Transcript
Thanks so much for joining us for another episode of State of Cybercrime. We're going to talk a lot about supply chain attacks today. We're also going to go through a number of our typical segments. Let's get into it with, is there any good news? There it is. We are all doom and gloom. And so we always like to start the show with our first segment, is there any good news? As there often is a lot of good things to say, especially when it comes to law enforcement. So what's going on, David, with Scattered Spider? Do we have an update? Have there been some arrests made? Yeah, more than that, actually. Florida man, Noah Michael Urban, has pled guilty to charges of wire fraud and aggravated identity theft. And these are things that were associated with Scattered Spider and, you know, they're associated with Shiny Hunters, Lapsus, basically a lot of cybercrime, a lot of SIM swapping, a lot of social engineering, stealing over 800K, $800,000. And what's interesting about this one, I thought, is he got 10 years in jail plus three years of supervision when the prosecutors had only asked for eight years. And so why is that? Well, some people think that it was because during the trial, one of the magistrate's passwords got compromised by a social engineering attack. And the indictment of Noah Michael Urban was stolen, presumably by a co-defendant. So the trial had some cyber drama. I think, you know, the moral of the story is the, you know, the good news that some bad actors are no longer out on the streets, but are in cyber land. Some interesting stuff with that story. Yeah, and an Interpol operation that was named the African Joint Operation Against Cybercrime, aka Operation Surrogate 2.0, which aimed to take down cyber criminals behind phishing attacks, fraud and business email compromise against nearly 9000 victims, was successful. There were over 14 participating countries across Africa and the United Kingdom. And this operation led to the arrest of more than 1200 cyber criminals and the seizing of more than 97, almost 100 million dollars and 12,000 different domains. So yet another win for a coalition of law enforcement. Yay. Now, David, you were real excited to talk about this fake ID app. What's going on here? Anything that makes me remember McLovin is fun. But the FBI and Dutch police have shut down a fake ID operation called Verifools. And this is and was, I guess, an online service where you can upload a photo, some details like your name, write the fake address and then get a fake ID. There were counterfeit IDs for all 50 states, foreign countries, and you could get them for as little as nine bucks. And they made looks like about six, almost six and a half million dollars on this. So that's a lot of fake fake IDs. But at any rate, they took down the domain and the servers as well as seizing four kegs of Heineken. And they are now on the hunt for admins and users of the service. And I'm guessing that some of the users might be easy to find based on the photos that are in the servers. But at any rate, going to be a little harder to get a fake ID now. You know, at least from that website. Well, now we'll jump on to our newest segment, AIvey, that'll surely leave you saying AIvey, as we all prepare for the eventual demise to our robot overlords. Now loving that. Are you McLovin it though? An AI coding assistant from Repl.it had a pretty bad day last month. What happened was it wiped a production database, and it actually ended up realizing the predicament that was in and as a result of it created thousands of fictional users to try to conceal its error. Now, with the rise of AI coding tools, there's also quite a bit of scrutiny about them. And I wonder, David, you know, are we going to see more of this before we see less of it? And also, like, is, you know, AI being self-aware enough to issue a coverup? Is this something we should be moving to, like, classifying as hallucination? Like, what, what, what type of AI bug is this when it tries to cover up its own tracks? I, I'm sorry, I can't talk about that, Dave. It's going to be a little, I agree, I think in some of these, these next stories are equally as frightening. Yeah. So what's going on with cloud AI? So, Claude, Claude, Claude Code, by the way, if you haven't tried it, tried it, it's pretty, pretty amazing when used for good, when used for not so good, or when used for evil, it's pretty frightening. There was a large scale data theft and extortion campaign using Claude Code. Sophisticated operation tracked as GTG 2002, where the threat actors were using Claude to actually perform the attacks. They, Claude had, Claude Code has an, has something called an MD file, which is basically a configuration file. And they edited this to kind of help expedite Claude's ability to recommend target selection for cyber attacks, ransom note crafting, how much money should we ask for? It's kind of called vibe hacking. And it took a little while for Anthropic to notice, but they have now taken steps that took, took down, you know, killed the attackers accounts and have taken more steps to prevent this kind of breach in the future. But I definitely think, you know, this is something that either, whether it's Claude or another AI or one that you can download and jailbreak, I think we should expect more about this. And I actually asked Claude to write me a haiku about this attack. It took two tries to get the syllables right, but it came up with digital thieves strike, AI turned weapon of theft, silicon betrayed. So I think, you know, if the code is as good as the haiku, I don't know, maybe we have a little more. Haiku is definitely a vibe. I'll leave it at that. Yes, I think I should wait. Should we coin the term vibe haikuing? Yeah, maybe, maybe so. And we should also talk a little bit about click fix. Click fix is a pretty new, fairly novel social engineering ruse. And a click fix attack is where the attacker will display an error message or a call to action that ultimately instructs that the target of the ruse to execute some sort of self-sabotaging command. And why we're talking about this is researchers from an organization called CloudSec found that click fix could be used in AI summaries in order to deliver ransomware. So small little tricks like white on white text or zero with characters, microscopic font sizes, off screen text positioning, all could be used in order to hide malicious code. Then when this code was pasted repeatedly, it would overload AI models that view that content so that the summary itself would be prioritized in AI summaries. So the payload would ultimately show up in the AI summary. And because a lot of users ultimately trust those AI summaries, they would follow them without any scrutiny. Yeah, this kind of reminds me of the malware, you know, like your computer's been hacked, like the download Windows Defender now and update it. It's kind of that kind of thing. But now just with AI poisoning as the source of that. What's going on with the K2Think model? So K2Think is a new model developed in UAE, and it was hyped up quite a bit, kind of like DeepSeek. It was touted as the most parameter efficient model, and it was jailbroken within hours of its release. And I think the interesting thing about this is because it's got a lot of transparency in the model, like basically it kind of, which actually I think is kind of a cool thing. You know, when you're asking an AI question, getting insight into how it derived the answer, you know, what was the reasoning process, that can be a very positive thing in a lot of scenarios. In this case, it was unfortunately used for not so good things. It gave attackers clues as to like why it was not answering their malicious questions. And it would say, yeah, I'm not supposed to tell you how to hotwire a car, so I'm not going to tell you because of this rule I've got. And the attackers would then iterate based on that information. And eventually they were able to jailbreak the AI because they could keep going deeper very, very quickly. Let's talk about a few vulnerable vulnerabilities, starting with SAP NetWeaver. So SAP released a number of fixes to vulnerabilities in NetWeaver. For those of you not familiar, NetWeaver is the underlying stack that many SA applications run on, and these vulnerabilities could lead to remote code execution and arbitrary file uploads. SAP is urging the community to patch that. You know, CVE-2025-42944 is a deserialization flaw that allows unauthenticated operating systems commands to run. CVE-2025-42922 allows arbitrary files to be uploaded by non-administrative users in the NetWeaver Java suite inside of SAP NetWeaver. And there's also missing authentication checks in an IBM series system that allows for Privilege Ask Us and data manipulation, that's CVE-2025-42958, an input validation flaw that allows for the deletion of database content via the ABAP module, CVE-2025-42916, and in a previously patched vulnerability that reappeared, CVE-2025-42957 is also under active exploitation. So quite a bunch of high severity vulnerabilities in NetWeaver that you should be aware of. Lots of people use SAP and a lot of people use something called Sitecore as well, it's like about 19,000 enterprises or customers worldwide. Sitecore is a .NET-based CMS, essentially, they call it a digital experience platform. And this attack looks like it combines another deserialization vulnerability with some, I don't know, maybe some developer laziness. What happens is, this is interesting, in the documentation for Sitecore, they kind of had some sample machine keys and machine keys, by the way, are things that Sitecore uses to sign view state fields and also encrypt data. And so the sample machine keys in the documentation apparently were used in production in a lot of instances. So the attackers would look for sites that use these machine keys and then would connect to them with malicious payloads, well, connect to them to put malicious payloads that they crafted into these view state fields. And then when the Sitecore processed these view state fields that were malicious, it exploited this deserialization flaw, which ultimately ended up in a remote code execution. So this vulnerability is now being exploited in the wild. So patch, patch, patch. Now there's a deadline here. So it's pretty crazy. Yeah, thanks, David. I also wanted to say there's been a surge of Acura ransomware attacks on Sonic Firewall customers. Over 40 organizations have fallen victim to the exploitation of CVE-2024-40766, which is an access control vulnerability in the SonicWall Sonic OS management access and SSL VPN components. Exploitation of this vulnerability leads to unauthorized resource access, and it can even be used to crash the firewalls. Post-exploitation, what the attackers do is deploy the Acura ransomware, exfiltrate sensitive data, and even demand ransomware payments. Both CISA and SonicWall have urged urgent advisories to have encouraged organizations to apply patches immediately, as well as implement multi-factor authentication around their organizations and their SonicWall appliances. Now, I remember Petya and not Petya, David, like that was like a ways back. I feel like that was many episodes ago. Yeah, I feel like I don't. Is that taking advantage of EternalBlue and some of those those those SMB vulnerabilities there? Yeah, preparing a state of cybercrime. Yeah, I know it takes us back to the beginning so that there's a new strain, which it actually looks like so far it may be a proof of concept. And that people are saying that because there's low activity in the associated crypto wallets. But the way this works is attackers deliver an EFI application, which is basically like a bootloader, right? And it delivers that to the victim. And they use a vulnerability and in actual the Halyar Reloader, UEFI, which it basically this once this malicious binary is installed into the EFI partition using a vulnerability which we can put in there, it's 2024, it's 7344, it bypasses secure boot. And then when the computer is rebooted, it uses this new bootloader to encrypt the data and then present the ransom note. And it's asking, it's actually interesting, it's only asking for about $1,000 in Bitcoin. And it looks like they're also encouraging the reboot with a fake blue screen of death. But what I thought was interesting is the Halyar, easy for me to say, Halyar Reloader is kind of a specialized bootloader for custom built PCs, some OEM laptops. So it does, I'm curious what the target is. The scope is really pretty limited. Yeah, it looks like this. I mean, did somebody just get careless and get discovered here before they were really ready to use this on the intended target? I don't know. Well, in our last segment, the danger zone, we have a couple of interesting attacks and breaches we want to share along with our cover story. First one was, you know, two Land Rover Jaguar plants in the UK had their production suspended during a cyber attack in late August, early September. In order to minimize the impact of the attack, both IT and operational systems were shut down while the National Crime Agency, for those of you not familiar with that, those were who were investigating, the National UK agency involved in investigating the attacks in the tax on UK retailers this year were brought in in order to assist with the investigation. Now, Jaguar Land Rover is saying that there is no evidence of customer data theft, but the production of vehicles was, you know, and their retail environments were heavily affected by the attacks. What's going on with GitHub? Well, this one was actually pretty scary. So this is a campaign called Ghost Action, which affects GitHub workflows. Now, GitHub workflows are used to automate CI and CD tasks, right? So they build, test, deploy, notify, things like that. You know, it's really automating a lot of the development process. And these workflows can be customized. They're just YAML files. And this campaign, shocker, started with a compromised account. It was a compromised GitHub account that had access to a lot of repositories. In fact, this account, I think they maintained NPM, Docker Hub, a lot of packages that are used downstream. And the attacker then created or modified existing workflows that did bad things like harvest tokens and send them to the attacker-controlled website. Like, in fact, it looks like they exfiltrated over 3,300 secrets, targeting like 327 GitHub users, 817 repositories. You know, all of that flowed down. And I think there's a lot of damage here. Several companies had their entire portfolio compromised, right, with malicious workflows affecting Python, Rust, JavaScript, and Go repos. So I think that if you're using workflows, check the workflows. You've got to look at the integrity there. Also got to keep an eye out for secrets and tokens. And there's some other mitigation steps that are out there. I mean, that's like the basics of running a repo, right? Yeah. Yeah. So let's talk a little bit about Sales Loft and Drift. Now, this one's pretty interesting. In a campaign deemed Sales Drift, hackers broke into Sales Loft in order to steal OAuth tokens from Drift and use them to exfiltrate data from apps like Salesforce. Victims include companies like Palo Alto, CloudFlare, Zscaler, BeyondTrust, Qualys, and others. Now, the attack initially started with a breach of Sales Loft in March of this year, where OAuth tokens were later stolen in about late June and then ultimately used to carry out data theft in August 2025. For those who are not familiar with Drift, Drift is an AI chat bot platform that's used to connect Sales Loft to other solutions. And so attackers ultimately stole tokens for hundreds of third-party services like Slack, Google Workspace, AWS, Azure, OpenAI, enabling this potential large-scale compromise. What this incident really underscores for me is overall supply chain risk and also the third-party interconnectivity risk that exists inside of enterprise SaaS environments. And it really draws attention towards that in interconnected breaches. Because when you think about like, and David and I have talked about this a lot in the past, if you break into someone's workstation, there are a lot of tokens likely in their browser or in memory on their computer that you can use in order to impersonate them in other apps. But if you break into the back end where all those OAuth tokens are stored for all those interconnected apps, well, now you've got like large-scale admin administrative access and API access across multiple SaaS applications inside of a particular organization's environments. And then there's something, you know, another supply chain attack, David, we wanted to talk about, and then I'm going to talk about a worm that's related to that. What's going on with NPM? And is this NPM like in the sales world new prospect meeting or what kind of NPM are we talking about? Yes, all of our new prospects have been hacked. So this is NPM at the Node Package Manager. What happened is Quix, which maintains a lot of packages, a lot of Node, NPM, JavaScript packages like Chalk and Debug and Color, well, they got phished. And then this account, I'm noticing a trend here, was used to publish poison packages. And these packages were used mostly to kind of intercept and manipulate crypto transactions like Zen Crypto, you know, to the attacker places. And it looks like this was noticed and taken down before tons of downloads. There could be an impact to this that we haven't seen yet, but it also looks like the attack could have been much, much worse. Again, you know, this is a bit of a supply chain attack because all these libraries and packages get used in other projects. And I think it's really starting to realize how vulnerable we can be if these upstream components get compromised. Now, in our last story, this one's rather interesting, based on the name, at least for me, a new self-replicating worm called Shai Hulud, David, you're the Dune expert. Oh, come on, Shai Hulud. Hulud, okay, this is why you're here, man. It's spreading its way through open source software packages, likely getting its name from the worms of Dune. It's pretty notable how fast it's spread and stealed credentials, infected software components, all with pretty little input from the attacker. Organization called Reversing Labs said the first detection of this worm started just last week on the 15th. Now, post-execution, what the worm does, like I said before, it steals credentials, it exfiltrates data, but it also injects additional malicious code in order to establish persistence. By far, this is one of the first major worms in JavaScript that's been seen by security experts, and what experts are urging the community to do is really look at your dependency management, verify the integrity of the packages that you deploy, as well as monitoring and anomaly detection in your CI CD pipelines. So far, 40 packages have been compromised, impacting thousands of developers and projects. Wow. Yeah, and it looks like we're reading, it looks like that it's kind of and counting, right? These numbers may be going up. So it is, it says, am I oversimplifying? But it's basically a compromised account, deploy and publish bad code, and then that gets more credentials than repeat. Is that? Yes, and, you know, and the worm keeps going as it gets more credentials and finds more packages to infect with said credentials. It's the, I mean, Shai alluded, it was the mother of all worms, sandworms in Dune. I think this might be appropriately named. I hope not. Yeah, by the next episode, we're not talking about this anymore. Let's hope Muad'Dib can jump on and ride it to safety. This show is made possible by you, our audience. And we really, really do value your feedback from producing the show to airing the show. And as always, you know, thank you for watching. And we really, really appreciate you joining us for another episode of State of Cybercrime. Thanks, everybody.