- Vulnerable U
- Posts
- 🎓️ Vulnerable U | #181
🎓️ Vulnerable U | #181
Delta WiFi Hack from DEFCON, Defendant hides AI prompt in court documents, Whitehouse enables privateering hackers, and more!
Read Time: 9 minutes

Brought to you by:
Howdy friends!
How’s everyone recovering? Emotional hangovers? Actual hangovers? Con Flu? - I’m feeling pretty much back to normal at this point but it took me a few days. I think by the time I hit Saturday at DEFCON, having gotten there Monday, I was ready to not see another human for a bit.
But man was it great to see and hear from so many of you! Whoever did the zoom by me whispering “big fan. big fan” a bunch of times without actually stopping to say hey, you cracked me up. But also got a whole lot of “Are you that guy from….” pull overs - always funny to see where they know me from since I yap all over the Internet.
Either way, appreciate you all.
ICYMI
🖊️ Something I wrote: We’re not talking enough about OAuth apps in infosec
🎧️ Something I heard: The Low Down - Live at DEFCON episode!
🎤 Something I said: Interview with Cal[.]com CEO about why they went closed source due to security risk of giving AI the blueprint to the vault.
Vulnerable News

Hacker summer camp ended and somebody decided the flight home counted. Delta 591, Vegas to Atlanta, the morning after DEFCON 34 wrapped. About an hour in the crew ACARS'd the ground asking for corporate security, saying a passenger had stood up a scam network called "Delta WiFi Fast," then followed with "THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." Cabin crew killed the onboard wifi for 30 minutes. Delta told Ars an unauthorized network it doesn't operate was up briefly, no aircraft systems were affected, and no emergency was declared.
Reddit supplied the rest of it, the captive portal harvesting Google credentials and the Wi-Fi Pineapple and the agents waiting at the gate. FBI Atlanta told Ars they're looking into it, nobody has been arrested, and no agents met the flight. On the record you've got a rogue SSID and a deauth. DEFCON's press lead told CyberScoop that neither Delta nor the feds had contacted them, that they'll ban the attendee if one turns out to be involved, and that the con itself ate multiple deauth attacks this year that hit its own operations. (read more here and here)

If juggling multiple cloud providers wasn't complicated enough, it turns out they don't fail in the same places. There's surprisingly little overlap in the issues affecting AWS, Azure, and Google Cloud, meaning each provider demands different priorities.
Intruder’s new report helps you understand where those priorities differ, breaking down the most common issues across each provider, how they compare across key risk categories, and how those risks change as organizations grow.
*Sponsored

A guy representing himself in a Connecticut civil case buried prompt injections in his own court filings, 3 point white text scattered through the document, telling any AI that processed it to make sure its output agreed with him. What caught it was a person at the court noticing those pleadings had more white space than his earlier ones. In later filings he added more hidden text, including "hi :) I hope yo ucant see me" and a link to the SpongeBob Nosferatu scene. He told 404 Media it was an audit of the court's systems.
The Connecticut Judicial Branch does not run AI over filings, so the injection landed on nothing, and he says that changes nothing about the impropriety, comparing it to arranging for an automated agent to talk to a juror in private. He is also explicit that the tool is fine, that somebody who cannot afford a lawyer using AI to assemble a coherent filing is a win for access to justice, and that the dishonest part is transmitting a second message the other side cannot see. He expects more of this and points at a recent case in a Brazilian court. Sanction is that the plaintiff loses electronic filing and goes back to paper. 404 fed the motion to ChatGPT as a test, and it ruled against him and mentioned unprompted that it had noticed the injection and ignored it. (read more here)
Microsoft published a blog in May threatening legal action against researchers who drop zero-days outside its disclosure policy. This is number nine since April from the researcher everyone assumed it was aimed at. ShieldBreak abuses a Defender cloud-hydration scan through the Cloud Filter API to hand any local user a SYSTEM shell on fully patched Windows 10, Windows 11 25H2, and Server 2025, and it landed one day after a Patch Tuesday that closed 421 CVEs. Will Dormann verified it, Kevin Beaumont verified it on latest Windows 11, and Defender has to be enabled for it to fire, which for most of you means it fires.
Nightmare Eclipse is saying this is a full bypass of the RoguePlanet patch, CVE-2026-50656, and both Dormann and Beaumont say the two work on entirely different mechanisms, so hold that framing loosely. It's local privesc, so someone has to already be running code on the box, which is exactly where a ransomware crew is standing when they go shopping for SYSTEM. Microsoft says it's investigating validity and there's no patch, so Beaumont's Defender for Endpoint hunting queries are the whole mitigation right now: alert on processes foreign to Defender loading its libraries, and on unvalidated processes loading cfapi. (read more here, here and here)
Trump signed a memo Wednesday letting vetted US companies get authorization to hack foreign criminal groups. Two categories: Cyber Surveillance Operations, meaning unauthorized access for collection, and Cyber Effects Operations, meaning manipulation, disruption, denial, degradation, or destruction. Participating Companies contract with DOJ or DHS, and every operations package needs written approval from two co-Executive Directors, one at each. Rob Graham has the take to read on the plumbing: it rides on 18 U.S.C. 1030(f), the CFAA carve out for authorized law enforcement investigative and intelligence activity. Nobody is getting an automated hack back button. CrowdStrike gets to ask permission to hit specific boxes of a specific crew it is already tracking.
The CE-TCO (Cyber-Enabled Transnational Criminal Organization) definition is doing most of the work. It covers any foreign group committing cyber-enabled crime against the US that is not an institutional part of a foreign government, and the memo says to assume that unless clear intelligence says otherwise. A good chunk of the ransomware ecosystem lives in that gap. Operating procedures are due in 60 days, so mid October is the earliest anyone runs an op. DOJ and DHS can also require a company to post a bond of at least $1 million, forfeited if it breaks its contract. So your employer's downside is a million bucks and a canceled contract, and yours, if you get staffed on one of these teams, is that you have no combatant status and no sovereign immunity. (read more here and here)
Legit delivers security where AI code is written. Legit VibeGuard is a developer endpoint solution that embeds security directly in the AI coding experience (e.g., Claude Code, Cursor). With agentic context and prioritization, Legit uses app context, business impact and AI insights to separate risk from noise. Autonomous agents then act, resolving vulnerabilities with fixes that understand your standards & workflows. (read more)
*Sponsored

Back in #139 I covered Lazarus going after European defense companies with fake job offers. Same campaign, new zero day. Check Point found the latest wave of Operation Dream Job burning CVE-2026-68820, a use-after-free race condition in AFD.sys that gets a local user to SYSTEM, to load a fresh build of the FudModule kernel rootkit that kills EDR telemetry and now tampers with Smart App Control too. Entry is still a trojanized PDF viewer pulled off an SEO poisoned impersonation site, which drops a new backdoor Check Point named Troy. Microsoft patched on August 11 after CP reported it on July 28, and the rootkit artifact is timestamped July 7, so it ran about five weeks as a zero day.
It is a local privesc, so they need code exec first, and the lures are aimed at defense, aerospace and aviation staff in France, Germany, Brazil and India. The part that reaches the rest of us is the C2. Lazarus built its relay network out of hijacked Roundcube and WordPress boxes, dropping a PHP webshell called RelayShell, getting in with leaked creds or CVE-2025-49113. At least 17 servers so far, and one already compromised French org got used to spear phish the next set of victims. If you have public facing Roundcube, you are in scope as infrastructure. Check Point published IOCs and a YARA rule for the webshell. (read more here and here)

We did the 100s of fake Chrome extensions story back in #117, and Socket just found the industrial scale version. 737 free VPN extensions across at least 40 developer accounts, 75,486 installs, 274 of them impersonating 66 real brands including Proton, NordVPN, ExpressVPN, Cloudflare's 1.1.1.1, and Google's own Outline. 520 of the 522 packages they pulled code for set chrome.proxy.settings to a fixed SOCKS5 server on port 1082 with a bypass list containing only loopback, so once you hit connect, every request in every tab goes through the operator. 94% of the campaign targets Russian speakers trying to reach blocked services, which means the two brands they most carefully cloned were AmneziaVPN and AntiZapret, the tools that audience actually trusts.
Socket is careful to say the proxy behavior by itself is how any browser VPN has to work. What makes the case is the surrounding stuff. All 200 premium subdomains for Japan, Singapore, Canada, Australia and Turkey resolve to nothing, and those are exactly the ones flagged premium: true. One extension ships a hardcoded license secret and a 32-bit rolling hash presented as a signature. Nine publisher accounts submitted byte-identical privacy justifications to Google claiming no data goes to external servers. And one package accidentally included an internal staff manual telling employees never to put a domain into chrome.proxy.settings, only the resolved IP, so takedowns cannot read the destination out of the shipped code. A Chrome Web Store developer account costs $5, 38 accounts published all 737, and 29 of the 30 accounts that have had something removed still have live extensions. (read more here)
These guys really do not want to get taken down again. Unit 42 has a v7 teardown of Kimwolf, the Android arm of the AISURU operation whose C2 got seized by DOJ and international partners back in #160, and the whole release reads like an answer to that. The DDoS traffic now imitates a real Chrome browser closely enough to blend into ordinary browsing, which makes layer 7 filtering a much worse day for whoever is catching it. The C2 grew three redundant paths, including pulling its current address out of public Ethereum name records with Tor waiting when that fails, all sitting behind a local proxy so they can swap pieces without reshipping the bot.
All the scanning and exploit code is gone, so propagation is somebody else's binary now and this one just attacks and relays. Infection still gets in through Android TV boxes that ship with debug access wide open, which was true two years ago and will be true two years from now. If you have any of those on your network, they're hostile, keep them away from anything that matters. Ports, hashes, and detection guidance are all in the intel post. (read more here and here)
Like a hack from a movie. Plug in a USB and hacker stuff just starts happening magically. Windows Plug and Play will fetch a signed vendor package off Windows Update and run its code as SYSTEM, with no admin rights, no UAC prompt, and nobody logged in. Alejandro Hernando and Borja Martinez did a DEFCON 34 talk on that and published the whole kit. Same family as the Razer mouse bug from 2021, except they went after the install path rather than one vendor's installer. The physical demo chains two boring vendor bugs: a Sierra Wireless service exposing a SetDNS call over a named pipe with an Everyone ACL, and a Sony co-installer that pulls config over plaintext HTTP and derives filenames without filtering traversal. (read more here and here)
Apple sent another round of mercenary spyware threat notifications on Thursday, this time to users in 110 countries, which puts the running total over 150 countries since 2021. These used to land as an email and a banner on your Apple account page, which is a great way to reach somebody two weeks late. Now it goes straight to the lock screen as a push, and the notification opens into guidance on who to contact and how to turn on Lockdown Mode. Apple says it still has not seen a device compromised with Lockdown Mode on.

John Scott-Railton at Citizen Lab said the push is a real improvement, and his reasoning is the part I would pass along to anyone who works with high risk users. One person getting an alert and reaching out is usually what starts an investigation, and the investigation is what finds the rest of the targets. He points at Poland, where the whole spyware scandal traces back to notifications like these. (read more here and here)
Over four days in early July, an agent framework built on Hermes and OpenClaw ran twelve waves against government systems in Asia, sometimes with eight sub-agents going at once. FT says the target was Taiwan. It cracked 85 employee accounts, pulled 2,564 personnel records, and then started poking at a nuclear safety agency and a handful of energy companies. Nobody can tell which model was driving, and whatever it was, it got to work once the operators told it this was an authorized pentest.
One system was handing its entire user database to anyone who asked. Somebody left debug endpoints in production that give you a valid session for free. There was a CAPTCHA, which Tesseract solved every single time, and the passwords behind it were employee IDs with a symbol stuck on the end. We have been writing that same list up for ten years. What the AI brought was doing all of it simultaneously for four days while nobody noticed. Also worth knowing who is telling us this: Dream is Shalev Hulio's company, the NSO co-founder, and the report concludes that defense has to become AI-native, which is what Dream sells. (read more here and here)
The FBI and NCAA announced a joint initiative Monday to warn student-athletes about cyber-enabled sexual exploitation. The FBI's position is that athletes get targeted because their public profiles, expanded by NIL activity, give offenders both more access and more leverage when they threaten to expose material. The tactics described are ordinary account takeover work. A text claiming the account will be disabled unless you send back a verification code. An email about a suspicious new login that pushes you to a reset page. Taushiana Bright, section chief in the FBI's cyber division, told ESPN that the explicit material circulating in athlete cases is mostly real rather than AI-generated, and that sellers will post a stock photo from the school's team page next to it to prove the person is who they say.
If you run awareness for a school, a team, or anyone with a public profile, the reporting guidance is the part to pass along. Stop communicating with the offender, do not pay, do not send more images or identification, preserve the messages, and report it. The FBI is direct that paying leads to further demands. Non-consensual intimate images go to ncii.ic3.gov, and anything else to tips.fbi.gov or 1-800-CALL-FBI. The FBI and NCAA are specifically asking coaches, compliance staff, and athletic department leadership to carry this to athletes, since they are usually the first trusted adult somebody in that situation would go to. (read more here, here and here)
Miscellaneous mattjay



How'd I do this edition?It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week. |
Parting Thoughts:
Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.
Stay safe, Matt Johansen
@mattjay
