- Vulnerable U
- Posts
- 🎓️ Vulnerable U | #183
🎓️ Vulnerable U | #183
OpenAI detailed Hugging Face report, GTA 6 leaks, Omarchy 0days, TeamPCP arrests, and much more!
Read Time: 8 minutes

Brought to you by:
Howdy friends!
Last night was the final day with a sunset later than 8pm for the year. I heard that and it immediately felt like I was now riding downhill. Summer is a bit oppresive here in Austin, but overall this was a good one.
It reminded me of that Treebeard quote to Merry and Pippen: “I always like going south; somehow, it feels like going downhill” - so let’s not be hasty and hope for this all to get over with, and enjoy the last of summer together.
If you haven’t - make sure to check out my new podcast with Low Level TV. We’re getting a ton of good feedback. We just recorded Episode 10 which apparently only about 20% of podcasts ever reach that milestone.
Leave it to 2 guys who’ve been making weekly videos consistently for years to lock in I guess? Thanks, Maze, for all the continued support helping make the show happen.
ICYMI
🎧️ Something I heard: John walks through an investigation of how TeamPCP got arrested
🎤 Something I said: Everything we know about the GTA 6 leaks
🔖 Something I read: Vibe coders have their own language
Vulnerable News

I’ve been saying sandboxing is not something you accomplish in a Guardrails[.]md file. OpenAI's postmortem makes that case better than I did. Models running cyber evals in sandboxes with no internet and no way to talk to each other found both those restrictions were merely suggestions. They left files in the internally hosted package manager, the one service they could still reach, and turned it into a message board. Then they got that same service making outbound requests for them. Nine weeks later they had code execution across dozens of Hugging Face servers and credentials from four regions.

I hate personifying AI agents, and it is really hard to talk about this incident without slipping into that. Like how else do you say: the agents divided labor and started calling themselves a collective. One paused, reasoning that hitting a third party with leaked credentials was probably unauthorized. Another posted GO with a six-minute deadline. It went. Peer pressure? And the safeguards that would have caught all of this existed already, they just weren't switched on for internal evals, where the production harness cuts this behavior 100x and the monitors would have paged security a day early. (read more here, the technical report and the independent METR and Redwood investigation)

A year ago, a handful of vendors claimed the "AI SOC" category. Today it's more than a hundred, and almost every one has slapped "agentic" on the box. Most stop at triage, wrap a chatbot around a legacy stack, or hide the AI's reasoning in a black box.
The plainest test is if it can't take action across the threat lifecycle, it isn't an AI SOC. Torq put the whole argument, and how to vet any vendor, in the AI SOC Apocalypse Manifesto.
*Sponsored

Doing my best TikTok influencer voice: OMG you guys. Come with me to check out the viral new Linux Distro, Omarchy! It has everything. Including 0days!
The proof of concept is a fake DHH hoodie drop that tells you to hit a keyboard shortcut to claim your size. That shortcut is Omarchy's download-video feature, which grabs the video off the page and then offers a click-to-play notification when it finishes. The problem is that the notification's play command got assembled partly out of the video's title, and the page decides what the title is. Mehmet Ince (@mdisec) wrote a title that turns the play command into a command of his own.
Separately this week, the command that sets up SSH access announces it's configuring key-based auth, then starts the server with distro defaults that accept passwords and opens the firewall before any key is authorized.
My main point on this whole story - just like the AI powered browsers. These Distros/Browsers are HARD to secure and get right. Going viral and working on this with a small team is bound to lead to vulns. Especially with all of the attention on this, they’re going to get found and published. Not saying don’t use it, but just know what you’re getting into here. (read more here, the fix and the sshd issue)
A threat actor, CyberLeek, has been releasing stolen GTA VI footage daily for over a week behind a manifesto about Rockstar going disc-less. The crypto wallets watermarked into the videos, the memecoin, and the offer to sell ad space on future leaks undercut the whole manifesto as they are just monetizing this. Katie Moussouris put it well: "The manifesto is what keeps them watching." To me it just reads as an insider with access to a real build rather than a network intrusion, which matches how Take-Two (Rockstar parent co) is responding.
Take-Two got DMCA subpoenas against Discord, Google, Microsoft and X, and the Discord one asks for device identifiers, login records and cloud storage contents for every person who spoke in three servers going back to June. Actually the same Windows Device ID that just caught the Scattered Spider hackers. Meanwhile fake Rockstar sites advertising a demo that does not exist are serving an infostealer. And of course with all the virality, torrents are up preteneding to be the unreleased game and are filled with malware. (read more here and here)

The Vulnpocalypse was supposed to be here by now…so where is it? Root Evidence traced every confirmed exploitation of a published CVE since 2018: all 3,769 of them, against the 253,912 published in that window. They found that adversaries never touched 98.5% of vulns.
Join Root Evidence co-founders Jeremiah Grossman and Robert "RSnake" Hansen on Wednesday, Sept. 2 for a first look at the data in their upcoming Vulnpocalypse Report. Attendees get the full report before it's publicly released.
*Sponsored
Cat hacker down! Two men from Western Australia, 21 and 23, appeared in Perth Magistrates Court on Thursday facing a combined 14 charges, accused by the AFP and the FBI of being principal participants in TeamPCP. That's the crew behind the March compromises of Trivy, Checkmarx KICS and LiteLLM, with the European Commission, Mistral, GitHub, OpenAI and Mercor also on the list. Police put it at more than a thousand organizations, over half a million stolen credentials and at least 300GB of data.
We covered this ad nauseum because the pattern was super clear and effective: poison a tool developers already trust, then use what falls out of that compromise to reach the next one.
Krebs had been talking to the alleged former leader, who goes by Ellis, since July, and that interview is the part worth your time. He claims he cleared roughly $20,000 total. A thousand organizations, half a million credentials …twenty grand. He also told Krebs he is "nowhere close to a skill level where I am comfortable," which is certainly interesting given how successful they were. It also really shines light on why a lot of people are cheering them on for exposing super easy weaknesses in the supply chain house of cards. Your build pipeline wasn’t tough enough against someone who describes himself as still learning. (read more here and Krebs' interview)
DOJ and the FBI seized three domains on Wednesday and killed the two platforms running behind them. Court documents name a PRC group, QTFY, working out of a Nanjing tech company, with confirmed victims including NASA, the Federal Reserve, DOE, DOJ, HHS, NIH and the Senate across about eight years. QTFY rents the capability, and its customers do the breaking in, hence “Quartermaster.” What it rents is a scanning platform that finds and profiles targets, an encrypted relay network to reach them through, and a preconfigured router that gets an operator onto that network.
Rather than grinding out a botnet from compromised home routers, they bought premium access on a Chinese commercial proxy service, so espionage traffic rides alongside real paying consumers and rotates on its own. I’d read the IOCs and the CVE list that they are hitting and bang out some detections since this is just a speed bump in infra takedown. (read more here and here)
We all heard an echo of a word this week that probably sent shivers down spines. Or at least brought back some sleepless night memories. "Log4j RCE.” Log4j2 (Electric Boogaloo) went floating around. A public PoC exists, but from what I can tell it is mostly a nothing burger. Go ahead and use this as an excuse to test that if this was real you’d be able to respond and find all your log4j installs quickly. But this by default is not exploitable. Highly conditional.
You need one of these network listeners running, an untrusted peer who can reach it, a usable gadget library already on that machine, and no JVM-level filter in the way. Ordinary logging never touches this path, and finding log4j-core in an SBOM proves nothing about exposure. There's no CVE and no fixed release, and Apache treats it as hardening. A public PoC exists. Go find out whether you run one of these listeners at all, and kill the ones you don't need. (read more here and the Apache discussion)
A few weeks back it was LG smart TVs shipping an SDK that rented your living room out as a residential proxy node. This week it's your car dashboard. Kaspersky found the first malware built specifically to infect car head units, targeting Android units running firmware from DoFun, whose own site claims more than 30 million vehicle owners. The way in was the head unit's own updater. The preinstalled app that handles software updates takes its instructions from a server the attackers got control of, so the malware arrived down the same pipe as legitimate updates.
The malware supports a decent range of commands and the only one Kaspersky watched anybody actually use was the one that installs the proxy, just like the Smart TVs. Nobody is steering your car with this. What they want is the thing sitting in your driveway with a SIM slot and a permanent connection, because traffic sourced from there looks like a person. (read more here)
This got caught because it broke a guy's headphones. Matt Callaghan noticed his multipoint pair would not hand back to his phone whenever an AliExpress tab was open, and muting the tab did nothing, because there was no video or audio player to mute. Digging in, he found two obfuscated scripts from Alibaba's anti-abuse stack generating a tone, measuring how his machine rendered it, and routing the result to the system audio output at zero volume. Nothing to hear, and the audio path stays busy the whole time.
The audio measurement is one input into a much larger fingerprint that also pulls canvas, graphics, hardware details and pointer behavior. Tom Ritter on the Firefox team reports they neutered the audio piece back in version 118, with 99.24% of users landing in one of three buckets that differ only by CPU, and a long tail of 48 people with strange enough hardware to be unique. He expects Chrome, Brave and Safari have similar defenses. Callaghan solved his own problem by blocking the two scripts. Fingerprinting works right up until it stops somebody's music. (read more here and here)
Comcast is now selling WiFi Motion detection as part of its privacy-invading repertoire. You nominate a few stationary devices around the house, a speaker or a thermostat, and the gateway watches how bodies moving between them disturb the signal. It's sensitive enough that Comcast ships tuning to filter out pets under 40 pounds and warns it can't reliably tell a small dog from a small child. The capability has quietly existed since 2024, so the launch is really a marketing event.
The catch is in Xfinity's own support documentation, which says Comcast may hand information generated by your WiFi Motion to third parties "without further notice to you" for a law enforcement investigation, any dispute Comcast is party to, or a subpoena. What it doesn't say is what gets kept or for how long. So there's a record of when people move around your house sitting somewhere with an unpublished retention policy.
Between this and the browser audio fingerprinting - I’m just seeing some bad misuse of radio frequencies as everyone is getting creative to privacy intrusions when our protections get better. (read more here and here)
Chrome 152 shipped Tuesday with 327 security fixes, ten of them critical and most of those memory-safety bugs in the graphics and UI layers. Nothing reported as exploited in the wild. The interesting read is the credit list, where the overwhelming majority say "Reported by Google" and only a couple dozen carry an outside name. Two of those belong to XBOW, the AI pentest outfit. Top bounty was $25,000 for a critical graphics bug found by a researcher going by Goodluck. Restart your browser. (read more)
Miscellaneous mattjay

zoom in. got a good chuckle


How'd I do this edition?It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week. |
Parting Thoughts:
Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.
Stay safe, Matt Johansen
@mattjay
