- Vulnerable U
- Posts
- đď¸ Vulnerable U | #186
đď¸ Vulnerable U | #186
ChatGPTs aren't private, Flock reverse engineered, Actively exploited 0days, Passkey phishing lures, and more!
Read Time: 8 minutes

Brought to you by:
Howdy friends!
It wouldnât be first month of school if I didnât go down with some random bug. Thought it was allergies but then I was sweating and shivering under a blanket and decided maybe I was wrong. Feeling better now though!
Any of you AI hackers get your hands on Astra? Itâs certainly feeling different/better than Claude Code to me at the moment, though Iâm not super deep into testing yet. Curious your experience.
ICYMI
đď¸ Something I wrote: I saw a mind blowing demo that feels like it is going to change the game at the data/speed layer of security
đ§ď¸ Something I heard: John Hammond shared a fun new malware lure via those annoying âacceptâ or âreject all cookiesâ banners.
đ¤ Something I said: We discussed whether TeamPCP hackers did anything worth going to jail for.
đ Something I read: Halvar Flakeâs Bluehat Singapore talk on the age of experimentation
Vulnerable News

Joseph Cox at 404 Media got internal docs showing OpenAI has hundreds of contractors reading a firehose of real ChatGPT conversations to rate and critique the model's replies. Whole conversations, sometimes with the intimate stuff still in them. OpenAI says it scrubs personal info before prompts reach reviewers and admits sensitive details get through anyway. Anthropic confirmed to 404 it does human review too. When Cox asked someone who works with the prompts whether users know a human might read their chat, the answer was a flat no. With 900 million weekly users treating this thing like a therapist, financial advisor, healthcare, etc. that's a lot of people who never got the memo.
Moxie Marlinspike wrote about exactly this in December when he launched Confer, an end-to-end encrypted AI chat. His point was that the chat UI tells your brain you're in a private conversation, and an honest version of that UI would be a group chat with the vendor's employees, their contractors, whoever breaches the plaintext later, the advertisers who show up eventually, and the lawyers who subpoena it. This story is the receipt for that argument. If you or your company are putting anything sensitive into a consumer chatbot, go re-read what your agreements actually say about training and human review, because the policy language was always the answer and now you can picture the person on the other end of it. (read more here and here)

We have all gotten stuck in bug finding bottlenecks over the years. It turns out we donât need a high volume of potential bugs to find the ones that matter most.
Rather than casting a wide net, we need expert humans guiding the most powerful models. My friends over at Teleport challenged a team of 13 engineers to figure out the most successful way to find vulnerabilities in a single quarter. They ended up âpressure washingâ their codebase using LLMs and coding agents.
Reviewing their existing code from a bunch of angles was the way to go. Check out their experiment here.
*Sponsored

A group calling itself stegan0gram pulled a Flock camera off a pole, dumped its storage, and reverse engineered the whole thing. Flock markets on-device encryption. The hackers found the encryption key sitting on an unencrypted partition, which unlocked thousands of vehicle detection videos. From there the reporters found the camera runs about 20 Flock-built Android apps, fires off roughly 28 photos per passing car, and generated 1.6 million images across three weeks of logs. The on-device model explicitly detects people as well as vehicles and plates, which Flock does not lead with, though nobody found face recognition in use.
Flock's response was that removing a camera is illegal and that nobody submitted this through their VDP. Both true. Also worth remembering that Jon "GainSec" Gaines got root on a Flock ALPR in 2025 and the company waved it off because it needed physical access and footage doesn't stay on the device long. Physical access turned out to be a ladder, and the footage stayed. Noel Pichardo, the ex-cop turned Flock critic, thinks this kind of vigilantism only hardens police in the belief that they need these things, and he's probably right. Best detail is in the logs though: 27,000 "no space left on device" errors, and a health check that writes "Who's a good boy?!" every two minutes. (read more here and here)
Revolut spent about five months answering law enforcement data requests from someone who was not law enforcement. The attacker most likely bought infostealer logs containing credentials for an Italian Ministry of the Interior employee, then used that real government mailbox to send legit-looking legal requests to Revolut's Lithuanian banking entity. Revolut answered them. Around 680 customers, reportedly crypto whales, had passports, verification selfies, contact details and financial info handed over, and ZachXBT says the haul also includes IBANs, occupations, and bitcoin transaction histories. The hacker claims 147GB from an Italian police agency on top of that. Now someone going by IAmNotAVillain is publicly demanding $3M, though Revolut told SecurityWeek nobody has actually contacted them.

None of this should surprise anyone who read Abnormal's writeup last year on the market for compromised .gov and .police inboxes: active accounts for $40, bulk infostealer logs for $5, and the listings explicitly advertise "send fraudulent emergency data requests" as the use case, alongside access to the law enforcement portals at Meta and X. Real mailbox, real domain, nothing to spot in the headers. Hudson Rock says it's tracking 300+ compromised credentials for that same ministry domain, so Revolut is unlikely to be the only recipient. If your company has a law enforcement request process, it's worth asking what the verification step actually is beyond "the email came from a government address." (read more here, here and here)
Your team canât chase every CVE. The Vulnpocalypse Report from Root Evidence examines 3,769 exploited CVEs to uncover whatâs actually driving risk, challenge assumptions about AI and zero-days, and give security teams better evidence for deciding what to fix.
*Sponsored

Someone took over the verified u/hbomax Reddit account and ran 108 promoted posts in 48 hours advertising a native HBO Max app for macOS. There is no native HBO Max app for macOS. The ads pointed at a lookalike domain with a download button that opens a ClickFix prompt: copy this command, open Terminal, paste, run. Mac users got MacSync and AMOS variants plus fake wallet apps, Windows users got Amatera Stealer via living-off-the-land tooling, and both sides also picked up clipboard hijackers that swap crypto addresses at paste time.
Reddit pulled the ads once notified. What makes this one nasty is that every trust signal was green: verified corporate account, promoted placement, a brand people actually pay for. ClickFix keeps working because "paste this into your terminal" reads like tech support to normal humans. If you own a brand account, put hardware keys on it. (read more here and here)

Headline scared me here because Passkeys are supposed to be phish-proof. Turns out it was passkey themed phishing. Microsoft published details on a campaign it's tracked since May where attackers call or text employees on their personal phones, pose as the IT helpdesk, and say their passkey or SSO setup needs updating right now or they'll lose access. The link goes to a Microsoft lookalike on a domain like passkeyhelpdesk[.]com with the victim's company name as the subdomain. From there it's adversary-in-the-middle or device-code phishing, and once they're in, move one is registering their own MFA method so the access survives a password reset. Then Graph API recon, SharePoint and OneDrive bulk downloads, and mailbox collection running for hours to days.
Microsoft ties the initial access to Storm-3121 and Storm-3032, the latter being UNC6671 / Cordial Spider, the crew feeding ShinyHunters and Helix extortion. Passkeys are the phishing-resistant fix we've all been pushing, and here they're the lure, because "update your passkey" sounds urgent and plausible to someone who was told to set one up last quarter. The passkey itself held. The person got walked through a device-code flow while thinking they were doing a passkey ceremony. Microsoft's detection advice to work into your detection engineering pipe: no single Graph call looks bad, so alert on the sequence, new MFA method registered followed by bulk download. (read more)
The headline made me chuckle. Cisco Secure Email Gateway owned âŚby an email. Not just that, but a SQL injection that ends up allowing command execution as root. OWASP top 1 for years rears itâs ugly head. Reminds me of all the times Antivirus was the thing that was getting popped.
If you run a Cisco Secure Email Gateway, patch today. CVE-2026-76461 (CVSS 9.8) lets an unauthenticated attacker root the appliance by sending it a message, which is a bad property for the box whose job is inspecting hostile email. Cisco found it working a support case, says exploitation started in September, there's no workaround, and it's in CISA KEV with a federal deadline of today. Cisco already upgraded its own Secure Email Cloud fleet and has contacted customers with indicators of compromise. Their warning for everyone else: root means the attacker can clean the logs, so check firewall and network logs rather than trusting the appliance, and if a virtual appliance looks touched, rebuild from fresh media and rotate creds and certs. Second exploited AsyncOS bug this year after January's CVSS 10. (read more)
The FBI, UK NCSC and Dutch AIVD put out a joint advisory on Chosen Brick, Windows malware Iranian intelligence has used since at least 2025 against dissidents, activists and journalists. The wild part on this one for me was how personalized each lure was. One message had MRI results for someone who was awaiting MRI results⌠They did extensive research on each target, then a WhatsApp or Telegram message from someone the victim believes they know, some rapport building, and finally a file dressed up as Pictory, RunwayML, Norton, Telegram, KeePass or, incredibly, Adobe Flash Player. Once it runs it persists across reboots, adds Defender exclusions, and uses a per-victim Telegram bot for C2. Capabilities are the full surveillance kit: contacts, email, WhatsApp and Telegram data pulled from browsers, screen and audio capture, and a wipe function.
The advisory says that Iran has plotted to kidnap or kill people it considers enemies of the regime, so the stolen data can feed physical operations. The part for corporate security teams is that this actor goes after personal devices, and the agencies are asking orgs to push this out to staff who might be targets and help them check their own machines, which is a different audience than the usual advisory. If you employ or work with Iranian diaspora, journalists, or anyone doing Iran-adjacent work, forward this one. (read more)
This one feels kind of wild to me. We have CISA making a rare guidance suggestion specifically targeted to critical infrastructure operators. With a 22 page PDF going into fantastic detail of how to setup your Cyber deception program. My issue here is that this is targeted at a sector that routinely gets popped for exposed PLCs on the internet running decade old CVEs. Deception seems like a luxury item at that point. Honey tokens is one thing, but the PDF describes doing a full exercise to expose a honeytrap and gain intelligence on threat actor behavior once they get in. IMO the threat actors are screaming their behavior from the rooftops and donât need to change because nobody is playing the right defense anyway.
The pitch is that decoys assume the attacker already has some level of access, so they catch the living-off-the-land activity that identity controls wave through because the credentials are real. Place them where legitimate users never go, tune them for high-fidelity alerts, and run it as a loop of prepare, execute, learn. The doc walks each decoy type, deployment, and example scenarios, and it's written for teams at any maturity level.
None of it is bad advice, just seems like we need to nail the basics first. Honey tokens are easy and cheap, go do those. But if youâre chasing vulnerabilities that are old enough to be really into KPOP Demon Hunters, lets nail down that first. (read more)
If you carry a Pixel, take the September update. CVE-2026-58704 is a permission bypass in the cellular modem that Google says is under limited, targeted exploitation. Proximal attack, no user interaction, so this has spyware vendor written all over it, and Google isn't saying who. It's one of 110 fixes in this month's Pixel bulletin. Settings, Security & privacy, System & updates, install, reboot. (read more)
Miscellaneous mattjay



How'd I do this edition?It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week. |
Parting Thoughts:
Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.
Stay safe, Matt Johansen
@mattjay
