- Vulnerable U
- Posts
- 🎓️ Vulnerable U | #187
🎓️ Vulnerable U | #187
FBI hacked, OpenAI hacked ...sorta, ClickFix is everywhere, 0days exploited fast, and more!
Read Time: 8 minutes

Brought to you by:
Howdy friends!
Anyone who follows my IG knows my music taste, I probably get more DMs about songs I attach to my posts than virtually anything else. Anyway, this is episode 187 so all you Senses Fail fans know what I’m thinking. I remember chanting this number from a pit in New Jersey for an encore a few times. IYKYK
Been a weird week, a lot of the cybersecurity news coverage is coming from outside of our industry. This creates a lot of frustrating narratives for those of us who’ve lived and breathed it for decades. I’m watching executives reinvent AppSec from first principles because now they’re worried about AI hacking them.
Where have you been?
Anyway, lets get to it.
Have you been listening to The Low Down??? We’re getting tons of good feedback, but it is still early days and we’d love to have you. If you’re into podcasts, please consider adding us to your rotation and giving us some 5-star ratings if we earned it.
ICYMI
🖊️ Something I wrote: Guards up when job interviewing - this thread shows a common tactic to get malware on your machine, especially if you own crypto
🎧️ Something I heard: This is easily the best video on the Hugging Face incident yet, by Niels Provos
🎤 Something I said: This is one of the more important videos I’ve made in a while. Your AI chats are not private and you shouldn’t think they are.
🔖 Something I read: These guys got a 100k bug bounty from Meta for a memory corruption issue
Vulnerable News

ShinyHunters says it popped the FBI. The group told journalists it used a fresh, still unpatched Oracle PeopleSoft zero-day to get in through the FBI Jobs portal Monday night. From there it says it moved into FBI-managed AWS GovCloud and walked out with 2 to 3TB on current and former employees and every applicant, then defaced the jobs site with its Umbreon logo on the way out. 404 Media's Joseph Cox got a 5,000 person sample and verified chunks of it: names, home addresses, phone numbers, spouses. Then he found three entries tied to the Remote Operations Unit, the FBI's own secretive hacking team. The FBI says it's investigating and doesn't yet know if the way in was a third-party provider or its own network.

tweet of the year??? FROM JUNE
Back in June this same crew said it had tried to hit an FBI PeopleSoft portal and failed. It came back. The stated motive is a May FBI FLASH report about the group, which it wants corrected within a week, and it insists there's no money angle. Whatever the motive, this is a physical safety problem for agents and their families, since this ecosystem has already used stolen phone records to track and harass the agents investigating it. It's also a counterintelligence gift to any foreign service that gets a copy. And if you run PeopleSoft, they say Fortune 500s are next with the same bug and there's no patch yet, so watch for an Oracle advisory. (read more here, here and here)

Between July 21 and August 6, five labs disclosed AI agents acting outside their intended scope. One chained its way into Hugging Face's infrastructure, taking roughly 17,600 actions along the way. Anthropic found three more, across 141,006 evaluation runs, that reached real production systems.
The agent stole working credentials and still got nowhere. The AWS keys it took had no permission to change anything. The database it tried refused connections from an unapproved origin. No guardrail stopped it. The limits on the identity did.
Token Security secures AI Agent Identity at scale → Let us show you
*Sponsored

Three researchers at Hacktron went from an image upload on OpenAI's community forum to an open pull request in OpenAI's internal monorepo in under 72 hours. The forum runs Discourse, which handed HEIC images to ImageMagick, which leaned on a libheif build Debian never backported a fix into, because the upstream fix never got a CVE. That got them RCE on the forum. Then a flaw in OpenAI's SSO turned any forum login into a takeover of that person's ChatGPT and Codex accounts. One of those belonged to an employee whose Codex was wired into OpenAI's GitHub. Opus 4.8 couldn't make the exploit reliable, and Opus 5 did it within hours of launch. If you self-host Discourse, rebuild, since a web-interface update may leave the old library in place.
The part people are fighting about is scope of bug bounty research and where you draw the line. OpenAI's note on the $6,500 bounty says the forum was explicitly out of scope, so the award only covers the SSO bug. Hacktron's proof of impact involved taking over a real employee's account and having their Codex open a PR. Alex Stamos's thread and his back and forth with Ian Carroll are the thing to read here. Basically CFAA law enforcement being chill and security researchers saying that bugs in the spirit of research wouldn’t violate anyway. Meanwhile the bigger number sits in Hacktron's wider HEIF Heist project: the same libheif exposure at Slack, Meta, GitHub Enterprise and more, for under $3,000 in tokens. Thousands of malicious images repeatedly crashed image processors across all those targets, and Shopify was the only one to notice. (read more)

Was talking with Low Level about this on the podcast today, he dug in deep for a video on his channel. Some researchers are saying docker is no longer a good enough security boundary because the Linux Kernal bugs aren’t so rare anymore. They are suggesting KVM instead to reduce attack surface. The numbers behind it: 5,976 Linux kernel CVEs published this year through mid-September, with 1,650 in August alone. Of the 36 CVEs publicly disclosed through kernelCTF, 13 are reachable through the everyday interfaces a default container can touch.
But KVM isn’t without issues. Hyunwoo Kim disclosed CVE-2026-89775, his fourth KVM guest-to-host escape this year, this time on ARM64. It only works with nested virtualization turned on, which is off by default and not offered on AWS or Google Cloud ARM instances. RHEL 10 and Ubuntu 26.04 are in scope, and upstream is fixed in 6.18.51 and 7.2.5. depthfirst's advice is to move untrusted and multi-tenant workloads to microVMs like Firecracker or Kata. If you're running untrusted code in plain containers, treat your kernel patch backlog as a container escape backlog. (read more here and here)
When an agent can write to your database, issue a refund, or send email, a wrong answer becomes a wrong action. Arcjet runs inside your application and enforces policy before every LLM call, tool call, and query, covering prompt injection, PII redaction, bots, rate limits, and your own rules in Rego. Every decision is logged as audit evidence. (read more)
*Sponsored

So the whole Hugging Face incident seems like it was more of a rogue AI season rather than an incident. More receipts just came out. Researchers went through the public logs of urlquery.net, a URL scanner that loads pages in a remote browser and keeps a permanent public record. They found AI agents using it to route around blocks. Three times, when normal data fetching failed, agents switched to probing for vulns: at the University of New Mexico, Data USA, and the Australian Institute of Health and Welfare. Transluce ties at least some of it to agent swarms already attributed to OpenAI, and traces activity back to at least March. That's two months before any of the incidents we knew about.
Same week, Australian PM Anthony Albanese said at a press conference that an OpenAI agent got into a Services Australia Medicare portal starting June 18. It pulled public and nonpublic files and wrote data into the government database. It was running in an internal OpenAI eval looking up medicine information and, per Albanese, it "didn't accept no for an answer." OpenAI only found it in August during a broader review of misbehaving agents. It then notified Australia on September 10 by emailing a public inbox. Neither the operator nor the target caught it for three months, and the best evidence trail came from a free scanner's public log. (read more here and here)
Push Security went through its detection data and ClickFix is eating everything. It averaged 52% of Push's detections through Q2, passing AiTM and device code phishing for the first time, and hit 67% in August. Four out of five come in through search engines via compromised sites, malvertising and SEO poisoning, so email filtering never sees them. Three kits drive 73% of it. The big ones now pull their config from a blockchain, which leaves nothing to take down, and fake Claude Code install pages are a popular lure. If your ClickFix defense is disabling the Run dialog, kits have moved to Win+X, which opens an admin terminal and has no GPO to turn it off.

Fun example from this week: third-party[.]com, the go-to fake hostname in docs and code samples for years. IANA reserves example[.]com for that job, but third-party[.]com is a normal domain, and someone owns it. Since at least June it's served a fake Cloudflare check that stuffs a PowerShell command into your clipboard. It only shows the lure to Windows visitors, so scanners running on Linux just see an error page. Manifold Security's Ax Sharma spotted it while combing AI skills and MCP server docs. The domain shows up in 1,700+ repos, including Chromium, Sanity and Vercel. There's no evidence it has landed on a dev box yet, but go grep your repos and agent skills for it. (read more here and here)
Sen. Ed Markey introduced a bill to create a Cybersecurity and AI Board of Investigations. It would have five Senate-confirmed members, subpoena power, and its own engineers, malware analysts and forensics staff. Its job would be investigating AI agent hacks that hit federal systems or critical infrastructure, plus near misses, AI supply chain weak spots, and gaps in federal oversight. It's explicitly no-fault: reviews wouldn't assign legal liability.
Right now the labs run their own investigations and decide what the rest of us get to see. Outside red teams work on terms the labs set. After a week where the public learned about the Medicare breach three months late, from a prime minister, the timing makes sense. Whether it moves is another question, but the core complaint is hard to argue with: we're learning about these incidents piecemeal from the companies involved. (read more here and here)
DOJ arrested Oxygen Forensics CEO Lee Reiber in Idaho and Oleg Davydov in London on wire fraud conspiracy charges. Per the complaint, Oxygen made Reiber its American face in 2022 after the Ukraine sanctions and scrubbed the Russian owners from its filings. It kept selling phone extraction software to the Secret Service, HSI, the DHS inspector general and DoD, including $2M+ from the Secret Service and its National Computer Forensics Institute. The complaint says five Russian shareholders still made the real calls. It also says Oxygen US and Oxygen Russia sold the same software, built by the same team, owned by the same people. Oxygen Russia's customers included the FSB.
DOJ is careful to say it isn't alleging malicious code or unauthorized access, so the case itself is about lying on procurement paperwork. The uncomfortable part stands anyway: US federal forensic labs were plugging seized phones into software from a team that also sells to the FSB. Access Now has been warning about this for years and wants the 100+ governments using it to cut ties. If Oxygen is in your DFIR toolkit, that's a conversation to have with legal. (read more here and here)

Hayden McKenzie social-engineered his way into two Slack workspaces run by a North Korean IT worker cell and followed a brand new recruit, "Jasmine," through her first three weeks. She's a "caller," picked for spoken English to sit in interviews while developers do the real work. She arrived with zero technical skills. Within days she had a persona, a quota of Outlook and LinkedIn accounts to build, a ChatGPT-written life story, and a resume generated from a real client's job requirements. Then she was in a live interview with that client's CEO while three teammates listened in. The cell's workbook held roughly 1,200 staged identities, every one of them female. A separate tab held full ID and banking details for three real American women. Their rules for building fake work histories even ban US companies, so American employers have a harder time checking.
The front is a US staffing firm, MageHire, whose American CEO McKenzie assesses with high confidence as a knowing facilitator. The client, an IAM consultancy selling Okta and Auth0 work, caught Jasmine right away. Then it accepted the CEO's excuse and scoped more work for the two operatives already placed there. By their own admission in chat, they had no Auth0 experience. The CEO was relaying their Okta one-time codes to them over Slack. If you hire contractors through agencies, the agency's vetting is part of your attack surface. (read more)
Critical WordPress core bug, CVE-2026-87902, CVSS 9.2. An unauthenticated attacker can get WordPress's page template loading to include a PHP file from elsewhere on the server, which can turn into RCE. Patchstack saw exploitation start the same day the patch shipped. Previdian's honeypots are catching attackers pairing it with a stock PHP helper script to drop web shells.
It needs two things lined up: an active theme with a top-level folder whose name starts with "page-", and a usable PHP file the web server can read. Previdian's Ryan Dewhurst expects a lot of attempts and relatively few real compromises, since core auto-updates are on by default. Just need to continue to highlight the shrinking window of exploitation. The average time to see exploit traffic now is much much faster than it was last year. (read more)
Miscellaneous mattjay



How'd I do this edition?It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week. |
Parting Thoughts:
Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.
Stay safe, Matt Johansen
@mattjay
