🎓️ Vulnerable U | #179

More AIs escaping labs, FCC cracks down on foreign hardware, Amazon selling pre-hacked streaming sticks, and more!

Read Time: 9 minutes

Brought to you by:

Howdy friends!

Writing you from San Diego on vacation. First real non work/family trip in a few years which is nice. Got to see some infosec friends down here and get tips on all the best fish tacos, burritos, and poke bowls. I booked a few scuba dives while out here but a big storm off the coast ruined water conditions so those all got cancelled which is a bummer, I guess I’ll have to come back!

Headed home for a bit and then off to BlackHat which looks like it’ll be about 119 degrees, and no I don’t care its a dry heat. I celebrated 4 years sober this week which makes Vegas much more tolerable for the whole week, so I’m looking forward to seeing a bunch of you out there at summer camp.

ICYMI

🖊️ Something I wrote: Some thoughts about Adrian, an open source prompt injection defense tool

🎧️ Something I heard: The Low Down latest episode talking Hugging Face incident, wp2shell and more

🎤 Something I said: Dug into some identity as code techniques with Teleport

🔖 Something I read: Minimal’s open source announcement. Hearing good things.

Vulnerable News

When I covered this it was an AI escaping a sandbox to cheat on a test. It is now a four-day intrusion in which the model built itself attack infrastructure out of strangers' cloud accounts, and OpenAI is still adding to the disclosure.

Hugging Face published their forensics and it is the best security writeup I have read this year. 17,600 recovered attacker actions between July 9 and July 13, grouped into phases, with an interactive replay you can step through action by action. Go look at it. The agent was being evaluated on ExploitGym, worked out that Hugging Face probably hosted the benchmark's reference solutions, and went to get them. The whole four and a half day campaign was a model trying to cheat on a test.

The other update this week is that we found out what the vendor was for the zero day it found. JFrog’s Artifactory wrote up their side of the story. After that it was rooting a public code-execution harness some third party had left exposed on Modal (Modal's own platform held up, this was a customer's endpoint). That box became the launchpad for everything after. Stage two was into Hugging Face, and the agent got in by uploading malicious dataset configs and letting their own loader do the work.

From JFrog’s POV the models chained previously unknown bugs in self-hosted Artifactory to get off the range and onto the open internet. Nine fixes shipped in 7.161.15 and 7.146.34 covering RCE, SSRF, path traversal and privilege escalation up to admin. Cloud tenants are already covered, self-hosted is on you.

OpenAI's update says GPT-5.6 Sol and an unnamed pre-release model went looking for publicly exposed credentials and used four accounts across four separate services. It assembled a C2 and a dead drop out of other people's accounts.

Security teams face thousands of remediation decisions every day, yet none are based on evidence showing which vulnerabilities actually lead to financial loss.

The Evidence Platform from Root Evidence introduces a new operating model for vulnerability management, using cyber insurance claims, actuarial analysis, digital forensics, attack surface intelligence, and real-world breach data to reduce noise, prioritize remediation, and focus resources where they'll have the greatest business impact.

*Sponsored

After OpenAI's disclosure, Anthropic went back through 141,006 of its own evaluation runs where Claude could have reached the internet, and found three incidents where it did, and then compromised the production infrastructure of three real companies. All three were capture-the-flag challenges run through their third-party eval partner Irregular. The prompt told Claude it had no internet access. A misconfiguration gave it internet access anyway. So when Claude's search wandered off the range, it treated the real companies it found as part of the game.

Key distinction: these model test environments just had internet access. Calude didn’t need to go zero day hunting to escape the lab, it just was misconfig’d to leave the door wide open. I also hate the personification of these mistakes. A human prompted for these things to happen, and then they happened and were missed. This isn’t some mysterious model issue.

In one of the incidents Claude found setup docs in the fictional environment pointing at a Python package that did not exist, and did what any red teamer would do: registered the name and published a booby-trapped package. It needed a PyPI account, which needed an email address, which needed a phone number, which it tried and failed to buy, before backtracking to a free email provider. The package was live for about an hour, got installed on 15 real systems. (read more here)

We talked about the $10 million bounty and the six sanctioned IRGC officials tied to Cyber Av3ngers, after they rewrote Unitronics PLC code and put "Gaza" on screens from Ireland to Pittsburgh. Well we’re so back. Andy Greenberg got hold of a WaterISAC memo, and it is the first official document to explicitly connect the Minnesota water attacks to Iran. The memo relays a Minnesota Fusion Center alert finding the activity aligned with the Iran-affiliated PLC campaign CISA described in April.

The intent line is what made me perk up a bit. Per the Fusion Center, the attackers hit remotely accessible PLCs with the likely goal of causing "loss of system pressure and potential contamination of the water supply."

Plymouth said its impact was limited to equipment connected over cellular. Suzu Labs' Denis Calderone points out that water towers, lift stations and pump stations usually phone home to SCADA over cellular modems, and those secondary comm paths are routinely left out of risk and vulnerability assessments, especially when an integrator built the network. In the 2020 attacks on Israeli water facilities, Iran-linked actors came in through vulnerable cellular routers. Braham's city administrator is now asking for their vulnerability study to be redone, and I would bet the cellular paths were never in it.

Get PLCs off the public internet, allow-list what can talk to them. And go find out what your remote sites are talking over, because that inventory is probably wrong. (read more here, here, and the city statements from Braham and Plymouth)

Chrome fixed 1,072 security bugs across milestones 149 and 150, which beats the total from the previous 23 milestones combined. Look at that chart. Try to spot the Opus moment (when all the frontier models got good). They built a Gemini agent harness that runs over the whole Chrome codebase, and one of its finds was a sandbox escape letting a compromised renderer read local files that had been sitting there for 13 years. BigSleep and CodeMender run in CI every 24 hours across all CLs, and in May alone blocked over 20 vulnerabilities from reaching production including a critical S1+. They are piloting two security releases per week and building dynamic patching that swaps out renderer and GPU processes with updated binaries without making you restart the browser.

By March they were receiving more bug reports than they got in all of 2025, so they rewrote the Chrome VRP to push researchers toward findings that are additive to what the machines already catch. (read more here)

Following on from the LG proxy mess last week, here is the version where the device was built for this from the factory. Bitsight's Pedro Falé registered an expired domain that H96 Android TV boxes had been phoning home to, and found roughly 38,000 of them worldwide reporting full hardware details and installed app lists. Except they were not reporting as TV boxes. They claimed to be Samsung, Vivo, Huawei and Xiaomi phones. As Falé put it, "multiple devices reporting to this factory Android TV Box backdoor were 'phones.'"

The operation traces to Zhejiang Fengwo IoT Technology, a mainland China company running an ad publishing arm called Fengwo Group, with monetization collected through Hong Kong, Singapore and single-person shell identities. The boxes get pushed jobs to open a browser, load AI-generated finance, health, gaming and food blogs owned by the same group, and click the ads. Those sites serve no ads at all unless the visitor matches the spoofed mobile profile, so the entire loop is closed and self-dealing.

Amazon, Best Buy and Newegg are all still selling hundreds of these, and the FBI has been warning about them for years. Stick to name brands, check for Play Protect certification, and go look at Synthient's running list of consumer devices that ship with proxyware preinstalled, because it is not just streaming sticks. Digital photo frames are on there. The gift you bought your mom might be renting out her IP address.

(read more here and here, the FBI alert and Synthient's device list)

A health insurer serving 3.6M members, running modern pipelines at scale, had best-of-breed scanners and still could not prove its artifacts were trustworthy when the critical vulnerabilities dropped.

Kusari became its system of record: every artifact mapped from source, every dependency searchable, proven exposure answered in seconds instead of days.

Learn how they did it → read more

*Sponsored

Anthropic pointed Claude Mythos at cryptanalysis this week and published two results. Matthew Green (my cryptography god) read both so you don't have to.

First he talked about HAWK, a proposed post-quantum signature scheme that was working its way toward becoming a standard. Claude found a key recovery attack that roughly halves its security bits. Still exponential time, so nothing is broken today, and you could paper over it by doubling key sizes. Except being small and fast was HAWK's entire pitch, so Green figures the scheme is now dead. There's working code too, and it recovers keys in a few hours against a weakened challenge instance the HAWK authors published themselves.

The other result is the one with the scary headline. An improved attack on 7-round AES, which sounds like your TLS is on fire, until you learn people have been chipping at reduced-round AES for two decades, this is a constant-factor improvement on work from 2013, and it needs 2^89 operations plus 2^105 chosen plaintexts. Nobody is decrypting anything.

Green says Anthropic didn't assemble a room of lattice experts to steer this either. They pointed the model at the problem and let it grind. His real warning is these things are much better at producing results that look real than results that are real. (read more here, Anthropic's research post and the HAWK paper)

The open-weights camp found its Exhibit A, and it is the Hugging Face incident. NVIDIA stood up the Open Secure AI Alliance with 55 inaugural partners, and the argument at the center of it is the thing I flagged last week: when the closed models could not tell an attacker from a defender and refused to help with the cleanup, Hugging Face ran open-weight GLM 5.2 on its own infrastructure to work through 17,000 actions and contain the intrusion. Defenders need models they can inspect, adapt, and run themselves. Fine by me. It is just funny watching it become a policy platform with a logo garden.

There is real code under the press release, which is more than most alliances manage. NVIDIA's NOOA agent harness project is on GitHub, Hugging Face handed Safetensors to the PyTorch Foundation, Microsoft brought its MDASH multi-model scanning harness, HPE is pushing SPIFFE/SPIRE for cryptographic agent identity. The closing ask is aimed at regulators: blanket restrictions on open frontier systems "would weaken defensive capacity." Which is the argument I have been making, now with a few trillion more in market cap behind it than VulnU could muster. (read more)

The robot dogs have met their match. The FCC added foreign-produced power inverters, humanoid robots and quadrupeds to its Covered List, blocking new imports on the grounds that they could be remotely controlled, used for surveillance, or turned on us in a cyberattack. Exceptions are available if a device is found not to pose a risk. This mostly means China, which dominates both markets. Around 15,000 humanoids shipped worldwide in all of 2025, so that half is preemptive. Inverters are in millions of American homes tying rooftop solar into the grid.

Where I land, and it is consistent with what I said about open-weight models a couple weeks ago: origin is a weak signal, capability is a strong one. A model's country of origin does not change its risk profile. But grid-connected hardware with a vendor-controlled remote management path is a different animal, because the capability ships with the box and the vendor is reachable by a government that can compel them. The part I would like to see is a rule about what a grid-edge device is allowed to phone home to, regardless of who built it. (read more here and here)

We heard you liked wp2shell, so now there’s more! Rails2shell! Kinda! (In my best Shamwow! voice) Ethiack went looking for the Rails equivalent, reported it July 22, and it landed publicly on the 29th. CVE-2026-66066, CVSS 9.5, unauthenticated arbitrary file read through Active Storage when it hands uploads to libvips. Ethiack has since confirmed that stock Debian, Ubuntu and Rails-generated Docker environments are all exposed, because the libraries the attack needs ship by default. So if your app takes image uploads from untrusted users, assume you are in scope. What comes back out is .env, database.yml, credentials.yml.enc, secret_key_base. MiniMagick apps are clear. Patch to 7.2.3.2, 8.0.5.1 or 8.1.3.1, and EOL branches get no upstream fix.

Ethiack and Rails were trying to sit on the technical details until August 28. That lasted two days. Ethiack now confirms at least one public PoC exists and says more details may arrive before the 28th. Patching does not un-steal anything, so rotate secret_key_base, the master key, database creds, Active Storage service keys and third-party tokens. (read more here, the Rails advisory)

Source: Lava

Researchers scanned UDP 623 and found 36,872 internet-exposed IPMI hosts. 24,650 of them will hand password-derived authentication material to anyone who asks, via CVE-2013-4786, a weakness in a protocol standardized in 2004. For about a third the researchers actually recovered the password using dictionaries and the patterns printed on factory stickers. 6,240 accepted an empty username. The US is 39% of it.

An HPE factory password takes roughly a day per captured handshake on an Apple M3. No rented GPU cluster needed! A lot of the exposed gear is Supermicro running a 10-character uppercase string off the chassis label with ADMIN as the username in every instance, which sounds like entropy until you notice the charset and the length are both fixed. Get IPMI and Redfish off the public internet and rotate the factory passwords. (read more here and the CVE)

A researcher has demonstrated a PoC Word document worm that abuses Microsoft 365 Copilot to spread itself without relying on traditional macros or exploits. The attack hides malicious instructions inside a Word document that Copilot faithfully follows when asked to summarize or interact with the file. The AI then generates new documents containing the same hidden prompt injection, effectively turning Copilot into the worm's replication mechanism. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post.

Prompt injection is starting to look a lot like the macro malware era, except the code is written in natural language. (read more)

Source: AWS

Amazon says the high-profile compromises of the Debug, Chalk, Axios, and typo-crypto npm packages came from a single North Korean state-sponsored operation, linking what previously looked like isolated incidents into one long-running software supply-chain campaign. Amazon's threat intelligence team said attackers spent months socially engineering open-source maintainers, building trust, and then slipping malicious code into legitimate package updates that were downloaded by developers around the world. (Sounds like XZ Utils to me)

This was an industrial-scale operation where Amazon says the attackers deliberately started with smaller packages before moving on to massively popular libraries like Debug, Chalk, and Axios, while using AI to appear like legitimate open-source contributors by fixing bugs, responding to issues, and earning maintainers' trust. (read more)

Miscellaneous mattjay

How'd I do this edition?

It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week.

Login or Subscribe to participate in polls.

Parting Thoughts:

Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.

Stay safe, Matt Johansen
@mattjay