🎓️ Vulnerable U | #185

AI labs are taking an official stance that there is a high probability they are going to kill us all, and I guess other cyber news...

Read Time: 5 minutes

Brought to you by:

Howdy friends!

It’s been hard to parse down what to cover the last few weeks. There is A LOT of stories taking up a lot of our attention. I’m trying to avoid too much random breach noise and stick to things that we can learn lessons from or are otherwise impactful/industry relevant.

ICYMI

🖊️ Something I wrote: I got absolutely nerd sniped watching the speed of this tool built on top of security relevant data by Scanner - wrote up my impressions here.

🎧️ Something I heard: The latest Low Down talking about the 153 million drivers licenses lost, people coming to the defense of TeamPCP hackers, Nigerian sextorion rings, and much more.

🎤 Something I said: We aren’t talking enough about OAuth security risks

Vulnerable News

WTF is going on at LG? Last time it was 42% of their smart TV apps carrying a residential proxy SDK, alongside a Gamers Nexus video about adware on their $1,200 monitors. Steve Burke is back with two hours and fifteen minutes on the TVs themselves. Packet captures on retail OLED sets show the TVs enumerating everything on the local network. One test TV found 38 devices, including phones and watches belonging to staff who had nothing to do with the testing. Add nearby Wi-Fi names, signal data, and ACR fingerprints of whatever is on screen, all flowing back to LG's advertising side.

They also reported RCE bugs to LG and used one to turn a G5 into a listening device, capturing room audio with the screen off and the ethernet unplugged, then uploading the file once the connection came back. Those bugs are still in disclosure so details are thin. The network enumeration and the ACR pipeline are the shipping product working as designed, which is the part that should actually bother you. Put the TV on your IoT VLAN and drive it with an Apple TV. (watch more here and read more here)

AI can now deliver the depth of a pentest at the frequency of a scan. Instead of one annual engagement, testing could soon happen continuously: triggered whenever a new feature ships, a port opens, or a configuration changes.

This Intruder blog explores the short, medium, and long-term future of pentesting, and why the annual pentest may eventually become a thing of the past. (read more)

*Sponsored

Jacob Coxon, a pretraining researcher who worked at both OpenAI and Anthropic, quit Tuesday and posted why: both labs are racing to self-improving superintelligence and "gambling with our lives." The thread did somewhere north of 150 million views overnight. Then Evan Hubinger, Anthropic's own Alignment Science Lead, quote tweeted it to agree, saying the people inside "really do earnestly believe AI could kill all humans" and putting his personal number at greater than 10% within the decade. Bernie Sanders says he is introducing a bill to pause development and ban superintelligence. Musk called the whole thing a psy op.

The reporting also notes Coxon had been at Anthropic four months and walked two months short of his vesting cliff, which is either the price of a principled exit or a reason to read it carefully. (read more here, here and here)

Thousands of crypto holders got phishing mail on Wednesday sent from real company domains, with SPF and DKIM passing and every instinct you have trained into your users passing right along with them. Trezor, CoinTracking and BitBox all confirmed it hit their newsletter subscribers. CoinTracking named the source as Brevo, the email marketing provider all three share, and BitBox noted that the other crypto companies getting hit were on the same platform. Brevo put out a notice Thursday saying an attacker had access to 120 customer accounts and used them to mail those clients' contact lists, that the access is closed, and that a post mortem is coming. Trezor's lure was a critical security alert about an STM32 entropy vulnerability.

The STM32 bug is invented, but Coldcard shipped a real entropy failure that cost holders around $89M in July, so the lure works on anyone who has been reading the news. Your marketing email vendor is now a load-bearing part of a hardware wallet's threat model, and one compromise there buys 120 sender reputations and every list behind them. Trezor is also still cleaning up the ShipMonk breach, now at 81,000 customers with names, phone numbers and shipping addresses, and customers have started reporting malicious QR codes arriving by postal mail. (read more here and here)

Anthropic published its threat intel report yesterday, eight months of actors it caught using Claude across seven harm areas. Everyone is covering the cyber section, and it earns it by being a crazy read. A Russian espionage operator whose tradecraft matches Midnight Blizzard hit more than 20 government and defense targets across Ukraine and Europe, running agents whose entire job was to watch whether security products flagged their malware and rebuild it until nothing did. Two undergrads at a Chinese university ran an exploit foundry producing more than a dozen possible zero days against appliance firmware in a single month. ShinyHunters affiliates, the same collective sitting on Florida's DMV data, dumped 2,100 Azure token sets across 40 tenants in 34 hours. Their own read on the trend is every technique in here is one you have already seen but who is doing the “work” changed from human to agent. Stolen credentials, unpatched edge devices, exposed services, SQL injection, phishing.

Going deeper beyond cyber for a sec because again, this is crazy. A cell in northern Yemen used Claude Code in place of software engineers to build guidance software for a rocket, test-fired it, and was back in a session within hours working out why it failed. A Russian freelance team built an autonomous drone swarm designed for lethal engagement with a person target class and no human in the loop, trained on scraped Ukrainian combat footage. A China-based researcher's electronic warfare targeting suite switched its default scenario mid-project to twelve targets in Taiwan.

And the biology section is the first time any AI company has published evidence of its own platform touching potential bioweapons work, including a reseller that tunneled around regional blocks and routed refused prompts to a competitor's more permissive model, with Claude writing much of that routing code because the developer described it as an over-refusal fix.

Lets all keep the incentives in mind here. This is the vendor selling the model, publishing four days after the federal advisory on Chinese distillation, in the same week its alignment lead put human extinction odds north of 10%. The case files are still the most specific public accounting anyone has of what this tooling does in the wrong hands. (read the full report here and read more here)

Name your own bug bounty? On September 6 someone minted about 4,000 L-BTC that no bitcoin was backing, pushed it through SideSwap's peg-out service, and left with roughly 95% of the bitcoin in Blockstream's Liquid federation wallet. About $320M. Blockstream says the peg-out authorization key was never compromised, and neither were any others. The signers approved it because from where they sat the withdrawal looked completely ordinary. Root cause traces to a proof verification bug in Elements, the Bitcoin Core fork Liquid runs on.

Then the attackers left an on-chain message declaring themselves white hats, opened a negotiation with Blockstream over OP_RETURN and PGP, and made the return conditional on the bug being fixed and every node patched first. Blockstream signed a message confirming the fix, and 3,400 BTC came back. The remaining 598.5 BTC, about $47M, they kept and called a bounty. Draining 95% of a federation's reserves and then setting your own fee is a novel reading of coordinated disclosure. (read more here and here)

Part of the Com, Malone Lam (22), pleaded guilty in DC this week to a RICO conspiracy count covering more than $245M in stolen and laundered crypto. The enterprise came together on gaming platforms, spread across California, Connecticut, New York, Florida and abroad, and ran on social engineering with the occasional home break-in. Lam picked the targets and assigned everyone their role.

Like all these young pups who get arrested, the spending and bragging was a huge part of his downfall. DOJ lists nightclub tabs running to $500,000 a night, handbags given away at parties, watches from $100,000 to north of half a million, rental houses in LA, the Hamptons and Miami, private jets, a personal security detail, and a car collection topping out at $3.8M. They picked him up at his Miami rental in September 2025 and the status hearing is set for December 8. The entire $245M came out of phone calls and people who were willing to answer questions about their wallets. (read more here and watch more here)

ShinyHunters says it pulled over 200,000 records out of DAVID, the Florida Highway Safety and Motor Vehicles system that law enforcement and court officials use to look up drivers. They told BleepingComputer they got in through a password reset flaw, took over multiple accounts belonging to DMV employees and an FBI agent, then walked the record IDs and saved the pages as they went. Their proof of breach was Jeffrey Epstein's DMV record. (read more)

Following up on this one. IDScan has now confirmed that an unauthorized party accessed customer data in its cloud platform, which is the company Brian Krebs traced on September 1 as the source behind a dark web service selling more than 153 million US and Canadian license scans, plus 10 million ID cards, 3 million travel documents and 579,000 medical cards. Krebs verified it by pulling his own record out of the thing. The FBI is investigating and the lawsuits were filed before the company acknowledged anything publicly. IDScan posted its notice on September 4 with a noindex directive on the page so search engines would skip right past it, which TechCrunch spotted. (read more here, here and here)

This is the good stuff. Researchers caught two separate Chinese threat actors, UTA0560 and JungleBamboo (APT31), running byte for byte identical exploit code against NGOs starting September 1. The chain is three bugs deep: a type confusion in Chrome's V8 for read/write inside the sandbox, a WebAssembly bug to get out of the V8 sandbox, then a Windows kernel bug to escape the renderer and land in the browser process. From there the payloads diverge. One group dropped a JScript backdoor. The other installed a credential stealing Chrome extension dressed up as Google Gemini.

Low Level and myself tried to figure this one out to talk about on the podcast and it is REALLY hard to understand unless you’re a V8 expert. (read more here and here)

With the power of AI! The vulnpocalypse continues. 974 CVEs, 723 of them in Windows, 999 total once you count the third party fixes bundled in. Two are already being exploited. One is a local privilege escalation in Windows ALPC, which is the same bug Volexity watched get used to break out of Chrome's renderer. The other is an improper link resolution flaw in the Windows Update stack that hands an attacker SYSTEM, and it is the first Windows Update Stack bug to be exploited in the wild. Both landed in KEV with a September 22 federal deadline. ZDI has Microsoft at 2,760 CVEs for the year so far, more than double the previous record with a quarter left to go.. (read more here and here)

Miscellaneous mattjay

How'd I do this edition?

It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week.

Login or Subscribe to participate in polls.

Parting Thoughts:

Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.

Stay safe, Matt Johansen
@mattjay