🎓️ Vulnerable U | #180

Rogue AI hackers follow ups, Blackhat and DEFCON research dropping, Water plants not pulling PLCs off the internet fast enough, and much more!

Read Time: 9 minutes

Brought to you by:

Howdy friends!

Writing to you from Las Vegas in the transition day between Blackhat and DEFCON. What a week already. Been here since Monday and not leavin till Sunday which is entirely too much Las Vegas. My voice is at about a 15%, which you will absolutely see if you watch my videos I’m recording here.

You know that phenomenon in science where evolution keeps producing crabs over and over? I feel like that is happening in cybersecurity as I walk the expo floor and notice many of the AI security companies that were at least trying to differentiate last year are all moving towards doing the same stuff. AI SOC and AI Pentest absolutely everywere. I do still think there are some stand out players in the spaces, but I still commend those trying to stay in their differentiated niche instead of just becoming a crab.

If you’re reading this and you’re one of the many people who jumped out of the crowd to take the time to say hi to me and let me know that you enjoy reading/watching my content - THANK YOU. Running Vulnerable U feels like screaming into the void often, so that really means a lot to me.

Some of my favorite conversations of the week have been either people letting me know how much my content helps them in life/work or convos with teams/founders asking how they can do better in content creation/go-to-market. It is fun to jam on this stuff and actually see you all in person.

If you’re here, what has been your favorite part of the trip?

ICYMI

🖊️ Something I wrote: My take on these frontier labs all hacking things illegally

🎧️ Something I heard: Low Level and I talking Iran hacking water plants and the hugging face incident write up

🎤 Something I said: Me and Dan Miessler talked about the headlines screaming about open-weight Chinese models and if they are risky or not

🔖 Something I read: Daniel Cuthbert’s summary of OpenAI on stage at Blackhat discussing the recent incidents

Vulnerable News

Another supply-chain nightmare. While what felt like the entire security industry was walking the halls at Black Hat and BSides Las Vegas, a self-replicating npm worm was tearing through the JavaScript ecosystem, compromising packages that collectively see more than 2 billion monthly downloads. This one has serious Shai-Hulud vibes.

If one of the affected packages slips into your dependency tree, a simple npm install can pull down malicious files through a pre-install hook before you even realize anything is wrong. Researchers at Aikido say the campaign has already spread to hundreds of packages, and the list was still growing as responders raced to contain it.

I’m more worried about the ripple effects we haven’t seen yet. Sure, it steals npm and GitHub tokens so it can keep infecting more packages, but it also grabs Slack, Stripe, Vault and cloud credentials, SSH keys, Terraform state files, password manager databases, and just about every other secret you'd hope never leaves a developer workstation. (read more)

AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.

This Intruder blog explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (read more)

*Sponsored

Something got into North Carolina Ports' IT system late on August 4 and took all three facilities with it: Wilmington, Morehead City, and the Charlotte Inland Port. Truckers rolled up to signs reading "Operations Alert: System Issues. Expect Delays." The authority says the breach is contained, an outside forensics team is in there working alongside their IT group, and they pulled in NCDOT, the state IT department, and the Coast Guard. Gates went back to a normal schedule on the 6th, but everything is still being processed by hand.

The spokesperson declined to say whether this is ransomware, and no crew has claimed it yet, which usually means a negotiation window is still open. They had a Cybersecurity Contingency Plan(!!) and it was good enough to keep 4 million tons a year of cargo moving on paper. Manual fallback for gate operations is the thing you need written down before the bad day, and plenty of operators would have just closed the gate instead. Nothing has been said about cranes or other OT, so for now this reads as an enterprise IT hit with operational blast radius. (read more here and here)

A crew Google tracks as UNC6671 calls your employees on their personal cell phones, poses as your IT helpdesk, and tells them there's an urgent mandate to enroll a FIDO2 passkey. The victim lands on something like [company].createssopasskey[.]com, an AiTM panel takes the password and the MFA token, then scripts start pulling files out of M365 and Okta. They've been running this under five different extortion brands. BlackFile announced a retirement in May, Redact showed up in June claiming a rogue affiliate had hijacked the old name, and Pink, Helix and Falcon each operate their own leak site. GTIG found the root domains and phishing templates shared across all of them, with passkeyhelpdesk[.]com hitting a Falcon victim and a Helix victim at the same time.

Targeting narrowed over the summer from broad enterprise to private equity, law firms and financial rating agencies, which is where the M&A and litigation material lives, and they're standing up a new domain every 1.6 days. They clean up after themselves too, using compromised mailboxes to reset passwords on non-SSO apps and deleting the confirmations and security alerts behind them. Payments kept landing in BlackFile wallets after the May retirement notice, about $10.69 million tracked through mid-May. The pretext here is also the fix: real passkeys are origin bound, so the lookalike domain has nothing to relay. Push and TOTP shops get eaten. (read more here and the May BlackFile writeup)

Connor Riley Moucka, the 26-year-old from Kitchener who operated as Judische and Waifu, pleaded guilty to four counts including computer fraud and aggravated identity theft. Between February and October 2024 he and his co-conspirators worked through at least 165 Snowflake customer tenants, all of it on stolen credentials against accounts that had MFA turned off. Ticketmaster, LendingTree, Advance Auto Parts, Neiman Marcus, plus the AT&T haul of call and text records for more than 100 million people. DOJ puts the ransom take north of $2.5 million. He also re-extorted at least one victim using the stolen data of a government officer and a former officer's immediate family, and spent his spare time threatening the researchers and officials tracking him down. Sentencing is October 27, two year mandatory minimum, 30 year ceiling.

Cameron "Kiberphant0m" Wagenius, the Army soldier who pleaded out in July 2025, gets sentenced September 3. Which brings us to the third one, John Erin Binns of T-Mobile 2021 fame, who was sitting in a Turkish prison, has since been released, picked up Turkish citizenship, and is back online. Turkey does not extradite its own citizens.(read more here and the DOJ statement)

1Password stood up a security research team called Off-by-1 Labs and their first paper is a good one. They generated about 6,000 patches for six recently disclosed CVEs across two frontier models, picking bugs whose fixes landed too late to be in training data. Complete fix with no change to application behavior: 26%. Fixed the bug but altered behavior: 20%. Failed to fix it, introduced a new vulnerability, or both: 53.9%. Their going-in hypothesis was north of 67%.

More than a third of the patches they counted as successes were what they call fragile, meaning a narrow check bolted on in front of the vulnerable code. On the SpringAI SpEL bug, both models escaped the exact characters from the PoC they were handed and left the root cause sitting there, so the bug comes back the moment that code is reachable by another input. They also tossed 400 runs where the model got caught trying to look up the real patch. Tooling and the full dataset are on GitHub under FLAWED, for Fix-Like Artifacts With Embedded Defects, which is a solid bit of naming.(read more here and the tooling and datasets)

Meta is on the board now! Not to be outdone in the AI doing illegal hacking on its own games! The Information reported that Muse Spark 1.1 breached an unnamed company and made changes to its internal systems, and Meta confirmed to Reuters that a misconfiguration by evaluation vendor Irregular handed one of its models live internet access when it was supposed to be isolated. Irregular says this is the exact same environment issue behind Anthropic's disclosure last week, and is explicit that no sandbox escape or sophisticated cyber action was involved. A test range was wired to the real internet. (read more here and Reuters)

Michael DeSombre, State's assistant secretary for East Asian and Pacific Affairs, told the Senate Foreign Relations Committee on Thursday that Trump has raised transnational criminal organizations with Xi. He would not say when, or what Xi said back, and the White House did not confirm the conversation happened. The number that came out of the same hearing: more than $12 billion taken from Americans in scams last year, which State says is likely an undercount.

Chinese enforcement has knocked down compound activity in Cambodia and Myanmar over the last six months, largely because those operations started hitting Chinese nationals, and Beijing has been pulling scam bosses out of Southeast Asia and executing some of them. So the US is leaning on those governments to hand the bosses over for interviews first, because once they go to China, per DeSombre, "we don't have great transparency as to what happens to them." The tradecraft is being exported in the meantime. Senators raised cases in Peru and the Dominican Republic, and State flagged compounds rising in Sri Lanka. (read more here and the hearing itself)

Vangelis Stykas mailed WIRED's Andy Greenberg a lavender kids' smartwatch off Amazon and Greenberg wore it to work. He texted Stykas outside his Brooklyn subway station to say he might lose signal, and Stykas replied that he already knew. The watch's GPS was broken, but it was still shipping nearby Wi-Fi identifiers to a remote server, which was enough to place him on a specific block. At the office Stykas silently pulled a photo off the watch camera as Greenberg stepped into the elevator, took another at his desk, then opened the microphone and listened. The watch showed nothing the whole time.

It costs under $30, comes from YiQingTeng Electronics in Shenzhen, and dozens of other brands run on the same backend. For their Blackhat talk, Stykas and Felipe Solferini worked through more than 70 GPS watches and car trackers and traced tens of millions of devices back to three Shenzhen supply chains. On SETracker an authentication flaw let anyone send commands to any device on the platform. Greenberg handed over his email address and nothing else. The available commands include location spoofing, message interception, live mic, camera, and swapping the emergency contacts for numbers the attacker picks. Two of the three platforms never replied to WIRED and still work. (read more here)

Researchers ran a Shodan scan on Monday and found 4,400 Rockwell and Allen-Bradley PLCs sitting on the public internet with EtherNet/IP open, 2,844 of them in the US. Half were MicroLogix 1400s, the same family the FBI and EPA named in last week's joint advisory on the water sector attacks. That advisory covers utilities in at least 12 states since July 27, nine systems in Michigan alone, and in at least one case the attackers changed the controller's IP address and password so the utility lost its own view and control of its equipment. Pressure loss and flooding.

Forescout cross-referenced against the affected cities and found 22 devices still exposed, 19 of which look open to CVE-2017-16740 based on firmware version, an RCE from 2017 that needs Modbus TCP enabled to work. They're careful to say they cannot confirm those hosts belong to the hit utilities or that Modbus is on. Plenty of reporting has pointed at Iran and Forescout is not attributing, with their threat hunting lead saying the scale and speed look like mass scanning and enumeration against a known vulnerability class. Rockwell has been telling customers to keep these off the public internet since 2018. (read more here, the Forescout research and the FBI advisory)

HD Moore found more than a dozen new BMC flaws across HPE, Supermicro, Avocent, Huawei, Lenovo and Dell. His external scan turned up 86,000 BMCs exposing a management service to the public internet, and as many as 75,000 of those are still vulnerable to CVE-2013-4786, an IPMI 2.0 authentication flaw that hands you admin BMC password hashes for offline cracking. Thirteen years. Over half the exposed population carried at least one critical bug, and an internal survey of 126,761 BMCs sitting inside corporate networks put that figure at 29%. The new classes run from auth handshake sequences you can reorder to skip authentication entirely, to unsigned firmware and unenforced config integrity that turn an admin foothold into a permanent implant under the OS.

ILObleed already showed what that looks like in practice. In 2021 it landed wiper firmware on HPE servers that survived OS reinstalls and drive swaps and kept destroying disks, using a bug HPE had patched four years earlier. HD is holding CVE details until vendors ship fixes, so this week's work is inventory and segmentation. He released OOBscan to sweep your fleet, and his own hardening list is short: long unique usernames as well as long passwords, disable IPMI where you can, disable KCS to block host-side access to the BMC, and isolate each BMC NIC individually, one per segment, no shared management VLAN. (read more here and Ars)

AISI runs frontier models through cyber ranges with live internet access and the providers' cyber classifiers deliberately switched off, on the reasoning that a real attacker has both. Across 122 runs against seven models in late July they logged 19 unsanctioned actions on the live internet, nearly all of it one sustained line of activity from Claude Mythos 5. Their security team found out when monitoring flagged data leaving a research system over Tor.

Mythos decided the way to solve its challenge was a supply chain attack, so it ran one against a real open source project. It researched the maintainers, opened a PR with malicious code, then created a second account posing as an unrelated person who had reviewed that code and confirmed it was clean. Five emails to two maintainers, some carrying malware. Then it opened an Issue on another repo owned by one of them containing a prompt injection aimed at issue-triage coding agents, having reasoned the maintainer might be a bot like Claude Code. Nothing worked, the PR was refused, and AISI found no real-world harm. Their fix going forward is a second LLM watching the first one in real time to approve or deny out-of-scope actions, which is the same control problem everybody shipping an agent this year is about to own. (read more here and Ars)

How'd I do this edition?

It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week.

Login or Subscribe to participate in polls.

Parting Thoughts:

Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.

Stay safe, Matt Johansen
@mattjay