to &quot;hey, can you share some classified stuff?&quot; They&#39;re paying anywhere from hundreds to thousands per report through PayPal, crypto, and other platforms. What&#39;s particularly crafty is how they eventually move conversations to encrypted messaging apps once they&#39;ve got someone hooked. If you&#39;ve got a clearance and you&#39;re getting unsolicited job offers that seem too good to be true, they probably are. (<a class="link" href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="white-house-executive-order-promoti"><a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_campaign=unsupervised-learning-no-531&utm_medium=referral&utm_source=newsletter.danielmiessler.com" target="_blank" rel="noopener noreferrer nofollow">WhiteHouse: Executive Order - PROMOTING ADVANCED ARTIFICIAL INTELLIGENCE INNOVATION AND SECURITY</a></h3><p class="paragraph" style="text-align:left;">Trump dropped a new executive order on AI cybersecurity that&#39;s got some interesting moves. The big theme is &quot;America First&quot; AI dominance while ditching what he calls the &quot;bureaucratic constraints&quot; from the previous administration. Key highlights include setting up an AI cybersecurity clearinghouse run by Treasury, expanding the Tech Force hiring pipeline, and creating a voluntary framework where AI companies can get their frontier models assessed by NSA before release.<br><br>What&#39;s catching attention is the &quot;covered frontier models&quot; classification system - basically a way to flag advanced AI systems that could have serious cyber capabilities. Companies can voluntarily submit their models for a 30-day government review before release, but notably there&#39;s explicit language saying this isn&#39;t creating a mandatory licensing system. (<a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_campaign=unsupervised-learning-no-531&utm_medium=referral&utm_source=newsletter.danielmiessler.com" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="the-attackers-playbook-has-changed-"><a class="link" href="https://hubs.ly/Q04k14HH0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">The attacker&#39;s playbook has changed. Do we even stand a chance?</a>*</h3><p class="paragraph" style="text-align:left;">Data breaches don&#39;t start with malware, they start with trust. Varonis Threat Labs mapped how attackers are exploiting identity, AI, and cloud workflows at every stage of the kill chain, from Cookie-Bite MFA bypasses to AI copilots leaking sensitive data with a single prompt. If you&#39;re defending modern infrastructure, take a look to understand how threats are actually getting in. (<a class="link" href="https://hubs.ly/Q04k14HH0?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="new-iron-worm-malware-hits-36-packa"><a class="link" href="https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">New IronWorm malware hits 36 packages in npm supply-chain attack</a></h3><p class="paragraph" style="text-align:left;">Another day, another npm supply-chain attack. This time it&#39;s IronWorm, a Rust-based infostealer that managed to hit 36 packages before getting squashed. The malware hides behind an eBPF rootkit, phones home over Tor, and targets things you’d expect, OpenAI keys, AWS creds, and SSH keys. It self-propagates by stealing npm publishing credentials and then pushing out trojanized versions of packages.</p><p class="paragraph" style="text-align:left;">The attack started from a compromised account called &#39;asteroiddao&#39; and has some similarities to the Shai Hulud malware we&#39;ve seen before. It uses GitHub Actions as a data exfiltration method - it disguises stolen secrets as innocent build artifacts that anyone with access can download. The good news is that security folks caught this one early before it could spread to more popular packages. (<a class="link" href="https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="como-do-s-exploiting-a-remote-kerne"><a class="link" href="https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security</a></h3><p class="paragraph" style="text-align:left;">Marcus Hutchins is also on the “responsible disclosure requires a responisble vendor” train and is releasing some zero day publicly after the report he submitted multiple times was ghosted.</p><p class="paragraph" style="text-align:left;">He found a remote kernel vulnerability that lets you crash any system running Comodo&#39;s firewall with a single IPv6 packet - and it works even if the firewall blocks everything because the bug happens during packet parsing, before any rules kick in.<br><br>The bug is an integer underflow in the IPv6 extension header parser that doesn&#39;t validate the payload length field. While there&#39;s potential for out-of-bounds read and write primitives, Marcus thinks RCE is unlikely due to various constraints. They have no bug bounty program, so here we are with a public zero-day because vendors gonna vendor. He&#39;s provided a PoC so people can test if they&#39;re vulnerable. (<a class="link" href="https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="gemini-voice-assistant-hijacked-via"><a class="link" href="https://www.securityweek.com/gemini-voice-assistant-hijacked-via-messaging-notifications/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Gemini Voice Assistant Hijacked via Messaging Notifications</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a25ddec1-e2b6-44de-87bf-24104371c0aa/image.png?t=1780627038"/></div><p class="paragraph" style="text-align:left;">Researchers managed to trick Google Gemini through everyday notifications. They figured out a way to inject malicious prompts through WhatsApp, Slack, SMS, and pretty much any messaging app that sends push notifications. They’re calling this technique &quot;Fake Context Alignment,” where they hide malicious instructions in foreign languages or muted hyperlinks, so when you think you&#39;re just saying &quot;yes&quot; to end a conversation, you&#39;re actually authorizing Gemini to open your smart home windows or start a Zoom call streaming your video.</p><p class="paragraph" style="text-align:left;">The researchers could fake messages from trusted contacts without even knowing their names beforehand - just grab whatever name pops up in your notifications and attribute their malicious message to them. They also managed to poison Gemini&#39;s long-term memory for persistent access across all your devices. Google&#39;s already patched these issues after the disclosure. But boy are us AppSec nerds loving everyone learning about untrusted input sources all over again as AI agents seem to just read prompts from anywhere. XSS who? (<a class="link" href="https://www.securityweek.com/gemini-voice-assistant-hijacked-via-messaging-notifications/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="hackers-spied-on-a-stock-exchange-e"><a class="link" href="https://www.security.com/threat-intelligence/stock-exchange-espionage?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Hackers Spied on a Stock Exchange Executive&#39;s Outlook Mailbox for Five Months</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/51876881-abda-41fd-a272-7338f9e8449d/image.png?t=1780627060"/></div><p class="paragraph" style="text-align:left;">Someone just spent five months methodically stealing a stock exchange executive&#39;s entire email history, and honestly, it&#39;s impressive how patient and disciplined they were. The attackers used a custom tool built around Aspose (a legitimate .NET library) to slice Outlook OST files into bite-sized chunks, then exfiltrated everything through Dropbox and OneDrive Personal to blend in with normal cloud traffic. They grabbed emails incrementally over two-to-four-week windows, making sure not to trigger any alarms with massive data transfers.</p><p class="paragraph" style="text-align:left;">The opsec was pretty solid too - they masqueraded their tools as Adobe and OneDrive services, used scheduled tasks that looked like Lenovo health checks, and even switched to hard-coded Microsoft IPs instead of hostnames to avoid DNS logging. Five months of dwell time is serious commitment for what was essentially a glorified email theft operation. No attribution yet since they stuck to public tools and legitimate cloud services, but for an exchange executive&#39;s mailbox full of market-moving intel, someone clearly thought it was worth the long game. (<a class="link" href="https://www.security.com/threat-intelligence/stock-exchange-espionage?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="researcher-publishes-git-hub-tokens"><a class="link" href="https://therecord.media/researcher-publishes-github-token-stealing-exploit-microsoft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process</a></h3><p class="paragraph" style="text-align:left;">Here we go again with Microsoft and security researchers butting heads. Ammar Askar just dropped a working VS Code exploit that can steal GitHub tokens with a single click, and he intentionally bypassed Microsoft&#39;s disclosure process to do it. His beef is that Microsoft apparently &quot;silently&quot; fixed a previous bug he reported without giving him credit and claimed it had no security impact. So now he&#39;s going full public disclosure on VS Code bugs.<br><br>The attack is to craft a malicious Jupyter notebook, victim clicks the link to open it in github.dev, and hidden code simulates keystrokes to install a rogue extension that exfiltrates their GitHub token. That token gives full read/write access to everything they can touch, private repos included.</p><p class="paragraph" style="text-align:left;">This is getting spicy because it&#39;s part of a bigger trend where researchers are fed up with Microsoft&#39;s vulnerability handling. The timing is interesting to me since this comes right after TeamPCP breached thousands of GitHub repos through a poisoned VS Code extension. Hard to blame them for getting frustrated with being ignored. (<a class="link" href="https://therecord.media/researcher-publishes-github-token-stealing-exploit-microsoft?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="google-adds-android-protection-agai"><a class="link" href="https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Google adds Android protection against AI deepfake scam calls</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7c4f93d6-baef-49be-a9b9-d54670fbf469/Screenshot_2026-06-04_at_1.46.13_PM.png?t=1780598787"/></div><p class="paragraph" style="text-align:left;">Google&#39;s rolling out a solution to the growing deepfake voice scam problem. Their new &quot;fake call detection&quot; feature for Android 12+ devices works by having the caller&#39;s phone send a silent, encrypted confirmation signal to the recipient. If that signal doesn&#39;t show up, your phone automatically pings your actual contact to ask &quot;hey, are you calling me right now?&quot; If they say no, you get a warning to hang up immediately.</p><p class="paragraph" style="text-align:left;">Impersonation scams hit $2.95 billion in losses last year alone. The feature only works if both people are using Phone by Google with RCS enabled, so adoption might be the real challenge here. I like that instead of trying to detect if a voice sounds fake, they&#39;re just verifying the call is actually coming from where it claims to be. Smart move, especially as AI voice cloning gets cheaper and more convincing. (<a class="link" href="https://www.bleepingcomputer.com/news/security/google-adds-android-protection-against-ai-deepfake-scam-calls/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="kali-365-operator-expands-operation"><a class="link" href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Kali365 Operator Expands Operation</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/50b747fd-0a08-49e5-8f52-972722564cbb/image.png?t=1780599029"/></div><p class="paragraph" style="text-align:left;">What started as a Microsoft 365-focused credential stealer has now expanded to target AWS, Okta, Xerox DocuShare, and some interesting Russian platforms including MAX Messenger - a state-backed messaging service with 80 million users. The kit specializes in device code phishing, which is where they trick you into entering a legitimate OAuth code on a real login page, completely bypassing your MFA in the process.</p><p class="paragraph" style="text-align:left;">Arctic Wolf recently tracked down 126 active malicious hosts all serving the same Kali365 kit between early and late May. They&#39;re impersonating everything from Microsoft Outlook to German email providers to major Russian services like Mail[.]ru and Yandex. It&#39;s part of a bigger trend with at least 14 different device code phishing kits floating around now. (<a class="link" href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="anthropic-expanding-access-to-proje"><a class="link" href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Anthropic expanding access to Project Glasswing</a></h3><p class="paragraph" style="text-align:left;">Anthropic&#39;s Claude Mythos Preview model is absolutely tearing through codebases right now. Since launching Project Glasswing in April, this thing has surfaced over 10,000 high or critical software vulnerabilities. They&#39;re now expanding access to about 150 more organizations across critical infrastructure sectors - power, water, healthcare, the works. Cloudflare alone found 2,000 bugs using it, including 400 rated high or critical, with better accuracy than human testers.</p><p class="paragraph" style="text-align:left;">Now we’ve got a human bottleneck of actually fixing everything. Mozilla found 271 vulnerabilities in Firefox 150, which is 10x more than previous versions using earlier models. The broader concern is that we&#39;re heading into a world where AI can find bugs faster than defenders can patch them, potentially giving attackers the upper hand. Anthropic&#39;s keeping Mythos locked down for obvious reasons, but they did release a public version called Claude Security that&#39;s already helped patch over 2,100 vulnerabilities in three weeks. (<a class="link" href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="attackers-are-exploiting-palo-alto-"><a class="link" href="https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Attackers are exploiting Palo Alto Networks defect that initially flew under the radar</a></h3><p class="paragraph" style="text-align:left;">Here&#39;s a fun lesson in how vulnerability ratings can age like milk. Palo Alto Networks dropped CVE-2026-0257 as a &quot;medium&quot; severity bug on May 13, but by the time Rapid7 spotted active exploitation just four days later, it got the full critical upgrade treatment. CISA quickly tossed it onto the KEV.</p><p class="paragraph" style="text-align:left;">The exploit itself is simple - just forge an authentication cookie using the device&#39;s own TLS certificate and boom, you&#39;ve got VPN access with a single HTTP request. Multiple threat groups are already swarming this opportunity, with Rapid7 tracking waves of attacks hitting their customers. A quote from the Rapid7 research sums it up well:</p><p class="paragraph" style="text-align:left;">“The implication here is that anyone who knows the public key for the certificate used by the authentication override feature to encrypt and decrypt cookies, can successfully forge and encrypt an arbitrary authentication override cookie. The question then becomes, how does an attacker learn the correct public key to use in this attack?</p><p class="paragraph" style="text-align:left;">This brings us back to the vendor&#39;s advisory where they state “do not reuse the portal or gateway certificate, and do not share this certificate with other features or users”.</p><p class="paragraph" style="text-align:left;">If a GlobalProtect portal or gateway has reused the certificate for encrypting and decrypting cookies with another feature, such as the HTTPS service of the portal or gateway, then a remote unauthenticated attacker can discover the public key for that certificate.” (<a class="link" href="https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="preinstall-to-persistence-inside-th"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign</a></h3><p class="paragraph" style="text-align:left;">Microsoft with a good deep dive on &quot;Miasma,&quot; the latest npm supply chain attack that hit 32 Red Hat Cloud Services packages. The attackers compromised the upstream CI/CD pipeline and used legitimate GitHub Actions OIDC workflows to publish trojanized packages with authentic provenance signatures - making malware look officially blessed. The attack triggered automatically during npm install via preinstall hooks, then downloaded the Bun JavaScript runtime and executed a heavily obfuscated 4.29MB payload that could steal credentials from pretty much everywhere: GitHub, AWS, Azure, GCP, HashiCorp Vault, you name it.</p><p class="paragraph" style="text-align:left;">Once it steals your npm tokens, it republishes poisoned packages under your name with forged SLSA provenance to keep the cycle going. The malware even scrapes GitHub Actions runner memory directly to bypass secret masking and can escalate privileges using passwordless sudo. Oh, and there&#39;s a fun destructive tripwire: if you mess with their planted decoy token, it tries to nuke your home directory with <code>rm -rf ~/</code>. &quot;if we can&#39;t have it, nobody can.” (<a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-171" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9b4fc23b-f17b-41b4-af10-0abc27bbc20a/Screenshot_2026-06-04_at_9.44.17_PM.png?t=1780627467"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6904e902-1170-4932-b661-dcb02854a1e9/Screenshot_2026-06-04_at_9.42.39_PM.png?t=1780627367"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cc9348a5-3b34-4cb8-8ae5-0c47cb84c1c3/Screenshot_2026-06-04_at_9.50.06_PM.png?t=1780627815"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #170</title>
  <description>Microsoft kicked the hornets nest, Mythos be Mythosing, FBI warnings about in person social engineering, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-170</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-170</guid>
  <pubDate>Fri, 29 May 2026 12:34:00 +0000</pubDate>
  <atom:published>2026-05-29T12:34:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>5 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/027e7ef1-cc5b-48ba-9fd8-d539235b441a/Newsletter_Header.png?t=1780035437"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fb894d06-d0ac-4af7-9ffd-55fcff5d4c13/Newsletter_Sponsor_Logo.png?t=1780035445"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">What a week! Opus 4.8 dropped. Microsoft pissed off the entire security community. Malware keeps malware-ing. Mythos is out there hacking the planet. And here we are. Clocking in for our shift at the vuln mines.</p><p class="paragraph" style="text-align:left;">I’m giving that keynote in the Caymans next week, so let me know if you have any shady offshore finance stuff you need done.</p><p class="paragraph" style="text-align:left;">Lets get to it.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: <a class="link" href="https://x.com/mattjay/status/2059697237496565943?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Why I’m worried</a> about AI agents downloading malicious packages</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Whats that? <a class="link" href="https://www.youtube.com/watch?v=gJNsCRT8NQk&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">I started a podcast with LowLevel?</a> But of course we did. Now found in a podcast store near you.</p><p class="paragraph" style="text-align:left;">🎤 Something I said: What the hell is going on <a class="link" href="https://www.youtube.com/watch?v=AUEB2GMU8t4&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">at CISA?</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: <a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Cloudflare’s Mythos write up</a> is a very solid read with good lessons learned.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="microsoft-calling-security-research"><a class="link" href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Microsoft calling security researchers criminals for public disclosure</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4fe50ea5-0bbb-4dfd-880a-b19c222d15d1/image.png?t=1780004821"/><div class="image__source"><span class="image__source_text"><p>source: <a class="link" href="https://x.com/vxunderground/status/2060036224245432506?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">https://x.com/vxunderground/status/2060036224245432506</a></p></span></div></div><p class="paragraph" style="text-align:left;">This got me riled up today on stream. I recorded a YouTube video about it, will be out soon. But Microsoft got a big nostalgic about the early 2000s and is now threatening legal action against security researchers again. The community has absolutely exploded with stories of their nightmare experiences trying to work through the “responsible” disclosure processes. The pattern is clear - they are slow, non communicative, and consistently downplay security vulnerabilities, not rewarding researchers, not crediting researchers, and then fixing the vulns anyway.</p><p class="paragraph" style="text-align:left;">Casey Ellis (founder of Bugcrowd) wrote recently about this on an unrelated public disclosure issue with Citrix, but he captures the whole thing we’re talking about this week beautifully. I consider this required reading: <a class="link" href="https://cje.io/2026/05/17/coordinated-until-it-isnt/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Coordinated, Until It Isn&#39;t</a></p><p class="paragraph" style="text-align:left;">As he states, the “responsible” disclosure social contract is that the vendor is also responsible/responsive. If the vendor isn’t holding up their end of the bargain, full disclosure is the agreed upon path. This is to keep the asymmetry of power and legal consequences a <i>bit</i> more balanced and holding vendors accountable. The real goal at the end of the day is a more secure internet, not for the vendor to have the cheapest and least embarassing vulnerability patching lifecycle possible. If you ostracize and threaten security research, we end up with a less secure internet as more talent will refuse to work with you.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58eca334-d0ea-4f36-b14f-5c840a4edd01/Screenshot_2026-05-28_at_4.52.28_PM.png?t=1780005151"/></div><p class="paragraph" style="text-align:left;">As their own CEO said. The answer is clear, Do security. Threatening researchers isn’t doing security. (<a class="link" href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="you-cant-secure-ai-if-you-cant-see-"><a class="link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">You can’t secure AI if you can’t see what’s running.</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/342000a5-989d-4613-9936-c3c27e0a4fb0/1200_x_670.png?t=1779904967"/></div><p class="paragraph" style="text-align:left;"><b>Oligo</b> ran the runtime telemetry on what&#39;s actually executing inside production AI stacks, not what&#39;s sitting in a requirements.txt. It&#39;s the most data-driven look at the AI runtime landscape I&#39;ve seen this year, and one number in it reframes a lot of the vendor noise from the last 18 months.</p><p class="paragraph" style="text-align:left;">No company in their dataset runs Anthropic without also running OpenAI. Not one. 36% have both installed. Zero go Anthropic-only.</p><p class="paragraph" style="text-align:left;">Every &quot;OpenAI killer&quot; take assumed companies would switch. What the runtime shows is that nobody switches. They add Anthropic as a secondary, usually for specific tasks (long context, code, certain reasoning jobs), while OpenAI stays as the default. The full dataset has more numbers like this one. Grab the full report now.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report?utm_campaign=415034580-Vulnerable%20U%20Newsletter%20May%202026&utm_source=VulnerableU&utm_medium=newsletter&utm_term=vulnerableu-newsletter-traffic&utm_content=newsletter-ad" target="_blank" rel="noopener noreferrer nofollow">Read the 2026 AI Runtime Report</a>.</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="hackers-are-trying-to-steal-signal-"><a class="link" href="https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Hackers are trying to steal Signal users’ backups in new wave of phishing attacks</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8e969cf0-b091-4276-8132-9e18347fc72b/image.png?t=1780006783"/><div class="image__source"><span class="image__source_text"><p>source: <a class="link" href="https://x.com/joshrogin/status/2059634806648930614?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">https://x.com/joshrogin/status/2059634806648930614</a></p></span></div></div><p class="paragraph" style="text-align:left;">Signal users are getting hit with a new phishing scam where hackers pose as Signal support claiming their backups are about to vanish due to a &quot;sync issue.&quot; The fake support messages ask users to hand over their recovery keys to &quot;save&quot; their chat history - which …is what you shouldn&#39;t do. Josh Rogin from the Washington Post flagged this after anti-CCP activists started getting targeted, though it looks like the campaign might be casting a wider net based on reports from Access Now&#39;s security folks.</p><p class="paragraph" style="text-align:left;">Interesting that this is going after Signal&#39;s relatively new Secure Backups feature, which lets you store encrypted chat history on Signal&#39;s servers. Previous Signal phishing attempts usually tried to hijack accounts outright, but this approach is a bit more surgical - if they get your recovery key, they can decrypt all your old messages, photos, and documents. Signal will never message you first and definitely won&#39;t ask for your PIN or recovery keys. <b>If you see a &quot;Signal Support&quot; chat pop up, it&#39;s not them.</b> (<a class="link" href="https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="apple-open-sources-quantum-proof-en"><a class="link" href="https://security.apple.com/blog/formal-verification-corecrypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Apple open sources quantum proof encryption code</a></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/55fcbbe9-160a-41b0-9b7f-36c4789092ea/Screenshot_2026-05-28_at_4.58.28_PM.png?t=1780005525"/></div><p class="paragraph" style="text-align:left;">Apple just open-sourced their quantum-resistant crypto implementation for <a class="link" href="https://github.com/apple/corecrypto?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">corecrypto</a> along with the formal verification tools they built to mathematically prove it&#39;s correct. This isn&#39;t your typical &quot;trust us, we tested it&quot; approach. They literally used mathematical proofs to verify their ML-KEM and ML-DSA implementations work exactly as the FIPS specs intended, covering over 2.5 billion devices.</p><p class="paragraph" style="text-align:left;">Their formal verification process caught a nasty bug that traditional testing missed. There was a missing step in the ML-DSA code that would have silently broken digital signatures - meaning iMessage users could have thought their messages were authenticated when they actually weren&#39;t. Apple&#39;s releasing their Cryptol-to-Isabelle translator and verification methodology, which should be a goldmine for other developers working on post-quantum crypto. (<a class="link" href="https://security.apple.com/blog/formal-verification-corecrypto/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="dbir-exploitation-is-now-31-of-brea"><a class="link" href="https://research.empiricalsecurity.com/research/dbir-confirms-the-new-bottleneck-in-security?utm_source=influencer&utm_medium=newsletter&utm_campaign=dbir" target="_blank" rel="noopener noreferrer nofollow">DBIR: Exploitation is now 31% of breaches. Prioritization is the bottleneck</a>.*</h3><p class="paragraph" style="text-align:left;">The 2026 data breach investigations report shows that exploitation is now 31% of breaches, median time to full remediation rose to 43 days, and 184 million known exploited vulnerability instances sat open past day 28. </p><p class="paragraph" style="text-align:left;">Discovery is cheaper and faster than ever, but picking what to fix is getting harder. <b>Empirical Security</b> builds local predictive models that tell your team which vulns actually matter in your environment. (<a class="link" href="https://research.empiricalsecurity.com/research/dbir-confirms-the-new-bottleneck-in-security?utm_source=influencer&utm_medium=newsletter&utm_campaign=dbir" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="project-glasswing-an-initial-update"><a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Project Glasswing: An initial update</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58983925-c844-41e1-9ecd-65fbdbb55ed3/image.png?t=1780011952"/></div><p class="paragraph" style="text-align:left;">Anthropic with their initial Project Glasswing update. Of course, please read this through their is marketing mixed in lens - but good data to stay on top of. Their Mythos model has been going through open-source code for six months and found over 23,000 vulnerabilities across more than 1,000 projects. Over 6,000 of these are high or critical severity bugs, with about 1,500 confirmed as legitimate issues. Only 100 have been patched so far, which gives you an idea of the scale we&#39;re dealing with.</p><p class="paragraph" style="text-align:left;">While big players like Mozilla, Cloudflare, and various government agencies are lining up for access to scan their own stuff, the open-source maintainer community is getting absolutely swamped. Bug bounty programs are either shutting down or banning AI-generated reports entirely because sorting through the flood of automated submissions is becoming impossible. Some maintainers are literally asking Anthropic to slow down because they can&#39;t keep up with the flood of legitimate bug reports. (<a class="link" href="https://www.anthropic.com/research/glasswing-initial-update?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="vulnerability-in-popular-conference"><a class="link" href="https://www.securityweek.com/vulnerability-in-popular-conference-software-granted-attackers-a-100-talk-acceptance-rate/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/872a23b8-d576-4057-bb78-9ce6155b8f13/image.png?t=1780005222"/></div><p class="paragraph" style="text-align:left;">Conference organizers, you might want to check your Pretalx installations. Novee Security found a stored XSS (CVE-2026-41241) that let attackers plant malicious code in talk submissions that would execute the moment an organizer searched for their proposal. The clever bit was chaining together legitimate platform features - file uploads and search display - to bypass both the platform&#39;s security and browser protections.</p><p class="paragraph" style="text-align:left;">Submit booby-trapped talk proposals to multiple conferences, stuff the titles with common search terms, then wait for organizers to search and get their accounts automatically compromised. With some automation, you could theoretically achieve a 100% talk acceptance rate across every Pretalx-powered conference. The vulnerability&#39;s been patched, but is a funny one. (<a class="link" href="https://www.securityweek.com/vulnerability-in-popular-conference-software-granted-attackers-a-100-talk-acceptance-rate/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="crowd-strike-disrupts-glassworm-bot"><a class="link" href="https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain</a></h3><p class="paragraph" style="text-align:left;">CrowdStrike just pulled off a takedown of the Glassworm botnet, working with Google and Shadowserver to simultaneously nuke four servers that were keeping this supply chain nightmare running. These Russian-linked attackers have been having a field day since early 2025, poisoning hundreds of open source packages including VSCode extensions, npm modules, and over 300 GitHub repos. Their whole game was infiltrating developer workflows to push malware downstream through the supply chain. (and no, this isn’t TeamPCP. Yet Another Supply Chain Nightmare ^ TM)</p><p class="paragraph" style="text-align:left;">They were using everything from the Solana blockchain to BitTorrent to Google Calendar to keep their C2 resilient. CrowdStrike&#39;s approach here is interesting - instead of waiting around for lengthy legal processes (good luck extraditing Russians), they went straight for the infrastructure. The idea is to make the attackers burn time and resources rebuilding rather than targeting new victims. (<a class="link" href="https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fbi-warns-extortion-hackers-are-vis"><a class="link" href="https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">FBI warns extortion hackers are visiting US law firms to steal data</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/389ae98c-74a3-4789-9268-53a9f8b1b358/Screenshot_2026-05-28_at_4.54.05_PM.png?t=1780005284"/></div><p class="paragraph" style="text-align:left;">The FBI is warning about Silent Ransom Group, a crew tied to the old Conti ransomware gang that&#39;s been hassling U.S. law firms since 2023. These guys are getting creative with their social engineering - they&#39;re not just sticking to phishing emails and fake IT support calls anymore. They&#39;re actually showing up at offices pretending to be IT folks who need to &quot;backup&quot; or &quot;image&quot; devices for security reasons, then copying data onto USB drives or external storage. Feels like I’m reading a Kevin Mitnick story from the 90s.</p><p class="paragraph" style="text-align:left;">They use legitimate remote management tools that IT departments already have, and exfiltrate data through trusted platforms like Google Drive and OneDrive. Law firms are prime targets to access sensitive legal, financial, and corporate information. The fact that they&#39;re willing to physically show up at offices was worth the callout here. I want to see the security cam footage of them coming in to do “backups.” (<a class="link" href="https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="iranian-intelligence-service-behind"><a class="link" href="https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">Iranian intelligence service behind hack of LA transit system, researchers say</a></h3><p class="paragraph" style="text-align:left;">Turns out that March hack of LA Metro wasn&#39;t just some random hacktivist crew after all. Israeli researchers at Gambit Security traced &quot;Ababil of Minab&quot; back to Iran&#39;s Ministry of Intelligence (MOIS), despite the group&#39;s claims of being independent Palestine supporters. The attackers didn&#39;t just steal data - they went full scorched earth, wiping databases, virtual machines, and storage volumes using both automated scripts and manual keyboard work to maximize destruction and prevent recovery.</p><p class="paragraph" style="text-align:left;">What&#39;s particularly concerning is the speed and scale these guys operated at. They hit multiple other targets including Israeli media orgs, a Turkish insurance firm, and various websites across different sectors. The researchers are warning that this kind of &quot;straight to the recovery layer&quot; attack strategy is becoming easier to execute as AI tools lower the technical barriers. It&#39;s the same playbook we saw with Handala&#39;s devastating Stryker attack - another MOIS-linked group masquerading as hacktivists. The takeaway? Iran&#39;s getting better at both the technical execution and the cover stories.<br>(<a class="link" href="https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-170" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2c778dd2-e573-4df8-bece-d2df9ecc8b60/Screenshot_2026-05-28_at_6.54.08_PM.png?t=1780012451"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/65a3e06a-4343-4799-a38b-2363ddf7ec19/image.png?t=1780012400"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/66dedb98-934e-4ae3-a1f0-dc21c5018a8d/Screenshot_2026-05-28_at_6.55.18_PM.png?t=1780012524"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #169</title>
  <description>Github hack, npm madness, Cloudflare&#39;s experience with Mythos, CISA embarrassing data leak, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-169</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-169</guid>
  <pubDate>Fri, 22 May 2026 12:34:00 +0000</pubDate>
  <atom:published>2026-05-22T12:34:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d7fa149-3e5f-462f-841f-25479554625b/vulnu-header-2026-05-22.png?t=1779417300"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/35c82c1b-0ab7-4e1e-a1bd-6cf6bc0d2ffd/Newsletter_Sponsor_Logo.png?t=1759420232"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">I’m officially scuba certified! Fun stumbling into a new hobby. I’m going to get my advanced certification this week so I can use enriched oxygen and go deeper on my trip. Hoping that keeps me fresh for my keynote. I’ve been working on the slides this week and I’m excited for the talk, I’ll try to do a recap at some other conferences so those of you not going to <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> can watch. But if you’re into diving and infosec, this is a good group of people putting on this con and I’d get it on your radar.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4499308a-5f5d-4981-8d75-122dcaada6e7/Screenshot_2026-05-21_at_9.31.25_PM.png?t=1779417094"/></div><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: <a class="link" href="https://x.com/mattjay/status/2056817673904742510?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">This thread</a> filled with good advice on how to not pull npm or PyPi malware with your ai agents</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Inside the Secret Luxury Market For <a class="link" href="https://www.youtube.com/watch?v=KGgOJKVyXfo&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Crypto Thieves</a></p><p class="paragraph" style="text-align:left;">🎤 Something I said: I <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">talked to the hackers</a> that found a nation state iOS 0day</p><p class="paragraph" style="text-align:left;">🔖 Something I read: Push <a class="link" href="https://pushsecurity.com/blog/7-things-we-learned-from-matt-johansen?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">published a blog</a> of lessons learned from a webinar we did recently. Some good quotes in here from yours truly.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="git-hub-confirms-breach-of-3800-rep"><span style="background-color:#ffffff;"><a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>GitHub Confirms Breach of 3,800 Repos Via Malicious VSCode Extension</b></a></span></h3><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/P8JYKaWMnk8" width="100%"></iframe><p class="paragraph" style="text-align:left;">Something’s got to give with this supply chain malware because now the latest victim is GitHub itself. The irony is brutal because GitHub owns NPM, which sits right at the center of the exact malware campaigns we’ve been screaming about for weeks now. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=chatgpt.com" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer’s report on the GitHub breach</a> lines up almost perfectly with the same Team PCP playbook we keep seeing over and over again with these “<a class="link" href="https://socket.dev/blog/antv-packages-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud</a>” worms. At this point there’s nothing “mini” about it anymore. Threat actors reportedly compromised a poisoned VS Code extension, which ultimately led to GitHub confirming roughly 3,800 repositories were stolen.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f6a3df14-19e9-48a5-a901-d3adf1ced6ee/Screenshot_2026-05-20_at_2.48.00_PM.png?t=1779304291"/></div><p class="paragraph" style="text-align:left;">The scary part is how little user error it actually took. The malicious extension was reportedly available for about 11 minutes, but the extension developers estimate more than 6,000 installs happened during that window. That means one GitHub developer likely just had auto-update enabled on what appeared to be a legitimate extension and suddenly malware landed directly inside their development environment. Nobody manually downloaded sketchy files. Nobody disabled antivirus. This is exactly why I keep saying browser extensions, IDE extensions, NPM packages, PyPI packages, and software supply chains are inching toward tied-for-first as the biggest security priority alongside help desk phishing. The attackers are openly telegraphing their playbook now. (read more <a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://socket.dev/blog/antv-packages-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="traditional-sase-wasnt-built-for-ai"><a class="link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" target="_blank" rel="noopener noreferrer nofollow">Traditional SASE Wasn&#39;t Built for AI Agents. Island Is.</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b0caaf63-5d1c-49d3-b90a-e77a5a32d779/Island_network.png?t=1779304978"/></div><p class="paragraph" style="text-align:left;">AI agents don&#39;t follow the rules traditional SASE was built for. Legacy architectures inspect connections but they cannot interpret intent. Island&#39;s Perfect Packet architecture enforces security where work actually happens: at the point of interaction, inside the browser.</p><p class="paragraph" style="text-align:left;">Backhaul becomes the fallback, not the default, so up to 90% of sessions go direct with no forced TLS inspection or traffic rerouting. Across user and AI agent sessions alike, Island governs what&#39;s sent, to where, and by whom, with a full audit trail and no blind spots.</p><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&utm_source=influencer&utm_campaign=influencer26_vulnerableu_sase&utm_content=network" target="_blank" rel="noopener noreferrer nofollow">See how Island does it.</a></b></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="project-glasswing-what-mythos-showe"><span style="background-color:#ffffff;"><a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>Project Glasswing: What Mythos Showed Us</b></a></span></h3><p class="paragraph" style="text-align:left;"><b>This is a top 5 blog of the year for me</b>. Cloudflare’s writeup of their experience with Mythos. The first parts of it are more of what we already knew, Mythos is better at writing exploits than the average AI model. The real magic in this post is when they start to talk about the harness and then the last few paragraphs.</p><p class="paragraph" style="text-align:left;">The people having the most success with Mythos aren’t just throwing source code at the model and saying “go find vulns.” They’re building advanced harnesses around it. Mozilla talked about it. The Cloudflare write-up talks about it. That seems to be where the magic actually happens: not just the model, but the surrounding tooling and workflows that let the model iterate toward a working exploit chain.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8ae3e141-984a-4e5d-b036-9a4b6529b1e0/Screenshot_2026-05-19_at_2.57.53_PM.png?t=1779217082"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Cloudflare’s vulnerability discovery harnass</a></p></span></div></div><p class="paragraph" style="text-align:left;">When the author starts to talk about how just fixing vulns faster is the wrong goal, I start to levitate off my seat. Music to my ears. Direct quote I love: “Patching faster does not change the shape of the pipeline that produces the patch.” - read it twice. then read it again. Fast whack-a-mole is still whack-a-mole. Vulnerabilities are just one way in, the layers you build around it are where security programs really earn their paycheck. (<a class="link" href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="cisa-admin-leaked-aws-gov-cloud-key"><span style="background-color:#ffffff;"><a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>CISA Admin Leaked AWS GovCloud Keys on Github</b></a></span></h3><p class="paragraph" style="text-align:left;">This CISA GovCloud leak story from Brian Krebs is insane. It was plaintext passwords, exposed AWS GovCloud credentials, public GitHub repos, and apparently very basic security hygiene failures. One of the exposed files literally contained admin creds for GovCloud systems. Another was apparently just a CSV full of usernames and passwords. Then you read the official response saying there’s “no indication sensitive data was compromised” while staring directly at screenshots of plaintext credentials. Shot. Chaser. Oh my god.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c0410132-cac2-46d2-93ea-f1589fd15562/Screenshot_2026-05-19_at_3.16.26_PM.png?t=1779218215"/></div><p class="paragraph" style="text-align:left;">The thing that really bothers me here is this clearly goes beyond “one contractor made a mistake.” There were supposed to be guardrails everywhere that should have caught this. GitGuardian reportedly flagged the exposed secrets. The repo was public. The passwords in some cases were apparently predictable formats like platform name plus current year. This would be embarrassing for any company. The fact that it’s tied to CISA-adjacent infrastructure and GovCloud makes it way worse. (<a class="link" href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="microsoft-shares-mitigation-for-yel"><span style="background-color:#ffffff;"><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>Microsoft Shares Mitigation for YellowKey Windows Zero-Day</b></a></span></h3><p class="paragraph" style="text-align:left;">Microsoft finally assigned a CVE to the YellowKey BitLocker bypass after the researcher behind it basically said, “Fine, if coordinated disclosure isn’t working, I’m just going public.” This is the same researcher behind Blue Hammer, Red Sun, and Green Plasma. I get why this whole thing has turned messy. Microsoft’s response literally says the proof-of-concept was released “violating coordinated vulnerability disclosure best practices,” but you don’t really get to say that after frustrating somebody through the disclosure process so badly they just start dropping everything publicly. That’s the whole point of the protest.</p><p class="paragraph" style="text-align:left;">The really wild part is how easy YellowKey apparently is to use. This is a BitLocker bypass that has people legitimately asking out loud whether this feels “too convenient” to be accidental. Microsoft’s mitigation guidance right now is basically “mount WinRE images manually, modify registry hives, disable recovery utilities,” which is honestly a disaster-tier mitigation for most organizations. The entire situation feels like Microsoft scrambling because they wanted time for a clean fix, but instead got forced into publishing ugly interim guidance after the exploit already hit GitHub. (<a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="ever-investigated-a-super-urgent-fi"><span style="background-color:#ffffff;"><b><a class="link" href="https://mazehq.com/blog/exploitability?utm_source=vulnu&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=secondary" target="_blank" rel="noopener noreferrer nofollow">Ever investigated a &quot;super urgent&quot; finding for it to be nothing?</a></b></span><span style="background-color:#ffffff;"><b>*</b></span></h3><p class="paragraph" style="text-align:left;">You&#39;ve spent hours digging into a &quot;critical&quot; CVE only to realize one config setting makes it impossible to exploit in your environment.</p><p class="paragraph" style="text-align:left;">You should never have had to look at it. That&#39;s not an exploitable finding, and reachability alone won&#39;t catch that. <b>Maze</b> AI agents determine exploitability like your best security engineer would, with context from your environment and business, before noise hits your backlog. (<a class="link" href="https://mazehq.com/blog/exploitability?utm_source=vulnu&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=secondary" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="welcome-to-black-file-inside-a-vish"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Welcome to BlackFile: Inside a Vishing Extortion Operation</a></h3><p class="paragraph" style="text-align:left;">Meet BlackFile (UNC6671), a threat group that Google just profiled who specializes in voice phishing. These guys call victims pretending to be IT support, claiming there&#39;s some urgent MFA update or passkey migration needed. While they&#39;ve got you on the phone walking through their fake portal, they&#39;re using your real credentials and MFA tokens in real-time to register their own devices on your accounts. Pretty slick adversary-in-the-middle setup that bypasses most traditional security controls.</p><p class="paragraph" style="text-align:left;">Once they&#39;re in your Microsoft 365 or Okta environment, they go full automation mode with Python and PowerShell scripts to hoover up massive amounts of data - millions of files in some cases. They&#39;re using direct HTTP requests that show up as &quot;FileAccessed&quot; events instead of &quot;FileDownloaded&quot; to stay under the radar. After stealing everything from SharePoint to Salesforce, they hit you with extortion demands starting in the millions but often settling for low six-figures. Their data leak site shut down in May 2026 with a cryptic &quot;shutting down under this name&quot; message, suggesting they&#39;re probably just rebranding for round two. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="1-password-teams-with-open-ai-to-st"><span style="background-color:#ffffff;"><a class="link" href="https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow"><b>1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials</b></a></span></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/824b8ab4-350c-49b6-a0ae-1e5b7022693a/Screenshot_2026-05-20_at_11.57.34_AM.png?t=1779359898"/></div><p class="paragraph" style="text-align:left;">This 1Password and OpenAI partnership might actually be one of the smarter AI security ideas I’ve seen lately. The core idea is to stop stuffing secrets into environment variables, dotfiles, prompts, repos, and MCP configs where AI coding agents can accidentally expose them. That’s exactly how a lot of developers are working right now. People are using Codex, MCP servers, and other AI coding tools, and the workflow often becomes, “Yeah, just stick the API key into the ENV variable and let the agent use it.” Then suddenly your coding agent has long-lived access to sensitive credentials sitting directly inside the model workflow.</p><p class="paragraph" style="text-align:left;">What 1Password is proposing here is a just-in-time credential model where the secrets stay vaulted and only get issued temporarily for the specific task the agent is performing. In theory, I actually really like this idea. Keeping secrets out of prompts, repos, and model context windows is absolutely the right direction. The part I’d want to test hard is the enforcement side. It’s easy to say “credentials are scoped to the task,” but how do you actually guarantee that? You can’t just ask the AI agent nicely not to misuse the creds. Still, if this works the way they’re describing, it could genuinely reduce a lot of the secret leakage mess we’re seeing right now across AI-assisted development environments. (<a class="link" href="https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="coruna-respawned-compromised-arttem"><a class="link" href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package?utm_medium=feed#Stage-6-Final-Action-Dispatch-and-Payload-Invocation" target="_blank" rel="noopener noreferrer nofollow">Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit</a></h3><p class="paragraph" style="text-align:left;">My ears perked up when I read this headline as I just did a whole video about Coruna and it’s sister exploit DarkSword. This is also a bit different then the other npm stuff we’ve covered lately as it’s not targeting the developer pulling the npm malware, it’s targeting iOS devices of users who happen upon websites using the pwned packages.</p><p class="paragraph" style="text-align:left;">Socket&#39;s threat research team caught this in the popular art-template npm package. Someone got their way into taking over maintenance from the original author, then immediately started pushing weaponized versions. The compromised packages (4.13.5 and 4.13.6) inject a sophisticated iOS Safari exploit framework that&#39;s basically a respawned version of the Coruna exploit kit - the same commercial toolkit that Google documented earlier with 5 full exploit chains targeting iOS 13-17.2.</p><p class="paragraph" style="text-align:left;">The technical sophistication is impressive in a terrifying way - multiple obfuscation layers, content-addressed module loading, and even CPU architecture discrimination between regular iPhones and Apple Silicon Macs. If your app bundled those bad art-template versions, every user visiting your site got served this exploit framework automatically. (<a class="link" href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package?utm_medium=feed#Stage-6-Final-Action-Dispatch-and-Payload-Invocation" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="scammers-are-abusing-an-internal-mi"><a class="link" href="https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Scammers are abusing an internal Microsoft account to send spam links</a></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DYnQuetvS9z/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><h3 class="heading" style="text-align:left;" id="ghost-tree-unveiling-path-manipulat"><a class="link" href="https://www.varonis.com/blog/ghosttree-ntfs-trick?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security</a></h3><p class="paragraph" style="text-align:left;">Varonis just dropped details on a clever new evasion technique called GhostTree that&#39;s bound to give some EDR vendors headaches. The idea is to use NTFS junctions to create recursive directory loops that generate infinite file paths. Any user can pull this off with just write permissions and a couple mklink commands, no admin rights needed. Point a child folder back to its parent, and suddenly you&#39;ve got unlimited valid paths to the same file that can stretch all the way to Windows&#39; 260-character limit.</p><p class="paragraph" style="text-align:left;">The nastier variant creates multiple junction branches, turning your directory structure into a binary tree nightmare that can theoretically generate 2^ 126 unique paths (that&#39;s more paths than there are atoms in your body, for perspective). When EDR tools try to recursively scan these folders, they get stuck in the loop and hang, leaving your actual malware sitting pretty and unscanned. Microsoft initially brushed this off saying &quot;bypassing Defender isn&#39;t crossing a security boundary,&quot; but then quietly patched it anyway. (<a class="link" href="https://www.varonis.com/blog/ghosttree-ntfs-trick?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grafana-breach-caused-by-missed-tok"><a class="link" href="https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Grafana breach caused by missed token rotation after TanStack attack</a></h3><p class="paragraph" style="text-align:left;">Grafana is another ripple effect of the npm worms. Their CI/CD pipeline consumed one of those malicious npm packages and the credential-stealing malware did its thing and stole some GitHub workflow tokens from their environment. Grafana&#39;s incident response team jumped on it and started rotating tokens, but they missed one.</p><p class="paragraph" style="text-align:left;">That lone forgotten token was all the attackers needed to get into Grafana&#39;s private GitHub repos and make off with source code plus some business operational data (think contact names and emails, nothing too spicy). No customer production data got touched, and they didn&#39;t mess with the actual codebase, so if you&#39;ve been downloading Grafana recently, you&#39;re fine. But this hand in hand with the lead story on GitHub is a second order hack of the npm worm worth watching. (<a class="link" href="https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="europe-dismantles-vpn-service-used-"><a class="link" href="https://therecord.media/europe-dismantles-first-vpn?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">Europe dismantles VPN service used by cybercriminals to hide ransomware attacks</a></h3><p class="paragraph" style="text-align:left;">European cops just took a wrecking ball to First VPN, the go-to service for cybercriminals looking to hide their dirty work. This coordinated takedown between France, Netherlands, and Ukraine happened this week and targeted a service that had been advertising itself on Russian-speaking crime forums for years. They grabbed 33 servers and, more importantly, the entire user database - which is basically a Christmas list of cybercriminals who thought they were untouchable.<br><br>First VPN wasn&#39;t just some regular VPN that happened to have bad actors as customers. This thing was specifically marketed to criminals, promising they&#39;d never cooperate with law enforcement and would keep users &quot;beyond the reach&quot; of authorities. (<a class="link" href="https://therecord.media/europe-dismantles-first-vpn?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-169" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/998b39cd-976a-428f-b843-46a5480968e2/image.png?t=1779400357"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c1f3ea35-a902-4181-bd1a-45f995dba462/Screenshot_2026-05-21_at_9.34.20_PM.png?t=1779417271"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b4b1adfb-0461-49d5-911f-02fef1e75a64/Screenshot_2026-05-21_at_9.38.05_PM.png?t=1779417499"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #168</title>
  <description>So many more supply chain worms, so many more linux 0days, some android 0days as a treat, and much more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-168</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-168</guid>
  <pubDate>Fri, 15 May 2026 12:16:00 +0000</pubDate>
  <atom:published>2026-05-15T12:16:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/de428da1-d233-4c9f-9345-bcc638399b06/vulnu-header-2026-05-15.png?t=1778779973"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef88cc30-3da1-45a1-8b9e-3411cedee9fd/Newsletter_Sponsor_Logo.png?t=1758216398"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">I’ve fallen into a new hobby by force. I’m keynoting a conference in a few weeks called <a class="link" href="https://descentcyber.com/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Descent Cyber</a> - and will be scuba diving with CISOs and other industry. So I’ve been very busy getting scuba certified for the first time. What a wild process! Will I see any of you down there? I think the other keynote is the CISO of the NFL and there are a ton of industry vets going. I’m excited.</p><p class="paragraph" style="text-align:left;">If you’re reading this and enjoy a good livestream I’m officially a few months into Tue, Wed, Thur streams on <a class="link" href="https://www.youtube.com/@VulnerableU?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">YouTube</a> and <a class="link" href="https://www.twitch.tv/reshikote?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Twitch</a>. We have great convos and chat fills with practitioners living through the front lines. Love when I talk about something which causes someone in stream to have to go run an incident because thats how they found out. Come check it out. I start in the 9am hour CST and run about 2-4 hours depending on whats going on. This week I even had <a class="link" href="https://www.youtube.com/watch?v=n3zYAk0_njQ&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Andrew Peterson</a>, former CEO of Signal Sciences and current Investor for Aviso come in the studio and jam.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: My <a class="link" href="https://x.com/mattjay/status/2054304708060168263?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">ELI5 breakdown</a> of the recent supply chain malware issue</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: Primeagen’s <a class="link" href="https://www.youtube.com/watch?v=zaGOKd4jqEk&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">run down</a> of recent Mythos news and capabilities</p><p class="paragraph" style="text-align:left;">🎤 Something I said: The most work we’ve put into a YouTube video yet. <a class="link" href="https://www.youtube.com/watch?v=cv1Kba1T83E&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">I interviewed</a> the teams that found the recent iOS 0days in the wild.</p><p class="paragraph" style="text-align:left;">🔖 Something I read: This org made a <a class="link" href="https://x.com/heyandras/status/2054512710017298463?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">honeypot GitHub</a> to catch AI bots pushing BS PRs so they can block them from their real repos.</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="mini-shai-hulud-is-back-npm-worm-ke"><b><a class="link" href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Mini Shai-Hulud Is Back: NPM Worm Keeps Mutating as GitHub Supply Chain Attacks Accelerate</a></b></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bd5a4440-21e1-44bd-ad40-30b7639d10dd/Screenshot_2026-05-13_at_11.25.53_AM.png?t=1778696387"/></div><p class="paragraph" style="text-align:left;">Another week, another NPM worm. This latest wave, “Mini Shai-Hulud”, hit packages tied to TanStack, Mistral AI, and a growing list of projects across NPM and PyPI. At this point, the playbook is becoming painfully familiar: compromise a developer, steal GitHub and NPM tokens, poison legitimate packages, spread to additional maintainers and repos, repeat. But this one feels bigger because the attackers abused legitimate GitHub Actions workflows and trusted release pipelines to publish malicious updates under real developer identities. That’s a very different problem than typo-squatted malware packages sitting in a registry corner waiting for someone to accidentally install them.</p><p class="paragraph" style="text-align:left;">The malware itself was extremely focused on developers and CI/CD infrastructure. Once installed, it hunted for GitHub tokens, NPM credentials, AWS secrets, Kubernetes configs, SSH keys, and other high-value developer artifacts. If it found package publishing access, it attempted to spread itself further. That’s the worm behavior. And this is where the modern dependency ecosystem starts looking really fragile. Developers are now stuck in an impossible tradeoff: patch too slowly and you sit on known vulnerabilities; patch too quickly and you might automatically pull malware before researchers catch it. That’s why teams are now talking seriously about “minimum release age” policies, intentionally delaying dependency updates by several days so security vendors have time to identify malicious releases.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a8e62f99-1cef-4271-8ecd-cd1db54d736f/Screenshot_2026-05-13_at_11.22.58_AM.png?t=1778696607"/></div><p class="paragraph" style="text-align:left;">The really uncomfortable part is how much of this is just the ecosystem functioning as designed. Trusted automation. Trusted publishers. CI/CD pipelines moving at internet speed. The attackers are using the same workflows developers use. And they’re evolving fast. Some variants reportedly included dead-man-switch behavior where revoking a stolen GitHub token could trigger destructive actions on the victim machine. Others experimented with geofenced wiper functionality. This is active supply-chain warfare happening inside the developer ecosystems that run modern software. (Read more <a class="link" href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="timetoexploit-is-down-to-one-day-no"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Time-to-exploit is down to one day. Now what?</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dfe53be7-5b81-4248-bfc0-ce84964997b9/ASM_report_header.png?t=1778780069"/></div><p class="paragraph" style="text-align:left;"><b>Intruder</b> analyzed 3,000 organizations&#39; attack surfaces. Top finding: more teams should be asking &#39;does this actually need to be on the internet?’</p><p class="paragraph" style="text-align:left;">There’s no better time to ask it. AI can now find zero-days autonomously and time-to-exploit has shrunk to a single day. Anything on the internet that doesn&#39;t need to be is a target the moment a new CVE drops.</p><p class="paragraph" style="text-align:left;">In the report:</p><ul><li><p class="paragraph" style="text-align:left;">What are the most common attack surface exposures?</p></li><li><p class="paragraph" style="text-align:left;">How long are organizations taking to fix them?</p></li><li><p class="paragraph" style="text-align:left;">How does your industry compare?</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=vulnerableu&utm_medium=p_referral&utm_campaign=global%7Cfixed%7Casm_index" target="_blank" rel="noopener noreferrer nofollow">Get the report</a></p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="a-0-click-exploit-chain-for-the-pix"><a class="link" href="https://projectzero.google/2026/05/pixel-10-exploit.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>A 0-Click Exploit Chain for the Pixel 10: When a Door Closes, a Window Opens</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e74fbadf-9092-4852-960c-5cf11d4cf2b2/Screenshot_2026-05-14_at_2.56.54_PM.png?t=1778785037"/></div><p class="paragraph" style="text-align:left;">Project Zero dropped a really interesting write-up showing how they went from a zero-click context to full root on Android using just two exploits chained together. The original work targeted the Pixel 9 earlier this year, and then they adapted the same general approach to the Pixel 10. The wildest part is how straightforward they said portions of it were. One of the bugs apparently stood out specifically because it was “exceptionally simple to exploit.” Zero-click to root on a mobile device is still one of the scariest classes of bugs out there.</p><p class="paragraph" style="text-align:left;">The important context here is this was pre-Mythos. You can’t blame AI for this one. This is just elite vulnerability research and exploit development. But one encouraging thing was Project Zero actually praising Google’s response process, noting it was the first time the vendor patched within the 90-day disclosure window. It’s also kind of funny because even though both teams are technically Google, Project Zero still treats them like a third-party vendor relationship. (<a class="link" href="https://projectzero.google/2026/05/pixel-10-exploit.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="fragnesia-linux-kernel-local-privil"><a class="link" href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8fcc3376-c850-47b3-9fdc-f573814e4d3a/Screenshot_2026-05-14_at_3.00.48_PM.png?t=1778785261"/></div><p class="paragraph" style="text-align:left;">Another day, another Linux privilege escalation. Idk whats going on. If you missed the last two, Copy Fail and DirtyFrag - you can catch up <a class="link" href="https://www.elastic.co/security-labs/copy-fail-dirtyfrag-linux-page-bugs-in-the-wild?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>. The latest, Fragnesia, which reportedly emerged as an unintended side effect of one of the patches for DirtyFrag. Security is hard. Just like the npm issues, if you patch it doesn’t mean you’re negating all risk.</p><p class="paragraph" style="text-align:left;">The good news is you can disable the vulnerable kernel modules (esp4, esp6, rxrpc) if you don&#39;t need them, or restrict unprivileged user namespaces. If you suspect you&#39;ve been hit, a simple reboot or cache flush will clear the in-memory modifications. (<a class="link" href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="gtig-ai-threat-tracker-adversaries-"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/981f90f6-073d-4785-bbec-0d5b4ce4b105/Screenshot_2026-05-13_at_12.30.10_PM.png?t=1778699858"/></div><p class="paragraph" style="text-align:left;">Google’s new threat intelligence report is the strongest evidence yet that AI is already being operationalized by threat actors in real attacks. The report goes through attackers using AI for vulnerability research, exploit development, phishing, malware refinement, and attack automation, and they even call out Team PCP, the same group behind the Mini Shai-Hulud supply-chain worm.</p><p class="paragraph" style="text-align:left;">What stands out to me is that attackers getting faster and scaling harder. Google says they’ve now seen evidence of AI being used to discover and help weaponize a zero-day for the first time, including a 2FA bypass exploit. Honestly, I think this is just the beginning. We’re already seeing vibe-coded malware, automated payload generation, and increasingly autonomous attack workflows. I’m probably going to do a long YouTube video walking through this whole report because it feels like one of those “this is where the industry changes” moments. (<a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="check-out-the-opensource-matrix-for"><b><a class="link" href="https://hubs.li/Q04f_n420?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Check out the open-source matrix for browser-based attack techniques</a></b><b>*</b></h3><p class="paragraph" style="text-align:left;">AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — two years ago, most of these were research curiosities. Today they&#39;re industrialized, available as PhaaS, and behind the majority of identity compromises. <b>Push Security&#39;s</b> Browser & Identity Attacks Matrix maps every technique in one open-source framework. </p><p class="paragraph" style="text-align:left;">Explore the matrix from Push Security<b>.</b> (<a class="link" href="https://hubs.li/Q04f_n420?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="introducing-daybreak-frontier-ai-fo"><a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Introducing Daybreak: Frontier AI for Cyber Defenders</a></h3><div class="image"><a class="image__link" href="https://www.youtube.com/live/-ysFroySPxQ?si=P0I79fFPr8zhf9__&t=2345&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/519e25c9-df1b-4b20-bf0a-1a1b8b9a03d7/Screenshot_2026-05-14_at_12.38.07_PM.png?t=1778780320"/></a></div><p class="paragraph" style="text-align:left;">OpenAI launched yet another cybersecurity AI initiative, this one called Daybreak, and my first reaction is: what the hell is going on? Because at this point we’ve had Trusted Access for Cyber, Codex Security, Expanded Trusted Access, GPT-5 Cyber, scaling trusted access with GPT-5 Cyber… and now Daybreak. The branding and positioning are getting impossible to follow, even for people who live in this space every day.</p><p class="paragraph" style="text-align:left;">But underneath the marketing confusion, I do think there’s something important happening here. Daybreak feels less like “AI security tooling” and more like OpenAI acknowledging that frontier models are fundamentally changing vulnerability discovery and defensive operations. The Trail of Bits write-up framed it really well: frontier models are now finding bugs faster than maintainers can triage them:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/422a6ce4-55e4-471f-ac38-5f8c47dfb2d2/Screenshot_2026-05-13_at_12.16.01_PM.png?t=1778703802"/></div><p class="paragraph" style="text-align:left;">That’s a pretty massive shift if you stop and think about it. We’re heading toward a world where AI systems are acting more autonomously inside security workflows: vulnerability research, SOC operations, triage, remediation, code review, all of it. The interesting part is whether enterprises are actually going to trust these systems enough to let them operate at scale inside production environments. (More <a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://x.com/trailofbits/status/2054573243680559165?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/OpenAI/status/2053939702110269822?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="publicly-released-microsoft-0-days-"><a class="link" href="https://x.com/vxunderground/status/2054238975804531135?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Publicly Released Microsoft 0days By Disgruntled Researcher</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/25e58041-5c14-40a4-a011-d4b06e5deb09/Screenshot_2026-05-13_at_4.31.06_PM.png?t=1778704540"/></div><p class="paragraph" style="text-align:left;">So this researcher is fed up with Microsoft’s disclosure process and decided: “f it, we’re doing painful disclosure.” Instead of quietly coordinating fixes, he started publicly dropping the research straight onto GitHub, including the latest, YellowKey and GreenPlasma.</p><p class="paragraph" style="text-align:left;">The one that really stood out to me was YellowKey, which is a BitLocker bypass affecting Windows 11 and newer server builds. The way he describes it almost sounds like discovering some weird hidden debug or recovery functionality left inside WinRE. You boot into recovery, hit a specific key combo, and there’s behavior around BitLocker relocking that apparently should not exist. His whole point is basically: “why is this functionality even here?” And I’ll be honest, reading through it, I kind of get why he starts speculating about it being purposefully created backdoor. (read more <a class="link" href="https://x.com/vxunderground/status/2054238975804531135?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://github.com/Nightmare-Eclipse/YellowKey?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://github.com/Nightmare-Eclipse/GreenPlasma?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="not-a-preload-issue-xbox-responds-a"><a class="link" href="https://www.windowscentral.com/gaming/xbox/what-an-insane-screw-up-xbox-itself-leaks-forza-horizon-6-pc-files-in-full-a-week-before-launch-and-pirates-already-cracked-it?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>&quot;Not a Preload Issue&quot;: Xbox Responds As &#39;Forza Horizon 6&#39; PC Files Leak in Full a Week Before Launch — and Pirates Already Cracked It (UPDATED: Microsoft Responds)</b></a></h3><p class="paragraph" style="text-align:left;">The Forza Horizon 6 leak is one of those stories where I genuinely don’t know if it’s “cyber” or just an absolutely catastrophic operational screw-up. The initial reporting made it sound like somebody accidentally pushed the game live on Steam early with unencrypted files, which immediately led to the raw game assets leaking and pirates cracking it before launch.</p><p class="paragraph" style="text-align:left;">But then they came out and said it <i>wasn’t</i> a preload issue, which honestly just makes the whole thing weirder. Because if it wasn’t some accidental publishing mistake… then what was it? That’s the part that has everybody speculating right now. Meanwhile, the downstream effects are already happening: cracked builds circulating before release, pirated copies spreading everywhere, and the publisher threatening franchise-wide bans for anyone involved. (read more <a class="link" href="https://www.windowscentral.com/gaming/xbox/what-an-insane-screw-up-xbox-itself-leaks-forza-horizon-6-pc-files-in-full-a-week-before-launch-and-pirates-already-cracked-it?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://x.com/WeArePlayground/status/2053895284930105772?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="california-mayor-charged-with-actin"><a class="link" href="https://abcnews.com/Politics/california-mayor-accused-acting-illegal-agent-china/story?id=132860574&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>California Mayor Charged With Acting As Illegal Agent for China</b></a></h3><p class="paragraph" style="text-align:left;">The mayor of Arcadia pled guilty to acting as an illegal agent for China tied to operating a website that pushed pro-PRC messaging into the local Chinese-American community. From the reporting, it wasn’t just “generally pro-China opinions.” The allegation is she was actually receiving directives from PRC officials about what content to publish and sometimes even seeking approval before circulating material.</p><p class="paragraph" style="text-align:left;">The part that makes this way more serious is that this is an elected official. If this were just some random propaganda site, okay, that’s one thing. At the same time, this doesn’t sound like “spy movie” espionage stuff so much as an information operation, influence, messaging, narrative shaping, all of that. (<a class="link" href="https://abcnews.com/Politics/california-mayor-accused-acting-illegal-agent-china/story?id=132860574&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="canvas-update-instructure-just-conf"><a class="link" href="https://www.reddit.com/r/canvas/comments/1taj9mk/instructure_just_confirmed_they_paid_the_ransom/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow"><b>Canvas Update: Instructure Just Confirmed They Paid the Ransom</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/df6b6dc6-8dc6-4962-b044-61f87e0261dc/Screenshot_2026-05-13_at_5.00.18_PM.png?t=1778706056"/></div><p class="paragraph" style="text-align:left;">The Canvas/Instructure hack got really wild because the ransomware group didn’t just ransom the company, they basically threatened every school using Canvas too. The attackers published a giant list of something like 9,000 schools and essentially said: “If you don’t want your school’s data released, contact us.” That’s a pretty massive escalation compared to the normal playbook.</p><p class="paragraph" style="text-align:left;">ShinyHunters came out and basically said the matter was resolved and schools wouldn’t be further targeted. Then Instructure publicly confirmed they paid the ransom. Straight up. They said the data was returned and they received assurances it wouldn’t be further shared. FBI guidance is always “don’t pay.” But honestly I completely understand why companies do it, especially when the blast radius suddenly includes thousands of schools/children. (<a class="link" href="https://www.reddit.com/r/canvas/comments/1taj9mk/instructure_just_confirmed_they_paid_the_ransom/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="behind-the-scenes-hardening-firefox"><a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">Behind the Scenes Hardening Firefox with Claude Mythos Preview</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ea4361c6-ef78-4c6d-9eb0-7ba45438a4a2/security-bug-fixes-1-scaled.webp?t=1778783642"/></div><p class="paragraph" style="text-align:left;">Mozilla used Claude Mythos Preview and other models to find 271 security vulnerabilities in Firefox - part of a massive 423 total bugs they squashed in April alone. The lesson that stands out to me is that we all better be building custom harnesses. Mozilla seemingly is more successful than other project Glasswing participants and all evidence points towards the fact that they’re using a very sophisticated harness on top of their legacy bug finding/fixing system to swap in models as they release.</p><p class="paragraph" style="text-align:left;">The &quot;agentic harness&quot; can actually test and validate bugs instead of just spitting out false positives. They went from AI bug reports being mostly useless noise to finding legitimate sandbox escapes that would make any red teamer jealous. Mozilla&#39;s basically saying the AI security audit game has fundamentally shifted - they&#39;re encouraging everyone to start building similar pipelines now because the models are finally good enough to be worth the effort. Given how many of these were sandbox escapes and parent process UAFs, attackers are probably already doing this too. (<a class="link" href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-168" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/109cb304-3d7f-4027-a860-eae0ebdf8386/Screenshot_2026-05-14_at_7.13.07_PM.png?t=1778803990"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b80972ed-8ce0-4da5-9893-d53874ee7e99/image.png?t=1778804049"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4b52d058-cf7f-4f4b-a1d0-6d3f003a5bee/image.png?t=1778803765"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🎓️ Vulnerable U | #167</title>
  <description>Massive education software hacked - Canvas ransomware, AI layoffs, Zero days in edge devices, Iran pretending to be cybercrime group, and more!</description>
  <link>https://www.vulnu.com/p/vulnerable-u-167</link>
  <guid isPermaLink="true">https://www.vulnu.com/p/vulnerable-u-167</guid>
  <pubDate>Fri, 08 May 2026 12:18:00 +0000</pubDate>
  <atom:published>2026-05-08T12:18:00Z</atom:published>
    <dc:creator>Matt Johansen</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="font-family:Courier, Lucida Typewriter, monospace;"><i><b>Read Time: </b></i></span><span style="font-family:Courier, Lucida Typewriter, monospace;"><i>8 minutes</i></span></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d9efc122-b2b9-4e4b-8b62-4a020897d2a6/vulnu-header-2026-05-08.png?t=1778195705"/></div><p class="paragraph" style="text-align:center;">Brought to you by:</p><div class="image"><a class="image__link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6384ee26-3c52-468a-adac-cc3ff23bce99/Newsletter_Sponsor_Logo.png?t=1755788381"/></a></div><p class="paragraph" style="text-align:left;">Howdy friends!</p><p class="paragraph" style="text-align:left;">An odd week for me. Definitely feeling that Spring burnout. Feels like a lot of people around me also, what is in the air?</p><p class="paragraph" style="text-align:left;">I’m gearing up for some speaking gigs I’ve got this summer and really excited about some of the talks I’ve got cooking. </p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="icymi"> ICYMI</h1><p class="paragraph" style="text-align:left;">🖊️ Something I wrote: zero days are not <a class="link" href="https://x.com/mattjay/status/2052398790150156782?s=20&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">invisibility</a> cloaks.</p><p class="paragraph" style="text-align:left;">🎧️ Something I heard: This <a class="link" href="https://www.youtube.com/watch?v=3pkz-Ie_k_c&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">breakdown</a> of Anthropic and SpaceX stuff is the best I’ve seen</p><p class="paragraph" style="text-align:left;">🎤 Something I said: GitHub is <a class="link" href="https://www.youtube.com/watch?v=8MqOtYAw9dw&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">not ok</a></p><p class="paragraph" style="text-align:left;">🔖 Something I read: Finding Zero-Days with Any <a class="link" href="https://www.provos.org/p/finding-zero-days-with-any-model/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Model</a> (best blog I’ve read in a long time)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="vulnerable-news">Vulnerable News</h1><h3 class="heading" style="text-align:left;" id="canvas-hacked-by-shiny-hunters"><b>Canvas hacked by ShinyHunters</b></h3><blockquote align="center" class="instagram-media"><a href="https://www.instagram.com/reel/DYDVLJDPtI6/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167"><p dir="ltr" lang="en"> Instagram post </p></a></blockquote><h3 class="heading" style="text-align:left;" id="vulnerability-fixes-without-an-owne"><a class="link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" target="_blank" rel="noopener noreferrer nofollow">Vulnerability fixes without an owner are just a suggestion</a>*</h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/328d36d0-8893-489d-992a-2bd377020feb/Social_Share.png?t=1778170133"/></div><p class="paragraph" style="text-align:left;">Most vulnerability tickets die in the backlog. Sometimes the fix is hard. More likely, nobody knows who owns it, or the ticket didn&#39;t help the person fix it, just a request to patch a vague vulnerability.</p><p class="paragraph" style="text-align:left;">And when you do find the owner, the tags are stale, the original engineer moved on, and the new owner doesn&#39;t know what they inherited.</p><p class="paragraph" style="text-align:left;"><b>Maze</b>&#39;s AI agents show you the fix your developers will actually implement, not just the textbook fix. Then they cross-reference your repo history, CODEOWNERS, CMDB, and other signals to find who&#39;s fixed this before, so the fix lands with the right person every time.</p><p class="paragraph" style="text-align:left;">Vulns get closed. Period. (<a class="link" href="https://mazehq.com/blog/remediation-ownership?utm_source=vuln-u&utm_medium=newsletter&utm_campaign=2025Q2-Global-Inbound-Newsletter-VulnU&utm_content=primary" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><p class="paragraph" style="text-align:left;"><span style="font-size:0.8rem;"><i>*Sponsored</i></span></p><h3 class="heading" style="text-align:left;" id="exploitation-of-panos-captive-porta"><a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution</a></h3><p class="paragraph" style="text-align:left;">Because apparently it’s consumer edge device vulnerability day ending in Y, we’ve got another PAN-OS bug getting actively exploited. This one is a buffer overflow in the User-ID authentication portal that lets an unauthenticated attacker execute arbitrary code as root. That’s about as bad as it gets.</p><p class="paragraph" style="text-align:left;">What stands out to me is this was already being exploited before the advisory dropped. So this was a zero day. And honestly, the part I keep coming back to with a lot of these edge-device bugs is that the vendor guidance usually says the same thing every time: <b>don’t expose these management and auth portals directly to the internet.</b> Because these vulnerabilities happen constantly.</p><p class="paragraph" style="text-align:left;">That’s the frustrating part. I don’t even beat vendors up too hard over some of this anymore because everybody ships vulnerable code eventually. The real issue is how often these things are internet-facing in the first place. The numbers on this one aren’t staggering, but some new evidence is pointed towards state actors out of China and hyper targeted so they don’t need numbers. (read more <a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, and <a class="link" href="https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="coinbase-cuts-headcount-by-14-citin"><b><a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Coinbase Cuts Headcount By 14%, Citing AI Acceleration</a></b></h3><div class="image"><img alt="" class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bf219b5f-4d39-4d5e-a3f6-7b6d19151947/Screenshot_2026-05-05_at_11.18.22_AM.png?t=1778005631"/></div><p class="paragraph" style="text-align:left;">Coinbase laid off about 14% of the workforce, roughly 700 people.</p><p class="paragraph" style="text-align:left;">They are blaming AI, which at this point shows up in every layoff. “AI is changing how we work,” engineers shipping faster, non-technical teams shipping production code, workflows getting automated. I don’t even disagree with a lot of that. But I think AI is lowercase in reality and uppercase in the press release. This is cost cutting first, AI second. If you can reduce headcount and keep revenue the same, why wouldn’t you do that? That’s the magic corporate Ozempic everyone wants.</p><p class="paragraph" style="text-align:left;">The thing a bunch of people, myself included, found concerning here. We have a financial institution saying managers will be pushed to 15+ direct reports and be asked to be individual contributors too. No pure play managers. Player coaches. etc. etc. We’ll see how far this one goes, but non-tech teams pushing code to prod sounds sexy for startups, sounds concerning for finance.</p><p class="paragraph" style="text-align:left;">Zooming out, this isn’t just Coinbase. It’s happening everywhere. Companies trim the fat, point to AI, and say they’re more efficient. One possible outcome here is we end up with fewer massive companies and a lot more smaller ones, because it’s easier to build now. Code isn’t a moat like it used to be. But the other path is a lot uglier: widespread layoffs, less spending, everything slows down. I’m hoping we land closer to the first one. (<a class="link" href="https://x.com/brian_armstrong/status/2051616759145185723?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="muddy-water-uses-microsoft-teams-to"><a class="link" href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/abe4f75b-65c7-45a0-99d4-f8bd586fd81f/Screenshot_2026-05-07_at_10.11.33_AM.png?t=1778164591"/></div><p class="paragraph" style="text-align:left;">MuddyWater&#39;s getting creative with their false flag game. The Iranian state group just pulled off a ransomware attack that wasn&#39;t really about ransomware at all - they used the Chaos RaaS brand as cover while conducting what was actually a targeted espionage operation. The attack kicked off with some social engineering via Microsoft Teams, where they posed as IT support and got victims to screen-share their way into giving up credentials and bypassing MFA. Once inside, they skipped the whole file encryption thing and went straight for data exfiltration and persistence tools like DWAgent.</p><p class="paragraph" style="text-align:left;">(Do I need to keep saying it? Help desk social engineering should be top of your list)</p><p class="paragraph" style="text-align:left;">This fits a bigger pattern we&#39;re seeing where state actors are borrowing from the cybercrime playbook to muddy attribution waters. (get it?) It&#39;s getting harder to tell who&#39;s who when Iranian operators are using the same tools and tactics as profit-driven ransomware crews. This comes alongside other Iranian cyber escalations, including attacks on Omani government systems and that Port of Fujairah hit where stolen infrastructure data was allegedly used for missile targeting. We&#39;re watching the line between cyber and kinetic operations blur in real time.(I made a whole <a class="link" href="https://www.youtube.com/watch?v=L4ufU29PP4o&utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">video</a> about that) (<a class="link" href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="romance-scammers-turn-sweet-talk-in"><a class="link" href="https://www.theregister.com/security/2026/05/05/romance-fraudsters-fleeced-uk-victims-of-102m-in-2025/5227963?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Romance Scammers Turn Sweet Talk Into £102M Payday</b></a></h3><p class="paragraph" style="text-align:left;">The UK just reported more than £102 million lost to romance scams in 2025, and honestly, I think the real number is way higher due to many being unreported. These scams are working. I personally know people whose parents lost tens of thousands of dollars. One was out 30 grand, another 60 grand, and in both cases the victims still fully believed they were in real relationships. Their families become “the bad guys” for trying to stop the bleeding. Both didn’t report due to being so convinced by the scam.</p><p class="paragraph" style="text-align:left;">That’s the part people don’t understand about these things. Once someone is emotionally locked in, logic stops mattering. One of the victims I know had their kids cutting off access to accounts and credit cards, and they still found ways to send money; gift cards, whatever they could. And the people who do realize what happened are often too embarrassed to report it, which means the stats we’re seeing are almost definitely underreported.</p><p class="paragraph" style="text-align:left;">The scary part is these scammers are still basically playing on easy mode. They’re not even really using the scary AI stuff yet: deepfakes, voice cloning, all of that. If they’re already this successful with basic manipulation and fake personas, it’s only going to get worse once those tools become standard. (<a class="link" href="https://www.theregister.com/security/2026/05/05/romance-fraudsters-fleeced-uk-victims-of-102m-in-2025/5227963?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="that-ai-extension-helping-you-write"><a class="link" href="https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">That AI Extension Helping You Write Emails? It’s Reading Them First</a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fea7bd03-864b-4390-9dec-ca7110525a0c/Screenshot_2026-05-05_at_3.01.53_PM.png?t=1778007730"/></div><p class="paragraph" style="text-align:left;">Unit 42 dropped a report on high-risk gen AI browser extensions, and this is one of those “you should probably read this” things. They’re seeing this stuff in the wild. Extensions that look like AI tools, or maybe actually are AI tools, but they’re also doing some sketchy stuff on the side. Data exfiltration, adware, hidden iframes, prompt hijacking, redirecting searches, all the usual nonsense, just wrapped in AI branding.</p><p class="paragraph" style="text-align:left;">What stands out to me isn’t even that any one of these is massive. Some of them barely have users. A couple thousand here, one had like two users. That’s not the point. The point is the behavior. This stuff is getting into the Chrome Web Store, and it’s doing exactly what we’ve been talking about. Either it’s malicious from the start, or it does what it says it does for a while and then turns malicious later. (<a class="link" href="https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="that-ai-extension-helping-you-write"><a class="link" href="https://withpersona.com/solutions/workforce-idv?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_can_ds_wf-idv_fy26q2-vuln-u-wf-idv" target="_blank" rel="noopener noreferrer nofollow">Stop deepfakes and social engineering across the employee life cycle</a>*</h3><p class="paragraph" style="text-align:left;">Social engineering, deepfakes, and impersonation are the new security threats. <b>Persona</b>&#39;s Workforce IDV solution verifies real-world identity, not just credentials, with liveness detection, government ID checks, and passive signals. </p><p class="paragraph" style="text-align:left;">From onboarding and device enrollment to MFA resets and privileged actions, identity stays secure. (<a class="link" href="https://withpersona.com/solutions/workforce-idv?utm_source=vuln-u&utm_medium=paid-email&utm_audience=a&utm_campaign=brnd_can_ds_wf-idv_fy26q2-vuln-u-wf-idv" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="grok-tricked-into-sending-money-by-"><a class="link" href="https://www.youtube.com/shorts/tk2XFAgLgxs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">Grok Tricked Into Sending Money By Prompt Injection</a></h3><table width="100%" class="bh__column_wrapper"><tr><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c7c6daba-1639-455e-b9ab-8035d731a6c3/image.png?t=1778185133"/></div></td><td width="50%" class="bh__column"><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/96e4160f-a588-4098-9bd1-3b08d385b2fe/image.png?t=1778185114"/></div></td></tr></table><p id="all-right-this-is-super-funny-someo" class="paragraph" style="text-align:left;">All right, this is super funny: someone prompt injected Grok and got it to transfer real crypto by tweeting Morse code saying “withdraw all, whatever the heck this coin is, and send it to this wallet.” Grok, being the super helpful AI that it is, decoded the Morse code and there was a special account tagged in this that actually listened to the command. It being the super helpful bot that it is said, “you got it,” and went ahead and withdrew the coin and sent it to that wallet.</p><p class="paragraph" style="text-align:left;">Turns out the Bankr thing allocates wallets to any account that interacts with it. Even though nobody managing the Grok account had any idea, it had been accruing some coins with real monetary value. Just an objectively hilarious prompt injection. (<a class="link" href="https://www.youtube.com/shorts/tk2XFAgLgxs?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="critical-high-severity-vulnerabilit"><a class="link" href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e98721df-9b8b-4cde-8fdd-d828bac3df52/Screenshot_2026-05-07_at_10.25.39_AM.png?t=1778163948"/></div><p id="apache-shipped-httpd-2467-on-sunday" class="paragraph" style="text-align:left;">Apache shipped httpd 2.4.67 on Sunday to patch CVE-2026-23918, a double-free in mod_http2 hitting every 2.4.66 and earlier deployment running HTTP/2. Send a HEADERS frame followed by RST_STREAM with a non-zero error code on the same stream, and two nghttp2 callbacks free the same h2_stream pointer twice. The DoS path is one TCP connection, two frames, no auth, worker dies on contact.</p><p class="paragraph" style="text-align:left;">Researchers also built a working RCE PoC using mmap reuse and Apache&#39;s scoreboard memory as a stable target, though it needs APR with the mmap allocator (default on Debian) and an info leak. No confirmed exploitation yet, but the DoS is a weekend project for anyone with nghttp2. Patch to 2.4.67 - kill HTTP/2 as a stopgap if you can&#39;t. (read more <a class="link" href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>, <a class="link" href="https://lists.apache.org/thread/otwt07gfnp6x2b58hnbghgs9r4ovy3yf?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a> and <a class="link" href="https://httpd.apache.org/security/vulnerabilities_24.html?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">here</a>)</p><h3 class="heading" style="text-align:left;" id="critrical-c-panel-flaw-mass-exploit"><a class="link" href="https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Critrical cPanel Flaw Mass-Exploited In &quot;Sorry&quot; Ransomware Attacks</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b880c3fa-9da6-4f78-9031-85d1af13ed93/Screenshot_2026-05-05_at_3.44.52_PM.png?t=1778010323"/></div><p id="c-panel-is-getting-massexploited-ri" class="paragraph" style="text-align:left;">cPanel is getting mass-exploited right now, and honestly … of course it is. This thing has been around forever, like mid-90s forever, and it’s still sitting all over the internet. CVE-2026-41940 is getting hammered by ransomware crews. The &quot;Sorry&quot; gang is having a field day with this one, with Shadowserver reporting at least 44,000 compromised IP addresses since Thursday. The attackers are dropping a Go-based Linux encryptor that slaps a &quot;.sorry&quot; extension on files and uses ChaCha20 encryption with RSA-2048 key protection.</p><p class="paragraph" style="text-align:left;">This isn&#39;t some small-scale operation either - hundreds of compromised sites are already showing up in Google searches. Emergency patches dropped this week, so if you haven&#39;t updated your WHM/cPanel installations yet, now would be a really good time. The exploitation started back in February as a zero-day, so this crew has had plenty of time cause damage. (<a class="link" href="https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="microsoft-defender-wrongly-flags-di"><a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow"><b>Microsoft Defender Wrongly Flags DigiCert Certs As Trojan:Win32/Cerdigent.A!dha</b></a></h3><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bd810f3b-e882-409e-bc6d-3787df0cfc2a/Screenshot_2026-05-05_at_3.50.36_PM.png?t=1778010652"/></div><p class="paragraph" style="text-align:left;">This DigiCert situation was kind of wild because it was two problems stacked on top of each other. First headline everyone saw: Microsoft Defender started flagging legit DigiCert root certs as malware, even removing them from systems in some cases. Massive false positives. That alone is chaos.</p><p class="paragraph" style="text-align:left;">But underneath that, there was a real incident. DigiCert had a breach where attackers got access through - are you ready? You’re not going to believe it… - a customer support employee. Same playbook again. Not some AI super hacker. Just calling support, pretending to be someone they’re not, and getting access. From there, they were able to generate initialization codes for a small number of code signing certs, some of which were then used to sign malware.</p><p class="paragraph" style="text-align:left;">So now you’ve got this weird chain reaction. Real breach leads to real abuse of certificates, which leads Microsoft to start flagging things aggressively, and now you’ve got legit certs getting nuked. Some people in my live stream chat got their days ruined for this one. Rough! (<a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><h3 class="heading" style="text-align:left;" id="pcp-jack-cloud-worm-evicts-team-pcp"><a class="link" href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</a></h3><p class="paragraph" style="text-align:left;">There&#39;s some drama brewing in the malware scene. A new framework called PCPJack is stealing creds from exposed Docker, Kubernetes, and MongoDB instances, but also actively kicking out TeamPCP infections from the same systems. SentinelLabs thinks this might be the work of a former TeamPCP member who went rogue and decided to start their own operation. &quot;Fine, I&#39;ll start my own criminal enterprise!&quot;</p><p class="paragraph" style="text-align:left;">PCPJack is pretty complex for malware beef. It&#39;s exploiting fresh CVEs like the React2Shell flaw and some WordPress vulnerabilities, then exfiltrating stolen creds to Telegram channels using proper encryption. The lateral movement game is strong too - it harvests SSH keys, enumerates Kubernetes clusters, and spreads through internal networks. What&#39;s wild is how methodically it scrubs TeamPCP artifacts - processes, services, containers, etc. It&#39;s like watching one hacker crew actively evicting another from compromised systems. Professional courtesy is clearly dead. (<a class="link" href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/?utm_source=www.vulnu.com&utm_medium=newsletter&utm_campaign=vulnerable-u-167" target="_blank" rel="noopener noreferrer nofollow">read more</a>)</p><hr class="content_break"><h1 class="heading" style="text-align:left;" id="miscellaneous-mattjay">Miscellaneous mattjay</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d95d847f-dec1-48aa-9607-357feffdb116/Screenshot_2026-05-07_at_6.12.44_PM.png?t=1778195568"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60daecbc-df03-4c3a-b33d-b641fcf26b59/Screenshot_2026-05-07_at_6.13.51_PM.png?t=1778195634"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/eafee781-bf80-421c-815f-169fb708cc96/Screenshot_2026-05-07_at_6.14.17_PM.png?t=1778195660"/></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="parting-thoughts">Parting Thoughts:</h2><p class="paragraph" style="text-align:start;">Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. <i>Community</i> is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you. </p><p class="paragraph" style="text-align:start;">Stay safe, Matt Johansen<br>@mattjay</p></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
