🎓️ Vulnerable U | #184

Massive drivers license data breach, McKesson breached by ShinyHunters, TeamPCP OSINT investigation, and much more!

Read Time: 8 minutes

Brought to you by:

Howdy friends!

Why do kids sports in Texas start in August? Cruel and unusual. I went to exactly 1 soccer game at 11:30am without a shadow in sight and only brought a camping chair. I felt like a complete rookie, and immediately placed a way too large Amazon order to never feel that way again.

I’m now rolling up to games looking like Tom from Parks and Rec when he goes camping. Shade, fans, cooling towels, the works.

If you haven’t hopped on our new podcast bandwagon yet, what are you waiting for? Filming The Low Down is the most fun I have every week. Sound off if you like what we’re shipping over there. If YouTube isn’t your thing, catch us on Spotify, Apple, or wherever you get your finest podcasts.

ICYMI

🖊️ Something I wrote: hot take? $250k for a full chain chrome exploit is too low.

🎧️ Something I heard: The Low Down episode on the GTA 6 leaks, Omarchy 0days, and a bunch more (Thanks Maze for the continued support!)

🎤 Something I said: Great convo with Cal dot com CEO on why they went closed source due to perceived security risk of being open source in the age of AI code scanners

🔖 Something I read: Woke up to NightmareEclipse dropping a CrowdStrike 0day and RSA-260 being broken getting announced via a tweet.

Vulnerable News

Oh look the thing we all said would happen. A service that launched on a Russian cybercrime forum this week is selling scans of more than 153 million US and Canadian drivers licenses, plus ID cards, travel documents and medical cards. Each record carries front and back, plus the infrared and ultraviolet captures, with a timestamp on every file. Krebs found his own license in there as the free sample, then got a dozen friends and family to let him search for theirs. His mother's timestamps land a few seconds off his own, because the two of them handed their licenses across the same Hertz counter at the same time.

The thread runs to idscan[.]net in New Orleans, which does ID verification for Hertz, Target, FedEx, Caesars and a thousand-plus dispensaries, at 21 million verifications a month. The FBI's New Orleans field office opened an investigation Tuesday and pulled Krebs onto a call with half a dozen agents once word got around that he was digging. The seller claims a year of continuous exfiltration, and the record count climbed by roughly 400,000 in the 24 hours he was reporting it out. The site went dark within hours of publication, which fixes nothing. Zach Edwards makes the point I keep coming back to: every age verification law we pass pushes drivers licenses into another few thousand third party vendors, and a leaked UV scan of your ID is not a password you get to rotate. (read more)

AI-generated code moves at machine speed, but most AppSec programs still rely on find-it, fix-it triage built for a slower era. Legit's Agentic AppSec platform closes that gap. It secures code the moment AI writes it, using business context (exposure, sensitivity, criticality) to separate real risk from noise. When issues do surface, autonomous agents remediate automatically and feed what they learn back into your AI coding tools, so fewer vulnerabilities get introduced with each cycle.

*Sponsored

About a third of the pharmaceuticals in North America move through McKesson, and we have shockingly few details about this massive breach. The company filed an 8-K on August 28 and told customers that attackers reached third party applications and took data tied to its oncology, multispecialty and medical-surgical units. ShinyHunters claimed responsibility and their MO can give us some assumptions on the way in. Vishing into some corporate Okta SSO accounts, then walking into Salesforce and Snowflake and pulling about a terabyte over four days before anyone noticed on the 25th. They asked for $55,236,150 with a 72 hour clock. McKesson never answered, and the Tuesday contact deadline came and went.

The 284 million figure is getting quoted as patients, and the group itself corrected that to say it is a raw row count out of Snowflake, and they say they have not analyzed it yet. Take the claimed contents with that same salt. I’ve been saying this should be everyone’s top priority for a few years now as these threat actors are screaming their playbook from the rooftops. Your help desk identity verification process is the control that was supposed to catch this. (read more here and McKesson's notice)

Source: AFP, via Flare

Last week I covered the two arrests in Perth. Flare published the other half of that story, which is how one of them got found, and it is one of the cleaner OSINT walkthroughs I've read. Start with one distinctive handle the crew used in earlier operations. Run it across social platforms and a HackerOne profile comes back with a real name on it. A Hugging Face account under the same handle lists a domain that later shows up as command and control for one of their worms. From there a school email address turns up in a credential dump, the password on it gets reused, and the reverse pivot lands on a personal Gmail. That Gmail leads to a TikTok under the same name, the TikTok shows off a Steam account, and the Steam profile picture is the same cat sitting in front of monitors that fronts the group's Telegram channel.

This crew was loud on purpose, running Telegram channels, taunting victims on X, giving an interview to Forbes about being teenagers who couldn't find work. That appetite for credit is what made the campaigns spread, and it is also what left a distinctive avatar parked on a gaming profile since 2016 waiting for someone to look. (read more here and the AFP release)

Last week's lead was OpenAI's Hugging Face postmortem, with METR and Redwood running the independent investigation. This week METR published its own two incidents, and the March one is going to live in my head rent free. A researcher with no sensitive access stood up a personal EC2 box behind Google auth to run some agents on. The app was vibe coded, and it failed open, silently turning authentication off and leaving an agent orchestration dashboard on the public internet for days.

METR and OpenAI are also getting major criticism from the infosec community as nobody at METR is a cybersecurity expert, incident responder, forensics specialist, or anything like that. They eval’d the Hugging Face incident for their report and stuck just to the prompt and response transcripts, never looking at any of the logs. Zack has a good video on this topic here.

Nobody caught it for three weeks because METR runs enormous evals and is used to weird rate limit errors, the tokens were donated so no invoice ever showed up, and there was no way to cap spend on that key. The May incident is a sustained campaign against them by someone financially motivated and hunting frontier model access, using agents to automate discovery, credential stuffing their auth providers and phishing staff. During the same window they had accidentally exposed a read-only query path on their public transcript viewer that a bug could push past into unpublished evaluation data, which an outside researcher found and got paid for. (read more)

It seems a lot of common infostealer malware has added a new goal to their arsenal. Anthropic started emailing affected users this week to say that commodity infostealers on their machines lifted live Claude session cookies, and somebody is now sifting Claude sessions out of the stolen piles and spending other people's usage. They are signing those accounts out, stripping saved payment methods, and refunding charges they can identify as unauthorized. Named families are the usual crowd: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on a handful of Macs. The Redditor who posted his email confirmed he'd installed a pirated game which is how he caught some malware.

Anthropic is explicit that the malware has nothing to do with Claude and arrived through ordinary downloads, and that's worth repeating because the headline reads the other way. (read more here and the original email)

If you run self-hosted Artifactory, go patch. CVE-2026-82329 is an authentication bypass that works against the default configuration and hands an unauthenticated attacker with network access administrative privileges. JFrog fixed it on August 28 and says cloud instances were already covered. Days later watchTowr's honeypots caught real exploitation, with attackers minting themselves admin tokens and enumerating users, groups, credential sets and federated access topologies. CISA had not added it to KEV as of Wednesday.

The detail that turns this from a patch into an incident is that Artifactory access tokens are independent credentials with their own lifecycle, so upgrading the binary does not invalidate a token an attacker already minted. Patch, then go find tokens and revoke them. Admin on the box everything else pulls from means an attacker can swap trusted artifacts and let your build systems distribute the result for them, which is the part Guillermo Rauch and Black Duck's Collin Hogue-Spears both flagged. (read more here, the JFrog advisory and SecurityWeek)

Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, were extradited from Nigeria on Thursday to face charges tied to sextortion schemes that ended in the deaths of two minors, one in Mississippi and one in North Carolina. Both were arrested in Nigeria in August 2023 under Operation Artemis, the joint international effort against Nigerian sextortion rings targeting American children. Adekunle's charges include sexual exploitation of a minor resulting in death, production of child sexual abuse material, coercion and enticement of a minor, and interstate threats with intent to extort. That death charge carries a 30 year mandatory minimum and a life ceiling. It took three years to get them into a US courtroom.

404 Media ran a piece the same week that explains why that three year gap matters. Erin West, who founded Operation Shamrock, and cybercrime researcher Paul Raffile set up decoy accounts posing as a teenager, got approached within days, and worked backward: a link that logged the scammer's IP put him in Lagos, a second attempt captured his location and his face, and a move to WhatsApp gave up a phone number that resolved to a name. They flew out, got GPS coordinates, and drove to his village. He refused to meet them, so West told him on the phone that they knew who he was and where he lived and that it was going to the FBI. His accounts went dark that day. Her read on it is the thing to carry: these are people who are not afraid of being arrested, and somebody showing up is the first consequence any of them have felt. (read more here, the DOJ release and 404 Media)

Running theme around here lately, between the LG smart TV proxy SDK and the car head units, and now the router itself. VulnCheck published ENDLESSDOORS last month, a phone-home implant running as root with no authentication across twenty Zbtlink router models. Then they went shopping to see how far the supply chain reached, bought an $88 white-labeled unit on Amazon from a small New York company, and found two more implants on it. One listens on the WAN and executes commands with an authentication check that has a hardcoded bypass sitting in it. The other beacons outbound and supports hijacking your DNS, stealing the credentials that authenticate your ISP connection, and opening a reverse SSH tunnel home. They registered an abandoned backup C2 domain and sinkholed it. 392 devices reported in, 390 of them in China, mostly one carrier CPE model, one of them beaconing uninterrupted for nearly two years.

Zbtlink's answer to the first implant was that it assists customers who explicitly request support. VulnCheck could not find any mechanism for a customer to request or authorize it, and since none of the three implants authenticate or encrypt anything, the vendor has no way to know who has used them. The same hardware surfaces under brand names across the US, Canada, Australia, Germany and the Philippines, so match on model number rather than the logo. On the cheap streaming box side, Bitsight found preinstalled apps on H96 Android boxes rewriting the device identity to look like a phone, clicking ads and renting the home connection out as a residential proxy, roughly 38,000 unique MACs in a single day of telemetry. There is no patch coming for any of this. Inventory it, put it behind strict egress control, or throw it away. (read more here, the ENDLESSDOORS writeup and Bitsight on the TV boxes)

Miscellaneous mattjay

How'd I do this edition?

It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week.

Login or Subscribe to participate in polls.

Parting Thoughts:

Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.

Stay safe, Matt Johansen
@mattjay