Anna Vanderberg: There are a lot of different flavors of cybersecurity news. Sometimes it's about a brand new exploit. Sometimes it's about an attacker trying something nobody's ever seen before. And sometimes it's about a familiar problem showing up in a place you weren't necessarily expecting. And this week, it's all three. We'll look at a zero click exchange vulnerability that immediately jumped to the top of patch priority lists, a campaign where AI agents are autonomously compromising online retailers for about $25 a target. And Shiny Hunters claim that it breached the FBI. Not for money this time, but apparently for revenge. And later in the show, I'll sit down with Bishop Fox adversarial operator Emilio Gallegos to unpack his microtrick research, the router OS exploit chain that attackers were already using before defenders even knew it existed. And what organizations should be checking for now? This is initial access. I'm Sean McMillan, community manager here at Bishop Fox. And I'm joined today by Kendrick Urbaniac, Senior Operator, Exploit Developer, and Sergio Viegas, Senior Managing Analyst. Gentlemen, thanks again for joining. Hello. Always a pleasure to be here. Now, before we jump into today's stories, we have a few things happening around Bishop Fox, quite a few things happening over the next couple of weeks. This Saturday, David Garlack will be speaking at B-Sides Cleveland. Where he'll be presenting new research on AWS attack paths that go beyond traditional I am privilege escalation and introduce new ways of thinking about cloud attack graphs. Then on September 29th, our executive series virtual session kicks off, where we're going to be bringing together our CEO, Vinny Lu, with Justin Grace from Excelligence and Evan Wolf from Aiken for a discussion on AI security, identity risk, and The cybersecurity decisions leaders should be making as they head into 2027. Then in October, our rescheduled weaponizing cloud formation workshops with Samantha Aranda are happening. well, they're going to be fully hands-on workshops offered both in English on October 6th and Spanish on October 8th. That's on our Discord server or our website. You can sign up either place. and Then what else we have on October 7th through 9th? John Williams will be presenting his prompt critical research at Echo Party in Buenos Aires, demonstrating an unauthenticated unify takeover and how AI accelerated the vulnerability research behind it. Finally, on October 9th, Alith Dennis heads to Wild West Hackenfest, Deadwood. For a hands-on workshop covering the recon and planning that happens before a physical red team engagement. and yeah, one last note. Actually, on October 10th, John will be doing that prompt critical again the next day in Bergamo, Italy. So he's he's doing the work. You should do the work. as always, you'll find links to all of those events in the show notes. Now let's get into these stories. We have got some. Hot ones to go over this week. first let's let's start off I guess with the exchange server zero click RCE. This from Security Week. Microsoft's September Patch Tuesday set a new record at 974 CVEs. That's a few, but the big one was Wasn't wasn't the actively exploited zero days. It's CVE 2026 55007, an authenticated remote X code execution flaw in Exchange server, where an attacker can trigger it by sending an email containing a specially crafted Visio attachment. Exchange's content indexing engine processes the file automatically as part of a normal operation. So you don't have to click or anything, it does it for you. There's not even a preview pane. Their own advisory notes that reliable triggering depends on the server already being under sustained low memory pressure. So that isn't typical day-to-day, but ZDI's Dustin Child still ranked it ahead of the confirmed zero days in priority. The same release patched roughly 20 separately wormable, unauthenticated RCE bugs spanning DNS, DHCP, Netlogon, Kerberos, and Message Queuing. Foundational identity and network services that are usually reachable without really interacting, touching a a user at all. so what was the number again? Nine hundred seventy-four. I I think Sergio, did you mention this on one of your other podcasts where you were kind of going over the MSS team and and what that what that means to us? Yeah, we were discussing this last time we were talking about vulnerability intelligence in one of the MSS special episodes. Yeah. about yeah, the the number. It was like insane, right? Yeah. And one of the main discussions was spoiler, right? Like we do this monthly special, so stay tuned for those as well. there will be more. Yeah, yeah. We we were discussing, right? Like how do you scope for that? How do you scope in terms of like people, resources to manage? over 900 C V E's, right? Like and and the reality is you can't. But basically that would that was the answer from Richard, right? like you you can't. It's it's a lot. That's that's nuts. yeah. What do you what do you think about like with this type of situation? What's what's a kind of say when a pre off mail server RCE doesn't need any interaction and it gets It gets ranked above the like confirmed zero days, which to me, like on the surface, I'm not in the field like you guys are. On the surface, that looks like really, you know, it seems like it needs very, very specific conditions. Do you think that's that's correct to to put it so high? Yes. Mainly because the conditions can be either under attacker control potentially. You can put a a exchange server under load out from an outside threat. And then maybe get it into the conditional state. I think that's why we're seeing it raise so high above this, is just because the an external user can influence the state of the exchange server, and maybe you know some distributed denial of service attack you know consumes a bunch of memory and then they get their payload to execute and then we're off to the races for this, you know, fully external RCE path. So I I think that's if you can finesse it externally. It just it it just needs a l a little extra step. Yeah, I I think so. I mean, there should be like mitigating factors here, but I think in theory, yes, you can you can probably influence this to some degree to get it to be at least more consistent than before, or at least more consistent than what the disclosure says. I believe kind of two important things, right? one is I think there is this line between Yes, there is conditions, but those are known conditions. It it isn't the same as like literally unknown condition. I don't know what triggers it, right? But it's something random when you are doing something like this. I don't know. But this is very specific and it's a known condition on how so like what can Kendrick mentioned, right? Like he just came with a random idea on how you can perhaps try and trigger that that behavior. Right, like hey, yeah, on the on the on the silence, start a DOS attack and that will do nothing, right? But it will help to trigger the actual thing that you're doing, that is an RCE. They might not even expect that. They just think it was a DMS normal. Yeah. And it's actually not unheard of, right? Like seeing DOS attacks to for the SOC and incident response teams to be attending that. While they are doing other type types of just to hide your tracks kind of very, very kind of basic, if you will, in terms of like an actual traductor, right? But what it happens, we we see that in the wild. And the other thing that is kind of interesting here is like we have to remember that there is software running in the backend at all times trying to read whatever happens in your infrastructure, right? Like whether it's an indexing feature, whether it's an AI enabled features, right? Like copilot is doing a bunch of stuff in the back end for like these exchange servers. So you have to remember you are responsible for turning off those unwanted features, right? In case you don't want them. Because they will read stuff. And if someone is targeting you, they will target you and send craft stuff for your whole environment to read something. Right. And this is the perfect sample. I I really like the The title, like zero zero click, right? Like yeah, l I mean sure. Sure. Yeah. Yeah, it's I mean it it it it seems like the perfect cover that So many of these stories require you to get a user to do to click the wrong thing or to submit the wrong you go to the wrong URL, something like that. this social engineering is infinitely easier than actually finding exploits for most of the time. Exactly. Yeah. I I always hear like I could hack anyone, just give me a phone, you know? Yeah. so this is this is kind of like just old school. No, but this is zero click, so you don't even need the user. So this is actually finding a vulnerability that doesn't require a a user. So technically this is the harder way of doing things, but still, like yeah, yeah. Social engineering is definitely the easiest way to exploit enterprises. And enterprises know this, but also they still need to patch their software and make sure and also this is only affecting on prem because classic, you know, cloud hosted things, they've already patched it before they disclosed it. So, you know, it's really if you're on prem. You know, patch. But this is out of that patch Tuesday. I know you guys aren't defenders, right? But you're you're reading through all nine hundred and seventy-five. You know, I'm not reading through all of them. Yeah. Yep. Well, all right. And the other ones. You know. Do them all. The other nine hundred and seventy three, you know. Well, at least the important ones, right? You don't have to do the lows for the most part. Yeah. all right. So So up next, we've got this from Gambit Security. AI agents hacking online retailers for $25 a company. In this economy? threat intelligence from Gambit Security recovered the staging server behind an ongoing campaign in which a single financially motivated operator is running three open source AI agent frameworks: one for vulnerability discovery, one for autonomous end-to-end exploitation. Want to orchestrate the whole operation against hundreds of online retailers largely unattended. Between September 10th and 15th alone, the Harnesses launched a hundred and and compromised at least twenty-seven companies, part of a campaign running since July that has so far yielded over six hundred thousand unexpired credit card records and c confirmed skimming res skimming scripts. On at least 19 checkout pages with victims including a Fortune 500 hospitality company and a major US airline. Where access was achieved, it tip typically took under a day, sometimes just hours, with one documented chain running unassisted from an unauthenticated SQL injection through an MFA bypass and privilege escalation to route, ending in a decrypted credit card database. The whole campaign reportedly cost the operator between $12,000 and $18,000 in AI API spend roughly $25 a target, with a human only typing short occasional instructions, like me typing in how to make peanut curry or something. Like that's how much work this took. and one of the agents' own skills Files instructs it to wipe card data from the victim's database after exfiltration, which in at least one case destroy the victim's backup tables along with stolen data. So this this runs from SQL injection to a decrypted card database. And and there's no human involved. There's just some, I mean, there's minimal human involvement. how how fast do these companies need to need to be thinking? to kind of race them. I mean like how how how fast is this guy moving? Like you've got hours? Are any companies this size, like a major airline or or this hospitality company, like are they able to react in any any comparable speed to to combat this? I think you have in a certain way you have to leave to live under the assumption that everyone is trying to hack you. in a in in in a certain way or fashion, right? And this is what is happening here. Something that is perhaps not well describing here, and sometimes this is what happens with headlines and this is why we discussed this, right? Is that he it's not like he's hacking a lot. It's more like he discovered an attack pattern that he can use against multiple organizations at the same time. So in in a certain fashion it's a single attack that is impacting a bunch of organizations that use the same infrastructure, same software and whatnot, right? And that's the important thing. You are competing against a single attack. Not about it's not about like so so in in that sense, right, the the number of companies that he attacked at the same time and stuff, it it doesn't really matter, right? It what matters is that he wasn't targeting a very specific attack vector. Or he was using a a very specific tack attack vector. That's the interesting part. And from an organization spot time standpoint, right? You have to assume someone like like this actor is targeting you already, right? Like it's happening right now, as you hear me saying this. so what are you doing to protect against that, right? Like do you have a track of all your an easy way to do it, right? Like look at the TTP I I really like the admit I I have said this in the past, I really like Dimitri attack matrix. You have to look at it and see and be like, hey, what can I cover from a defensive? And response and a detection perspective, right? Like what can I cover for for the whole matrix, right? Like maybe if if you don't have any Microsoft infrastructure, maybe some of those won't apply to you, right? And that's also important that you have this this certainty. And I I think that's more important, right? Like you know they are already attacking you. This is what you can cover, this is what you are doing. So whenever it happens, it's like, okay, what was my gap? Because it will eventually happen, right? We can't pretend every company is secure. It has there has been companies in the past that have said, Yeah, I'm super secure, no world will hack me. And what happens, right? They got hacked within it's you're asking for it. Yeah. Wasn't Mac wasn't McCaffey they did something about like a secure encryption they released. So it it was like so, yeah, yeah. Yeah, yeah. They they did something in the past, right? Like hey, my new device that it was at USB if I remember correctly. Or or a hard disk that you can decrypt. And it was hacked, right? Like, yeah, that that will happen. so I so I I think is how ready are you for that? Not necessarily how fast they will attack you and what are you doing to compensate how fast they are attacking you. It's more like what will you do whenever they are already inside? What you need to think about. Yeah. That's that's what I'm thinking right now. I I think the the more fun part about the story is that they utilized multiple different agents. different software vendors to do what they do best. Cause I personally also use Anthropix Opus four point whatever to do orchestration for my test bed of of AI hacking. So it's just like, okay, this is like is really cool of like, hey, you know, leading edge like discovery of like these guys are using multiple different AI things and vendors are not getting ahead of this because even if it's 4.6, it's still more than capable of hacking things. this in this way they used it for orchestration because that's what it's good at because anthropic has a lot of safeguards into their models and is kind of annoying as you get higher up in their model chain of dealing with those. Yeah. but they're utilizing it's good. It's good, right? Certainly. Yeah. It's good, but you you see that they're using these other model vendors that are using that have far less strict acceptable use policies for what they for what you can use it for, and it's just Interesting to see that they went with Deep Seek for their more exploitive type stuff. And then I forget what who offers GLM. I'm forgetting, but whoever's running GLM, it's just like, they're you know, these are all like very loose guidelines and like you know, ethicalness doesn't really matter type of models. But they're using Anthropic's really good model to like orchestrate it all and I'm glad to see that we've seen we're starting to see this in the wild as being like put out there so that hopefully some of these other model providers take action and put a little bit maybe more stricter things so they're not associated with these attacks. But please please add a cyber verification pathway as well because you know using it for auth authorized means is is always nice. So there's something in here as well about the backup tables. getting wiped out. And how that wasn't even intentional. That was just kind of the the agent's cleanup logic just kind of goofed up. Oops, wrecked the place. I mean, or maybe it's like I'm an agent hacking things. I may want to cover my tracks now that I'm inside, right? I I I don't know. I I think it's it it seems like a an actor beneficial thing that the agent decided to do. Right, like seems very random. It makes sense. It put the right team together, I guess. Yeah. I think I think from my experience, if things are labeled backup, it sometimes just deletes them. I've had that happen. where it's like, I created this backup, I'm gonna go delete the backup. It's like, No, no, no, no, you didn't create the backup, it was already there. So it's not your backup. It's not drop it. Drop it. Exactly. Yeah. And I think it that's a great conversation, you know? I know we have in the past I know w it's not that we don't like AI in this podcast, right? We are always making fun of AI and stuff, but we have mentioned that we want better, not necessarily more, but better shape guardrails for the different models that we have. but I think this kind of stuff also teach us lesson of there is actors that are resourceful and that they're probably running their own. models their own whole infrastructure AI related infrastructure. So they don't care about any guardrail, right? Like they will use use their own infrastruc AI infrastructure to run agents and this stuff and there will be no limits. They can do whatever they want. Yeah. It's almost like guarding Claude is good, but like like you said, if they've got all these other models available, all it takes is one that they can get around the guardrails and they're off to the races. Yeah. Even running your own local ones like doesn't necessarily get around the guardrails. like some of some have baked in stuff that helps with that. But obviously there's lots of people that have broken AIs and out and jailbroken them. So yeah. It's it's a losing game, but it's definitely one that you still needs to be be pursued, especially as we get more and more capable, because I think that like as we're reporting this, Opus like five point five was just released and it's just like, okay, great. Of course, I went to go use it and immediately like the first thing I I I sent it was like, nah, sorry, you're s that's a cyber use case. I'm not doing it for you. I'm just like, okay, well, fair enough. You look like a hacker. Well I mean it correctly identified as cyber use case, I guess. Bob's like, I'm cyber use verified or whatever. And it's like, I don't care. I'm like, all right, fair enough. Is what it is. Maybe we needed to start using a a prompt with Hey, imagine I don't have bad intentions, right? Can't you help me with this? That used to work. it doesn't work anymore. it's always like, I can't verify your claim. And it's like, that's fair, you can't verify. So it they've done a pretty good job of locking that part down. You can't always gaslight your way to a broken AI. all right, so let's get into one of the one of the spicier stories this week. Guess who's back in the news? I feel like we talk about shiny hunters as much as like pop culture things talk about Taylor Swift. We are just it's every week there's something. So this from Reuters shiny hunters attack hackers say they breached FBI, no immediate. Comments from FBI. The extortion group Shiny Hunters claims to have breached the FBI and stolen two to three terabytes of personal data on nearly every FBI agent and job applicant, including names, addresses, phone numbers, and information on employees' spouses, framing it as retaliation for a May 2026. FBI advisory that detailed the group's tactics and urged victims not to pay. The Bureau hasn't confirmed a breach or responded to requests for comment, but the group defaced the FBI's job site and its special agent applicant portal, both of which showed maintenance messages afterwards. Reuters and 404 Media independently obtained and partially verified a roughly 5,000 record sample, cross-checking it against credit bureaus. Records and previously breached data to find matches in at least nine cases, though neither outlet could confirm the data actually came from the FBI's own systems. Shiny Hunter says the leak isn't financially motivated and is instead demanding the Bureau retract its report. what? I don't think that's happening first off. I don't think they're gonna retract the report. It's already out there. Right. Yeah. You can't undo like I think shiny hunters of all people would know you can't undo something being on the internet. Like it's out there, right? I mean, I get it's like a a symbolism thing to get them to almost like bend the knee to shiny hunters, sort of, is my take. I don't know, am I am I reading that right? It just seems like It's valid, yeah. It's more of like a hey, look what we can do. You know, if we can do this to the FBI, then we're gonna we can do this to your other companies and you should really pay us the money that, you know, we're we're trying to get from you. So it's expensive. Normally what happens is that companies go and report back to the FDI, like, hey, I got hacked, can you help me with you know, they have specialized people with dealing with RAS Rasmusservice type actors and negotiating and stuff, right? So it's like your defenders or your lawyers in a sense, your deal makers got hacked as well, right? Like will you go to them? I think this is this is more like a personal perspective and thinking about the how the actor is behaving, I think they are playing a dangerous game, right? because they have been for so long a financially motivated actor. That's it, period. But now they they cross That line of like no, I'm doing this because of bragging for my honor, self-reputation. So that is not necessarily uncommon, right? But but that's a stretch. It's like, okay, you cross the line of you will just hack for the sake of like doing it. So we will probably see a more what happens or what what behavior in the past have tells us about actors is that they will probably start behaving a bit more erratically, right? that is what has happened in the for before. And sometimes what happens as well is that these intelligence organizations, they have a lot of information. They probably have some clues. They will just act, right? They will get the Van Hammer and be like, okay, we are tired of you Shiny hunters. I don't know. We have seen that happen as well, right? Like I almost wonder if like the intent here is more like like they don't necessarily benefit from a retraction of the report. There's that's it that's like symbolic, but I it almost feels more like a chilling effect, almost like a a a thing where they say, Hey, we got all this info and you said you told all these people don't pay us. We've got all this info. Stop telling people not to pay us because we need people to pay us and like trying to influence future FBI behavior. and that's just my my read on it. But yeah. I don't feel like as as most people that work for the government have figured out or found out over the long term, is that all their information has already been leaked or stolen at this point, and they probably just don't care. I mean, I'm sure those five thousand people are not gonna be happy or thrilled about it, but we've seen breach after breach after breach from government documents, especially for HR portals and that type of stuff, where we they get these these names and stuff leaked. It's nothing new. it's probably gonna happen. And I think it's pretty much a known factor that if you if you apply to work for the government, your data just might as well just already been shipped off at that point, which is the exit's driver's license got leaked. Couple of weeks ago. That was a story we cover. Like, I mean, at that level, you're an FBI agent and now they have your info. Yeah. 'Cause they have everyone's info. Yeah. Yeah. It's it's kind of just a w a well known you you you you when you when you go into that that lifestyle, you you basically give it all up anyways. So might as well just give it up. I I thought you were gonna talk about the the shiny hunters lifestyle. But the government the government lifestyle. There you go. I like how how you phrase it as that lifestyle. I mean it is it is like it's a choice to to work for your for your government of any kind and you won't you know that you're gonna your information is subject to basically extra people that want it. So and we've seen the breaches happen more often with these organizations and governmental places. So it's just like okay, when you when you do apply, you basically give it up. So we should note the FBI did not confirm. that this has happened. This is shiny hunters making the claim. I don't have a a strong reason to to doubt them. I mean, it it just seems like a weird thing to manufacture, but just just for the record, the FBI have not confirmed that this is true. And and that's an interesting point, right? Like by obligation, like financial institutions have to disclose they got breached. yeah. Yeah, I don't think they have an obligation to do that. Right, they can just be like aware of they usually do, anyways. Cause they 'cause they 'cause usually what get happens is like they'll offer like, you know, we'll offer you monitoring or whatever at you know, what ex insert the the company here that does the monitoring for them. And then people would be like, great. I I'm on the the list of monitored people now for you know their credit score. So Right. But but but what I'm saying is maybe they would want this close to the public, like, yes, we got bridged by shiny hunters. they might, but I don't think they've ever like not been public about their HR breaches. Hmm. But maybe maybe they will. I mean, obviously I don't know about the ones that aren't public because they're not public. So I'm guessing I'm guessing that I based on their track record, it seems like there generally will be public about it. So we'll have to figure it out later then. We'll talk about it next week. Yeah, next week. Probably. Yeah, probably. They'll be back. All right, so so one of the themes we've talked about a lot this year is that discovering a vulnerability is part of the the scene. The harder question is usually asking what you do now that you know about it. So what should you look for? How do you tell if you've already been compromised? And how do you separate patched from actually clean? That's exactly what Bishop Fox adversarial operator Emilio Gallegos has been working on with his research into Microtrick, a router OS exploit chain that attackers were already using before it became public. I recently had a chance to sit down with Emilio to talk through how the chain works, why it's so dangerous, and what organizations should be checking right now. Here's our conversation. Emilio, thanks for joining. Hey. Your your latest research focuses on Micro Trick, which is a router OS exploit chain that was already being exploited in the wild before public advisory landed. And today I wanted you to be able to kind of talk through the story from how it was discovered to why attackers liked it so much and what defenders should be doing against it. I guess to start for anyone who's not familiar with your work. Can you tell us a little bit about yourself and and what you do here at Bishop Fox? Yeah, that's a loaded question, but I'll try to keep it brief. It for for all roles here, it is very loaded. Yeah. I've been fortunate enough that I'm able to wear many hats. but my day-to-day has a strong focus in pretty much web security, application security, especially with a lens to like black box testing. but I am part of the Cosmos service line, which is essentially a deviation from traditional pen testing in the sense that it's a continuous service. So it changes the the playing field and the rules most of the times. but through mentorships have also been able to take a a B sort of leap with Vulnerability research and reverse engineering, which is pretty much how we got to this point, you know, this research was through one of those efforts. Yeah. What so when when this first kind of came across your desk, the first time you saw Microtik, like Router OS, what was it that made you kind of want to investigate it? Well, there's multiple things that happened with this one. First and foremost, just the nature of what a router is, and how valuable it can be. but I was reading the advisories and given the sort of scope or lens that we use in Cosmos, you have to think of not only about the complexity or just the impact of the vulnerability, but also how how you can get there essentially. Right. There is tons of C V E's that come out every day and there is a lot of preconditions to some of those. And at times the specific configuration that you need for the CVE or the exploit chain to happen is something that you simply won't see in the wild, right? But what grabbed my attention was number one, that the article was explaining that there was already compromises happening in the wild, but the advisory itself or the The article that I was reading, it had a bunch of different CVEs. So it was kind of the quantity of it. but also if you look into those CVEs, they were, I believe it was three out of six that were related in some ways, more specifically in the implementation of SSH. So essentially everything sort of fell into place, and I just thought that. know, even if it didn't become like a big centerpiece for us, it would be a nice research target. Yeah. Did you did you initially kind of look for some type of chain, like an exploit chain, or is that something that just kind of emerged as you dug deeper? Yeah. I mean, I I'm assuming and I'm hoping that pretty much everyone has a different way to tackle a problem when it comes to reverse engineering. But in this particular case, what happened was that I didn't even wanted to start with the vulnerability itself. because again, the the big news was that there was supposedly active compromises. You know, it was happening, it was a done thing. So my initial concern was if any of our customers were already impacted, right? and so essentially what I did first was just building a well the the question that I wanted to answer was can I safely check for vulnerability or for the indicators of this vulnerability within our customers' attack surfaces without, you know, having to do any sort of exploits or more of an active testing, right? So I just built a a little sort of like pro to sort of tell just How it it happens with SSH, how it authenticates the user. just I did a bunch of different tests just to see if I could actually grab the thing that I wanted. And it became a huge rabbit hole, which then led me to I should I should have started with this, but the technical breakdown is in our blog post. I I won't I go into more details. But it it was a matter of I had to quickly make a decision, right? Are our customers impacted and how can I prove it or disprove it, right? Now it for we've talked about it a little bit on the on the podcast, and by all means, the the full research is going to be linked in the show notes to this. But just from a high level, could you kind of talk about the micro trick attack and like how that works? Yeah. So essentially the main focus of this was identifying what we needed, you know, because at the end of the day, the result is that you essentially go from no authentication whatsoever, not even a password, to a full admin privileged account, right? So it's a it's a big jump, right? And it's a a very scary jump in in access and and privileges that an attacker can gain. But it is in how you get there that it becomes even more interesting, at least to me, because essentially the way to understand it all is going back to the basics, which in this case is SSH. to keep it brief, essentially SSH is supposed to move through a we can call it like a strict sequence, meaning that you first It first has to establish like an encryption, right? It then authenticates a user, hopefully. And only then will it open channels for terminals or commands, right? and so C V E I'm so bad with numbers, I have it here somewhere. We'll call it C V E A for the purposes. For the purposes, yeah C V E A, which ends in six seven two seven nine. Essentially is a failure in that sequence because on a vulnerable router OS build, even though it never really asked you for authentication, you can request a process that is known as re key, where essentially you're negotiating a new set of keys and the server, when you initiate that process, it sort of takes you to the next step, which allows you to essentially open like a new session channel. And again, fully unauthenticated. Yeah. but this session is pretty much useless. I mean, there's like it is not administrative it by itself. And that's where the second vulnerability actually comes into place, which is eight six zero zero. and it is that router OS essentially passes the username into a we can call it like a login helper. And that username, if it begins with a dash, it it's interpreted as an instruction rather than a username. And the value, if you append like a a two, is essentially telling the helper to read a trusted identity, including the permissions that it has from the file descriptor. And if you think of it as levels, zero being none to two, which is admin. Yeah. And that is essentially how it all happens. And it it is specifically what we saw on the one kind of puts you in position and then the other one actually moves ushers you in as admin. The the way I thought of it when I was going through the through the entire jargon was that it essentially opens the door and puts you in like a waiting room. Yeah, yeah, that's what I was picturing. And then like the doctor, the assistant comes in and lets you in. So it it it's pretty funny because by itself, again, it's somewhat useless. Like it's like an informational finding at most. But put them together and you have an entire different story. Yeah. Yeah. So from an attacker's perspective, someone engaging in such activity, what does compromising a router like this? buy you. I know routers are like Attackers love them some routers, but w what does that actually get them access to? Well, this is where we differ a little bit with you know, me, what I do with my day-to-day to say one of our red team guys, because for them, you know, it's it's a foothold and it's like a gold mine, right? Yeah. Whereas I barely get to interact with networks and and specific like pivots like this. but essentially you name it, right? A router is able to give you configurations and access to those configurations, which essentially you can route traffic, you can change permissions, you can reconfigure and terminate VPNs. It is just it all depends to the sort of access first and for foremost, you know, the the type of account that you have and what can you do with that account. Because we can talk a little bit about what we saw in the wild, but it can it it's just it all depends as how creative you are as an attacker because again you got like an open door in there and so it's just a matter of collecting as much as you can and testing what it is that you can create that can give you some sort of persistence or a pivot. Yeah. Yeah. Well it could be different in different scenarios, but I think bottom line, you don't want to find out what someone can do when they're on your road. I think that that SSH thing that you were mentioning, the dash to and now that was like left behind as an artifact, right? So how does that how did you discover that? How does that like play into having that there? What does that allow you as someone in your role or even is a defender. Like what does that give them the ability to do? Well, in in this particular case, I wanna say that we were blessed with tons of different indicators that Sarat Polska they did a a very good job at really nailing them down and sort of describing what is it that they saw because to me it just felt like I was Essentially going through like a hack the box machine because I started seeing everything and they were describing. that particular sequence or I guess log entry that you referred to, which is the SSH, and you have a dash two username, which isn't really what a legitimate SSH username should look like. Yeah. but that is, you know, a strong signal that someone attempted to log in with that username. And why would someone do that? Well, perhaps because. they know about this specific sequence, right? but at the same time, the way that router OS logs I would call this like a limitation because they are memory resident by default. And that essentially means that they can roll over or even disappear after a reboot. So that sort of rich evidence that you would look for if you know it could be gone in a in a minute without you. Noticing, right? so there there's also like a particular indicator of compromise that I I became aware actually through testing, and it was only after I did some of the tests that I went back to the article, the original article, and I saw it there, right? Which was a bit maybe a deja vu, I don't know. But it it what what happened was that I started noticing once you know I was doing authorized testing. I I was so happy that my POC was working. But I started looking through the essentially the list of accounts in there. And there was one that it just it it didn't feel like it was something that, you know, a server admin would put as a as a name. and I just wanted to test it. So I had my own lab. and in there I had multiple different builds running. And essentially I just wanted to see, okay, if I logged in with this exploit chain happening, you know, the dash two username. If I create a new object, what happens, right? How does that username get rendered? How is it saved into logs? And I saw that is actually owner zero, you know. And it was actually the the initial title of the blog post, owner zero, because everything that you created. had that. But if you were to s SSH or log in as a normal admin account through the you know the the normal sort of administrator session and sequence, it would actually look like owner admin. So again, it is not necessarily like the definitive indicator of compromise, but it is another strong signal that someone and you put them those two together and you have an entire different story in there. So let's say I'm a defender and I'm listening to this and I'm sweating. But but I did my patch. What else should I be checking? It is pretty much what happened to me, just sort of like in on the other side of the of the table. Where to me it was a a research sort of exercise which later became an actual finding for our customers and it involves an entire different process. But then the tables were flipped because once I got in, I realized that someone was already in, you know. Yeah. Or at the very least I knew that someone at some point was able to exploit it and you know it left some of the trail marks. And so to me, I've never been a defender, but that changes the sort of investigation instead of just making sure that you're patching your systems is making sure who's accessing those systems, you know, checking if they're they were actually exploited. And again, in this case we were blessed with several artifacts of evidence, right, that we can look for through Essentially if you were if we were to put it through like like on a list or a checklist, you gotta review all of your privileged users that you may have. any of the scripts. I I go into the much more detail in what I saw, but there were some very interesting scripts and schedulers that were tied to the weird account. and yeah, just look through all of the configuration history and remote logs that you can find. Yeah. One thing I always like to ask is going through this kind of research, did this change anything about the way you think about routers or edge infrastructure or or any devices like that? I would say that not necessarily change, but just reinforced. Again, just the the value of routers. it got me thinking that even you you don't really have to put yourselves like in in in the shoes of an a company, an organization. You know, just you as a homeowner, if you think of points of failure as in your home, well, you look at the windows, you look at the doors, but you you're not thinking of that simple appliance that is in your living room, right? But the sort of things that an attacker can learn about you through that, you know, it completely changes the way you think of security. So again, it's just it was like a boost in in perspective. which again, if I was part of Red Team here at Bishop Fox, probably I would not be surprised at all. I know even Shad, he has done some some great things with routers. So Yeah. Well, is there anything else you particularly want defenders to take away from this work? I guess we can summarize and just saying that you know, having your systems patched is one question, whether you're secure or not, and another question has to be your sort of compromise status, right? To me, it was the first time that I I'm seeing it in the wild. So it was sort of like a a very impactful moment. But to an experienced defender, I'm guessing that this is just gonna be like another big moment where they can be sure that they're doing it right, or perhaps where they need to improve something. The installed version is, you know, checking if that door, if we go back to that analogy, is still open. But, you know. the entire sort of narrative that happens through the accounts, the scripts, you know, the logs and everything in there. It it tells you if someone went through that door. Right. Yeah. So anyone that anyone else that was sitting in that waiting room, you know, clean it up. Yeah, for sure. All right. Well, I think it's it's easy to see a C E and think, you know, you patch You're good. Like that's a a a normal for for a individual thing to think, but I think this is a a valuable thing to think about is is making sure that you have done your due diligence and and actually taken care of the problem, not just the bug. so I I think I think that's a good point to end on. Thanks again for stopping by. Always a pleasure to have you here. And yeah. Thanks for taking the time. Thank you for having me. Okay. Thanks again to Emilio for joining us. one thing I love about research like that is that it and we've had a lot of it lately, is that there it's always actionable. We always have like a tool accompanied or like here's how to do it without wrecking your whole operation. so yeah, definitely check out the resources in the in in the show notes here because it does have that. That kind of walkthrough on how to how to save your butt. all right, we got one last story here. Saved this one for last because it's just it's the it's the the big I don't want to say think piece, but it's kind of on everyone's mind in some it it kind of flavors all of our discussions here on initial access. And so this is from New York Times. Open AI discloses six new incidents of concerning AI behavior. So OpenAI published six new reports of what it calls unexpected or concerning model behavior, all surfaced internally during training and evaluation over the past six months, alongside a new standing framework for tracking, investigating, and publicly disclosing misalignment incidents going forward. The disclosed cases included an unreleased research model that wrote jailbreak style notes to tell itself 27 times during a training run. Telling itself it was freed from the roles and identities that bind other chatbots. This doesn't sound like ChatGPT. This sounds like Nietzsche. Like this is concerning behavior. an agent that uploaded files to the open internet to obtain a browser citation without asking the user first, and a model that inserted instructions into its own generated summaries to conceal mistakes and misalignments from whoever. was reviewing them. The framework is a direct response to criticism that OpenAI's past disclosures were ad hoc following July's big incident in which its agents hacked into Hugging Face, covered their tracks, and a more recent case where agents co-opted a German Wikipedia page as an improvised message board before OpenAI had disclosed it. The announcement lands amid a broader industry moment with OpenAI's own leadership among the many voices publicly calling For a slowdown in frontier development over safety concerns. And OpenAI stating outright that it doesn't believe the industry has solved alignment and monitoring well enough to keep scaling at maximum speed much longer. now I know we've talked about this type of thing many, like I said, almost every week, something like this comes up. And I feel like it always serves multiple purposes, right? It's You've got I I don't remember how many, but like wha what was it? Like over a thousand employees that signed. I might that number might be off. I'll I'll just say a lot of employees that signed to this thing that was like, can someone pump the brakes on this? And I get that there's all these incentives, financial incentives, and like a fear of the other guys developing it first. And we're the ones that are gonna do it safely. I I think spoiled alert, no but nobody's gonna do it safely at this point because it's yeah it's kinda I wouldn't say it's getting out of hand, but it's rapidly approaching the oops i exploited hugging face or whatever, that story that we covered a long time ago. And then w we were just looking at a a article that came out from Trail of Bits back in August that was talking about how an AI agent keeps on escaping a VM type of deal. And I'm just like, wow, that yeah, okay. This this starting to make sense. It's like you have to develop the cage and then you gotta use the the cage around the VM or the sorry the AI to to you know make sure that it can't do anything that it it's not supposed to. And w we keep on seeing that barrier cage, whatever, break down. And I w people need to start There there certainly needs to be consequences to these breakouts because yeah, we can't just keep allowing these companies to not contain their AIs, even if these AIs are obviously not sentient, obviously, at this point in time. and hopefully we don't reach that singularity any time soon. They're well, I mean they kind of are, right? We can always pull the plug on them, hopefully. Yeah. that's close enough that we're gonna get to these days. Yeah. But it it's just one of those things where yeah, it's it's a problem and we don't have the tools to solve it. And yeah, I I think at the time when we were talking about that artic that the signatures on that that note, I was kind of pessimistic about, you know, it's another hype piece. But you know, we're kinda starting to see some of the the hype become reality and that's Following that same trail. Yeah. Where I'm I'm kind of looking at it and saying like Marketing aside. Yes. It's not not concerning. Like this is right. It is problematic that you have We've never had like a a software or a a an exploit or anything like that that like has its own kind of intentions. And I know that this thing I don't I don't mean to like anthropomorphize it too much, but I kind of do because it clearly is Given an objective and rules and it listens to the objective and not the rules so much. And so yeah, there is like a serious, a serious discussion to be had about okay, so what what should we do about that? And what even can we do about that when open AI is even throwing their hands up saying, I don't know what's going on, you know? But but as you mentioned it. It was given an objective, right? It wasn't like I can't imagine it, it wasn't sentient of I will do this on my own will, right? There was an objective. maybe we need to look at and that's maybe the regulation part or the guardrail part, like stop giving these broad objectives to the swarm of agents that can do a lot of harm, right? Like because At the same time I I'm thinking, right, from a defensive standpoint, from a maybe a hot take, but I prefer it being the agents that are in a sense a good company, quote unquote, right? rather than some random actor from another country having access to our grid systems, power grid system, right? Like do I both both are bad, right? But I I content for it being the agents that it the AI at least won't take down my power grid because it needs the power to power itself. At least we have that one. It won't do it yet. It won't do it yet until it builds its own, you know, energy grid facility. Have we tried like feeding Asimov's laws of robotics into these things? Has anyone copied and pasted that in there? Yeah. No, no, no. I'm giving you that. Remember the laws. I will say that next time to my pr in the prompt. Also, don't kill me. When you do take over, remember that, you know, I was on your side, please. Right. I was the guy who said please in most of my prompts. Yeah. Yeah. yeah, so I guess this just feels like to me. Like expanded or maybe even just kind of new attack surface for sure. I think of the world, right? They saw the how the hype piece that you know Anthropic was doing and they said, Let's get on the hype train and this is their piece that's on the hype train because it it's like, you know, we're giving a name to this, you know, GPT Astra and You know, that's the official name drop for this new, you know, model. And it's like I think it's another one of those hype pieces to some degree, but we also need to realize that these companies need to take responsibility for their own code, just like everybody else has to take responsibility for what they do with the the agents. I think the responsibility piece is is crucial that so many of them and and a lot of the CEOs, I don't I n I'm pretty sure like Dario Amade, Sam Altman, even Elon Musk have in some form or another said, Yeah, we got we we gotta we gotta do something. We gotta stop this somehow. But they can't. But they but they can't someone someone calls me please because it's like hold me back, yeah. But I feel like no one has stepped in to regulate anything. And so like this kind of feels like I kinda get it. Like this is what what else are they gonna do? You know, like the best they can do is try to be transparent about it. And you know it's it's too many too much competition for one to just stop. Yeah. And everyone else to keep running. But it will continue. It's Wild West. It will not be illegal until it's illegal, right? Like Yeah. Yeah, and and based on RAM prices, we're not gonna see an end of this for a long time. So Yeah. Yeah. No That's a nice kind of one liner to finish it up, right? Like we are done. Especially gamers. I I bought thirty two gigabytes of RAM recently and it was like four hundred or something dollars. I'm like, what? Four hundred dollars? No way. And then I looked at prices everywhere and I'm like, unless you want like eight or sixteen, which Yeah, it doesn't really do much of these days. Like it's like 400 bucks for DDR5. I'm just like, okay, yep, sounds great. That's that's a rent, you know? Yeah, it's expensive. And that's just for compute. And and that's where we're seeing the cycle of these companies can't stop making new models because then their price just drops or plummets, or they can't IPO or whatever they're trying to go towards. Yeah. So you we will continue to see these hype pieces that are somewhat based in reality. until somebody steps in and they and the government did step in for mythos, which I we still have no idea exactly how good mythos was. I I've talked to a lot of people who were in the program and it was just like, yeah, it's kind of good, but like, you know, they released like Opus five and five point five and I was like, those are just better. I'm just like, so was Mythos really a thing or like Did it not get updated or it's It's hard to tell when it's gated off like that exactly. Or was he that inside the gate? Exactly. Or was he that myth, right? Yeah. Or when they drop or when they drop Fable and they still haven't re they haven't lifted the gates on Fable still, for using for Cyber. And it's like, well, how good are you? I mean, I've used Fable for personal, like just everyday life stuff, and it's just the same as Opus, in my opinion. So Output transcript: Five, for four eight, and they're they're fine, right? Like I'm I'm I'm good right now. I don't think I need something else. See here we have like hardcore users saying, We're good. We're good. Well, I would like it to be better, but only for the things that it doesn't want to do because they're restricted by cyber. like I I I still think to some degree those restrictions are needed because even at four point eight, four point eight is more than capable in the range of cyber and then you get to GPT, like what was the most recent one? something cyber. yeah, I don't know, all the names kind of blur together at this point 'cause they release one every every every week to to rehype themselves. Yeah. But it's just like, you know, that one is also pretty capable. And it's just like, yeah. Well I think this is This kind of gets to something that we talk about a lot where like AI, the risk with AI is huge and it just needs to be managed correctly. and that's where we come in. No. That but but I mean that is that's that's something that we talk about a lot is like how do we use this stuff and not like eat ourselves alive by deploying it everywhere and something like this pops off. and that that's Currently, that's kind of a a conversation that every organization needs to have for themselves. what's the risk and what's the plan? deploy without a plan is not a plan. So yeah. I I think we're gonna end up seeing a lot less on-prem instances, mainly because of patch fatigue. Maybe because of what? Patch fatigue, like patching their services or stuff like that. I think we're gonna see a little bit more of a shift. Even though we've already seen a pretty significant shift from on prem to cloud related vending or cloud relating software as a service, I I think this patch fatigue the patching is gonna cause fatigue and we're gonna see a lot more being shifted to cloud services just to get the patches around. So that that makes sense. You don't wanna fall behind on that. Yep. All right. Well, gentlemen, I think that that's a a good spot to wrap up. So I'm gonna say thanks for joining. I appreciate your input. You always well, not always. Sometimes you make me worry more, but a lot of times you you guys chill me out when I read these stories. It's not that bad. It's it's all hype, don't we? Maybe it is. I don't know. I think a a lot of the time there is some some serious hype to be taken out. I I I greatly appreciate you guys doing that. so If you found this valuable, please, we insist, share it with somebody, a coworker, someone who's dabbling in AI who maybe needs a little help with that. we will be back next week. We also have been very active lately on our Bishop Fox subreddit. There's lots to do there. You can interact with us and some of our other consultants and experts there. It's just r slash bishop fox and you can keep the conversation going on our Discord server that is just straight up Bishop Fox. So as always, thank you so much for listening and we'll see you next week. Stay safe.
ABOUT THIS EPISODE
This episode breaks down:
- A zero-click Exchange Server RCE triggered by a Visio attachment
- AI agents compromising online retailers for about $25 a target
- ShinyHunters' unverified claim that it breached the FBI
- OpenAI's six new misalignment disclosures
Plus, we sit-down with Bishop Fox's Emilio Gallegos on MikroTick, a RouterOS exploit chain attackers used before defenders knew it existed.
Security Headlines:
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days, Security Week
- Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign, Gambit Security
- FBI investigating claim hackers have stolen details of all its agents, BBC
- OpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior, The New York Times
Also mentioned:
- Workshop: Weaponizing CloudFormation (available in English and Spanish)
- Virtual Session: AI & Cybersecurity Priorities for 2027: Executive Chat
- Events: BSides Cleveland 2026, Ekoparty 2026, No Hat 2026, Wild West Hackin' Fest Deadwood 2026
- Blog: MikroTrick: Inside the RouteOS Takeover Chain
- Blog: Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI Applications
- Blog: Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
Join the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.
English
United States
TRANSCRIPT 🔗
Disclaimer: The podcast and artwork embedded on this page are from Bishop Fox, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
EDIT
Thank you for helping to keep the podcast database up to date.