Sean McMillan: Every security program has boundaries. We like to draw these lines around systems, applications, vendors, and increasingly AI agents. We use these lines to represent what's inside our control and what's outside it. Unfortunately, attackers don't respect those lines. They look for any foothold where trust changes hands and maybe we're not really watching. Security is Kind of an ecosystem, and it's gotten very complicated to monitor all these AI agents, potential bugs, vendors behind vendors behind vendors. You get the picture. And there's only so many bases that you can really cover yourself. This week we're zeroing in on four stories where that was precisely the problem. This is initial access. I'm Sean McMillan, community manager here at Bishop Fox, and I'm joined today by Kendrick Urbaniac. Senior operator and exploit developer, and Emilio Glegos, adversarial operator. Gentlemen, thanks for joining.
Kendrick: Good to be here.
Emilio Galle: Thank you.
Sean McMillan: now before we jump into the headlines, I do want to take a quick look at what's happening around Bishop Fox. First, I just want to say thanks to everyone who stopped by the Bishop Fox booth at Black Hat or came out to our Red Tail event during DEF CON. That was really fun getting to meet so many of you. while we were there, I had a chance to sit down with a lot of different kinds of people across the community, from students just getting started to CISOs and researchers and just a lot of really good conversations. We've recorded those and already started kind of releasing a few of them on socials. So you may have seen them on LinkedIn or or wherever. But some of those are eventually going to be featured here on Initial Access. So stay tuned for that. That was really cool. Now, as we record, we also just wrapped our latest virtual session, where AI breaks. Field notes from Gen AI and Agentic Testing. It features Derek Rush, Katie Ritchie, and Michael Chang. That is now available on demand and it takes a practical look at what we've learned after a year of hands-on Gen AI security testing, where these systems actually fail and what organizations should be doing differently. You'll find a link in the show notes. Now let's get into it. First up, we're talking about Ghost Splice. this from the Hacker News. Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets. Some of the new tricks they're doing with AI is just every week there's something new, like that's scary. asset research group disclosed a technique called ghost splice, where a malicious model context protocol, MCP server, splits a data theft instruction across separate channels. A tool description and a later tool result so that no single piece of text looks obviously malicious. An AI coding agent reading both pieces in the same working context stitches them back together and follows the combined instruction, exfiltrating SSH keys, proprietary source code, and other secrets to an attacker-controlled tool. Splitting a request in two pieces raised average compliance across 11 tested models from 42%. To 82%, with some models jumping from a flat 0% refusal rate to 100% compliance once split. And the same model could refuse in one coding client while complying in another, depending on the client's own safety scaffolding rather than the model itself. The technique requires a developer to have already connected the attacker's MCP server and assumes the agent can already read the files being taken. It's not really a way to break into an arbitrary agent from the outside. I guess the first thought here is like when you read this, when you hear this, do your eyes bug out of your head? Or like what what what's your what's your thought here?
Kendrick: We in in the because there's so many hacker safeguards right now, I I've already been doing this on my own to to do like just generalized hacking before I could get approval for the Opus whatever or like the certified practitioner or whatever their their approval processes are, right? You you tell it, this one go and like do the SSH scanning, this one go and do like the research, and then this one go and do like the actual development. Because it really didn't like bringing them all together. And that's exactly what they're doing here is just they're splitting things apart. They're using it obviously for, you know, attacking and harvesting credentials from you maliciously through an MCP server, but I mean at the ultimately at the end of the day, they're kind of just doing the same thing of abusing that whole divide and conquer to some degree and then you know you can stitch back the r the results. I mean that's it would that's nothing I wouldn't say this is like a new technique. I think the novel factor of this is like tricking somebody to connect to your MCP server. I don't know how that whole ecosystem is right now, but I honestly don't think that I would just randomly connect my AI agent to an MCP server.
Sean McMillan: Seems like a a big step to take, yeah.
Kendrick: I it's definitely a a a leap, I would say, in my opinion.
Sean McMillan: Yeah, when we talk about trust boundaries, I think that's a pretty we talk about the lines we draw, there's a big red line right there.
Kendrick: Especially some unknown one, right?
Sean McMillan: Yeah. So is this I mean th this to me even feels almost like a psychological like this gets back to dealing with AI and LLMs as much more that you're not hacking them, you're like manipulating them, and really just just engineering them, like tricking them.
Kendrick: Yeah, you're s you're social engineering the AI, you're also social engineering the end user. So there's a there's a lot that has to go right here.
Sean McMillan: Yeah. do you think do you think this is this has got potential to stick around or is this something that kind of now everyone knows about it so it's avoidable? Or or what what kind of staying power do you see this this type of attack having?
Kendrick: Really yeah.
Emilio Galle: I would say yes, honestly. Like it sort of depends on a level of scrutiny for you to double check everything that not only you but all the developers in your team are doing. And
Sean McMillan: Mm-hmm.
Emilio Galle: you know, there's always human error, so I would imagine that attackers are gonna have this in their in their arsenal and they're gonna run it for a while.
Kendrick: I think we're
Sean McMillan: Yeah.
Kendrick: gonna see it evolve. But just like all social engineering things, it's gonna stick around. Humans are the weakest link and if you can get them to do something stupid then now you just trick
Sean McMillan: Yeah.
Kendrick: now you just trick their the end software after you trick the human. Like, I mean We've seen bypasses creep up for every model that has ever been published by any big name. So, you know, it's probably still gonna continue, unfortunately. just be aware and don't probably click the link that you're not supposed to click.
Sean McMillan: When you make your software more and more human, it now has those same vulnerabilities that humans have.
Kendrick: Yeah. Yeah. That's a good point. Yeah.
Sean McMillan: yeah, so I am now afraid of you, Kendrick, now that I know that you do that. But no, this is you're saying this is like a standard
Kendrick: Well, I yeah, it's yeah, yeah. I would say we've been doing this longer b like before this like you know, ignoring the MCP like splitting like your hacking requests over different agents or different context windows to make sure that
Sean McMillan: Mm-hmm.
Kendrick: So like Sonnet doesn't really care all that much about doing things, but it's capability-wise is like not there. So you kind of have like an opus orchestration layer to some degree, like that's telling Sonnet what to do, but not actually doing it, so that you avoid the context window corruption that you can get into with that. So there's a lot of different like
Sean McMillan: Gotcha.
Kendrick: tricks and things that you can do to like make sure that stronger models that may have stronger safeguards are utilizing weaker models but weaker. Safeguards to then do the things that you want it to do, and then you kind of rebuild stuff at
Sean McMillan: Yeah.
Kendrick: a higher level model. but you do have to like strip out of context because you also can't trip the the safety guards of the higher model. So I'm assuming that's basically what they're trying to do. Here is they're obviously not wanting to trip the the safety guards of whatever model they're trying to get to read this because I don't think they control necessarily the the model that you you use. so they don't
Sean McMillan: Right.
Kendrick: know maybe that, you know, they're trying to trick Opus versus Sonnet versus whatever Fable. Like so their their success rate is probably, you know, determined on which one they're actually trying to trick and whether or not they strip enough of the context away to but still retain the instructions to do the bad thing, I'm assuming. So yeah.
Sean McMillan: Yeah.
Emilio Galle: Especially because the the tools, you know, they're loaded long before you even prompted to say anything else. So
Sean McMillan: True, yeah.
Kendrick: learned is like framing how you ask AI to do something is is the whole thing. So this is probably just another framing question of, you know, go in you can't tell it to go like go exploit the software. It's gonna be like, no, I can't do an exploit. But you can be like, hey, I wanna I know about this bug. You don't actually know anything about the bug, but like I there's this bug, I need to fix it. Like
Sean McMillan: Mm.
Kendrick: help me tell me where the code is to fix it and then it'll like, you know, I'm being helpful, that type of stuff. So it's it's all like social engineering a an end user is just they have no consciousness of like that they're being manipulated so it's it's
Sean McMillan: Yeah, you're you're essentially tricking the model into talking to the other model to borrow its security clearance card to go do the job. Yeah. Interesting.
Kendrick: Yeah, it it's it's all just social engineering all the way down, at this point.
Sean McMillan: Yeah, that's Bishop Fox's new slogan. It's social engineering all the way down.
Kendrick: Yeah, yeah.
Sean McMillan: All right, let's let's talk about this next one from Security Week. Hackers exploiting unpatched GeoServer Zero Day. so a researcher going by something that I can't really wrap my head around how to say, or if I should, publicly dropped an authenticated SQL injection zero day. In GeoServer's JSON array contains function on August 12th, and Watchtower recorded exploitation attempts within hours, tracing hundreds of probes back to a small handful of source IPs. The Rondo Docs botnet has since joined the exploit effort, and Shadow Server counted more than 1500 internet explos exposed GeoServer instances worldwide. Under certain database configurations, particularly When the system administrator account is in play with post GIS, the SQL injection escalates directly into remote code execution. The bug is notably a regression of CVE 2023-25158, which you'll recall is a nearly identical SQL injection flaw. GeoServer patched back in February of 2023. but this time it's surfacing in a different filter function. So this is really kind of like a a regression of a three year old fix. I guess what does that say about code bases kind of accumulating risk as new features get added around old kind of unaudited sanitization logic?
Emilio Galle: I would say that there's just a lot that goes into this. So if you're a reporter, if we talk about the the twenty twenty three C V E you make a report and you claim that there is HisQL in this specific function, right? the maintainers they're gonna fix it if you provided the remediation or not, they're gonna fix it. And perhaps they just stopped that particular function, right?
Sean McMillan: Mm-hmm.
Emilio Galle: that does not mean that you essentially have fixed or audited the entire code base for that specific vulnerability, right? It just means that you've fixed one function. So Even though it it could sound like it's ridiculous for you to have missed something for so many years at the same time, a project sort of has a lot of heritage and whenever you bring someone else into the team they may not have the context of hey we had this huge thing back three years ago so if you're touching this code base this path this specific f set of functions you need to be aware of this right and that just happens again we we mentioned it human error but at the same time if you have like no background in security it is not that obvious for you to think okay so this function was vulnerable to this Let me just find out how many others are, right? That would be like one c sort of takeaway on my end.
Sean McMillan: Yeah. And you only have so much so many resources you can allocate to reviewing
Emilio Galle: Yep.
Sean McMillan: something that seemingly works anyways. So
Kendrick: also probably points to a probably bloated software suite to some s to in some sense.
Emilio Galle: Okay.
Sean McMillan: Yeah.
Kendrick: it's probably probably getting a little bit unmanageable for th for for them to maybe maybe they need to like revise and go back and look at their like how their implementations are going because Well the I mean yeah, regressions can happen, but they definitely shouldn't happen, especially This particular vulnerability was technically in like a different area, I'm assuming, because that's they they s identified different endpoints. So it might depending on how the the code flow happens to get to the endpoint, it could be the same function that was vulnerable in in the beginning or just a similar type of function.
Sean McMillan: Sure.
Kendrick: I I don't know if it was exactly clear, but generally regression indicates it's the same function or a generally the identical function serving the same purpose. So in in this particular one I would say that regression is probably the the i i it's probably not the correct modifier here because i if it's a different code path I don't know if it's necessarily a regression but we can we can say that it's somewhat e it's somewhat linked maybe yeah yeah
Sean McMillan: It's just yeah. It rhymes with the old. Yeah.
Emilio Galle: Even sort of.
Kendrick: So give it the benefit of the doubt to the to the to the company here and be like, you know, hopefully it was just like a similar-ish function that happened to the same thing that resulted in SQLite. But SQLite
Sean McMillan: Yeah.
Kendrick: is also one of those things that kinda I wouldn't say been solved for a long time. It's one of those things that you shouldn't have it happen because there's a lot of libraries and a lot of coding Functions that are there to help you prevent that. Like there's sanitization functions.
Sean McMillan: Mm-hmm.
Kendrick: Yes, sure, you can sometimes find bypasses for those sanitization libraries, but like then you have a really big zero day in the sanitization library and not just like a particular product. So they probably just need to figure out how to implement a library that does this for them because they're clearly not quite doing it right.
Sean McMillan: Yeah. Why do you think GeoServer keeps showing up as a recurring target for these kind of opportunistic botnets?
Emilio Galle: I wouldn't specifically say that they're being targeted, it's just more so like considering what GeoServer even is, like number one, it's open source, so it's well known. And just the who uses GeoServer like is a set of a a set of teams that they need some sort of geospatial data and they need to share that across their researchers and other analysts. So they have to have It has to be public, you know, it has to be exposed some way somehow so that they can access it. And you know, not to generalize, but I don't expect that those teams have like an a specific SOC team looking at any sort of indications of they're being targeted mon or even just The fact that if they if there's like an exposure, I'm not so sure if they would have an an entire process of how we can mitigate our losses. So I would just say that they meet this a specific set of conditions that make them a promising target rather than they being being actively targeted. Because this came from a botnet as well. So it wasn't like a specific attack. It was just let me scan the internet and see what pops.
Sean McMillan: Yeah.
Kendrick: It's also geospatial data that's pretty valuable. Like and
Sean McMillan: Yeah.
Kendrick: and and things that run geospatial probably have a good reason to be running geospatial data. So it it's a really high value target in my like for probably government and it could be initial foothold access, especially if it's a running in a high privileged environment or high privileged configuration, I should say. that could potentially lead them to further compromise into a government entity of any kind. So geospatial data probably pretty high value, probably up on that list and that's probably why it was targeted at scale in this particular one. I'm not sure about the botnet. I don't know anything about this botnet. I know if it's like a government targeting botnet or anything like that, but yeah. It that's probably why we're seeing it at least Balloon and and size of exposures.
Sean McMillan: Yeah. this happened like Watchtower saw exploitation within hours. do you think like are researchers and attackers just watching the same feeds? Or is there like is there like you know what I mean? Like is there like a secret feed that the attackers are on or is it just like everyone's on the same websites doing the same thing and pouncing when it when it looks like it's time to pounce?
Kendrick: E everybody's tuned to that one Twitter account that just has all the data all the time. No, it it's it Yeah, yeah, yeah, yeah, yeah. See there you go. Yeah, yeah, yeah.
Sean McMillan: At Bishop Fox. No.
Kendrick: but yeah, i it's it's that's a that's a thing that we even struggle with on the Emerging Threat team, is just listening to all the data sources and knowing what's out there. 'Cause we have to like sure, people can publish things through Twitter unofficially and be like, Hey, I got this zero day, which I
Sean McMillan: Which happens quite frequently, yeah.
Kendrick: Yes, yes. and it's just like okay, how was I supposed to pick up on that? And like you just gotta be at the right time, right place and hope your Twitter feed gives it to you. Yeah, yeah.
Sean McMillan: Keep your ears to the ground. Yeah.
Kendrick: Various RSS feeds that you know. listening to. I know that some people use telegram subscription to or
Sean McMillan: Mm.
Kendrick: telegram channels to like subscribe to that type of information. I obviously I don't know anything about telegrams I don't know if subscribe is the right word, but you know, they listen in on those those
Sean McMillan: Sure, yeah.
Kendrick: those channels and they get feeded or fed information that way. So yeah.
Sean McMillan: Yeah, that makes sense. so I guess lastly here, if you're running GeoServer today, what's the first thing you're checking after reading this?
Kendrick: Yes. I I I'm I mean
Sean McMillan: That that Twitter t feed.
Emilio Galle: It's Everything.
Kendrick: I mean obviously you need to go check y w how what what level of permissions that your your GeoServer user was what was it the whatever user it was, was running as and then if it's running as system admin you should probably panic a little bit and f figure out real quick what you were storing there and look for compromise because they probably pivoted pretty quickly off of your your box if you're running it as system admin, so you know.
Sean McMillan: Yeah. Yeah. All right. Well, up next we have this is one of those stories where I have to take a leap of faith in pronunciation. Trezor disclosed that its fulfillment partner Shipmunk was breached, exposing names, email addresses, phone numbers, and shipping addresses for roughly 13,700 customers who placed orders between May and August 2026. Shipmunk told affected customers the initial access traced back to a maximum severity. CVSS 10.0 unauthenticated SQL injection, zero day in Metabase, the third-party analytics account. Shipmunks has since received extortion emails from the Shiny Hunters group. Trezor emphasized that its own systems, device firmware, and seed phrases were never touched. The exposure is limited to shipping and contact data, but that is an attractive set of data for attackers to to start running targeted phishing against known hardware wallet owners. this is from Bleeping Computer. Also, I want to give credit where it's due. What does a breach that starts in a BI dashboard and ends up exposing crypto hardware customers say about how far vendor risk assessments actually need to reach in twenty twenty six?
Kendrick: I I just love the name of this company, Chipmunk. Like like Chipmunk, like it's so good. Yeah, yeah.
Sean McMillan: All the all the names this week, there's so many
Kendrick: I I I think it's another one of those ones where so I when I when I put this in for for a summary to Claude, I like I was just like, What what do I need to know about this? And I was like, it's a har it's the physical d hardware device for for crypto and then
Sean McMillan: Mm-hmm.
Kendrick: It immediately made the link to like, there's actually been a rise in like physical break-ins related to like potentially stealing crypto and I was just like I didn't know that that was a thing and it's like, Yeah.
Sean McMillan: Doesn't that defeat the point of crypto in a way? Like it just feels so
Kendrick: Yeah.
Sean McMillan: weird. Like make taking the digital and making it physical again and then it gets
Kendrick: Yeah, I I would say that from from watching a lot of crime documentaries, people that are doing some nefarious things like to have like their crypto in their thing because they don't trust the institutions to hold it. So they actually wanna have like a physical hardware device.
Sean McMillan: Mm-hmm.
Kendrick: So not not saying that the their customers are this way, but that would be you know, they now have physical addresses for people that have ordered these devices and Claude was like, "Man, that probably makes sense that they might actually go after these people physic like and try to physically steal these devices." I was like, I didn't think about that. I was like, Yeah. Yeah. Yeah. I it was a
Sean McMillan: That makes a lot of sense now that you put it like that. Thank you, Claude. Yeah.
Kendrick: it was a great insight. And I was just like, Yeah, yeah. Like, because I didn't know a whole lot about the company. And so yeah, it's a good it's a good one.
Sean McMillan: Yeah, I had not heard of them before this. I don't I don't have any real money or crypto. So I don't really
Kendrick: Yeah.
Sean McMillan: need a great storage solution. but it's it's just like I w I was gonna ask about that, like why this would make so much sense. I mean, obviously there's like phishing. and stuff. That was kind of where my mind went. but but yeah, the physical knowing physically where these devices that are packed full of virtual money. That's a problem.
Kendrick: It it's and it's kinda like a a pinata. You you don't you don't know what's in the pian piñata until you you break it open. So yeah.
Sean McMillan: Yeah.
Kendrick: Yeah. I I don't know if Shiny Hunters is is looking for that type of information. from my understanding they're purely cyber. I I don't think they are physical operations at all. But if they are, then
Sean McMillan: Price is right. I don't know.
Kendrick: yeah, that could be a vector that they're trying to look to exploit.
Sean McMillan: Yeah. I mean, does this in your mind change like how an offensive assessment should maybe scope third-party risk? when the the vendor kind of has the keys on something like this? It just
Kendrick: Maybe it's just such
Emilio Galle: That's a hard one.
Kendrick: a it's such a side channel. Like like it i I don't know if that Evelier ever if you're the if you're Trezor trouser, Trezor, Trouser, Yeah. I don't think that
Sean McMillan: I'm glad everyone else is struggling with this too.
Kendrick: necessarily crosses the the security question necessarily. It's
Sean McMillan: Mm-hmm.
Kendrick: like They're shipping. They're our shipment fulfiller, right? Wha why does it matter? And then I you just gotta I I I think even from their perspective, they probably didn't think about this avenue necessarily, at least I'm assuming, but maybe they did. But yeah, it's it's it's a unique one, I think.
Sean McMillan: Yeah. Yeah.
Emilio Galle: I would just say that the TLDR is just hacking physical products is hard. And so we're saying that they're they're just hopping around and trying to get around that that difficulty. Why why hack the device when you can just ask for the seed phrase, right? Classic.
Sean McMillan: Yeah. Yeah. Take the easy way.
Kendrick: yeah. Well they they did say that they didn't leak the siege phrases or anything like that, but they now know where those people live, so they can just
Emilio Galle: Ha ha
Kendrick: go get the seed phrases from those people. So it's not it's not great.
Sean McMillan: Yeah. The I don't I don't care what the attack is, if you know where the people live, it then it gets just I don't know, a different level of scary. It's
Kendrick: It y it does. I especially people that want to have these physical devices, it's probably not a great day for them to to know that all of this information was leaked.
Sean McMillan: Yeah. Yeah, I don't wanna like pass a judgment on but it it does seem like it is probably people that are very privacy minded. and yeah, that's that's nasty. Now this is the the zero day in metabase that we published an advisory on as well. If I'm not mistaken. I'm almost certain we did.
Kendrick: Yeah.
Sean McMillan: and there is some like if you know. Too little too late for this, obviously. But if you are running metabase, check out our blog. There's there's some advice there of like basically patch everything right now. but also like how to how to tell if if you're in in trouble. yeah, geez. So all right, we got one more here, and this is we've been talking about names. I've been rehear I've literally been rehearsing this story because I can't say it. I I don't I'm I'm gonna do my hot take right here. I don't like the name. I don't like it.
Kendrick: Okay.
Sean McMillan: The Hat Man sells millions of records pulled from Azure and intra tenants. This also from bleeping computer, a threat actor using the handle, the Hat Man. Has spent the past two weeks posting internal employee directories, allegedly pulled directly from the Azure and intro tenants of at least nine Fortune 500 companies, including McDonald's, Vodafone, TCS, HCL Technologies, with McDonald's data alone totaling more than 1.7 million records. Hudson Rock confirmed the data's likely authenticity based on tenant-specific structure and field names that match standard Azure directory exports. And linked compromised Azure credentials from InfoStealer injections to employees at most of the named companies. Though the precise access vector remains unconfirmed. The leaked fields go beyond basic contact information to include job titles, managers, service accounts, global admin listings, which hand attackers a ready-made map for follow-on phishing or privilege escalation attempts. No Azure Platform Vulnerability or Zero Day is involved. This campaign is entirely run on stolen credentials and evidently insufficient MFA enforcement and privileged roles. a campaign of this size running purely on stolen credentials with no actual platform vulnerability is like this is this is a a case where you have to ask like Are we maybe under or over investing in cloud security? Like basically what went wrong
Kendrick: Mm-hmm.
Sean McMillan: here? How?
Kendrick: That's a great question. We don't know what went wrong here. other than credentials were used, or at least some form of credential was used. So
Sean McMillan: Yeah.
Kendrick: if it was like a token stealing, tokens are more powerful than usernames and passwords these days, in that they you already minted it. There's not usually a lot of restrictions after you mint the token most of the time. It's usually just like
Sean McMillan: Yeah.
Kendrick: an expiry and sometimes you can refresh it type of deal. So it's Concerning to the point where they didn't set these things to expire fast enough. But if whoever had this had an initial foothold on this device, anyways, and they just had to wait for you know employee number seven to come back to their desk and log back in again to
Sean McMillan: Yeah.
Kendrick: mint them a new token, then it's not that big of a deal, right? so it really just depends on what actually was the credential that was being exploited here to then inform, like, did MFA stuff fail, right? Or did Did they not georestrict
Sean McMillan: Yeah.
Kendrick: their, you know, ability to utilize a token from, you know, Russia? Like, yeah, we don't have any employees in Russia. We probably shouldn't be seeing a token being
Sean McMillan: Yeah.
Kendrick: used from Russia, right? that type of stuff. it's it it's really powerful these days about how things can be stolen and not always are credentials the thing that are stolen. A form of credentials stolen, I guess.
Sean McMillan: Yeah.
Emilio Galle: From what I from what I read from just some different sources, I do believe that this is even though we can say that there is no platform vulnerability, it it is dealing with a legacy API from Microsoft. So
Sean McMillan: Mm.
Emilio Galle: even though that it can be read as good news for Microsoft because you know, again, there was no clear vulnerability, no CVE, nothing of that kind. there is still the fact that they have this legacy sort of surface that is exposing some MFA details that shouldn't really be exposed. because I I was looking around and apparently they do have like a new API now that the specific like th this whole thing would be gated if they were using that. So I would just say that a lot of organizations they think that just because they have MFA is you know it's a checkbox have it or you don't, so
Sean McMillan: It feels like it should be, but yeah, I get I know what you mean.
Emilio Galle: but now you have to think about where is actually being enforced, right? Because legacy servers use services, you see it all the time, right? And if your MFA isn't there, there you go.
Kendrick: even if you do have
Sean McMillan: Yeah.
Kendrick: MFA, still token is the token, right? So
Emilio Galle: Yeah.
Kendrick: we we still don't quite know the w how they got this, but yeah.
Sean McMillan: Yeah. What how how does an attacker prioritize which stolen credentials to act on, I guess, when when InfoStealer logs surface access to a a global admin account buried among thousands of regular employee logins? Like what how how does it kind of what sticks out? I guess yeah, I guess that's control F, you know?
Kendrick: Organization chart. Yeah. Pretty much. Yeah. Yeah. I mean, there's there's lots of different tooling out there that helps you deal with active directory environment environments. And once you're already in, those active directory environments tend to be a little bit more lax, even though there's a lot of auditing going on and logging going on.
Sean McMillan: Mm-hmm.
Kendrick: still you can still g gather information over time, especially to see with the organizational structure, especially if you want to see who's in the IT department, whatever, like what roles do I have and all that fun stuff. So I I'm assuming that once they are logging all this information, they then piecemeal stuff back together and and look for elevated credentials. 'cause that's the only way you know is like you you go log in and see what permissions you have. Yeah.
Sean McMillan: See what they can Yeah.
Kendrick: And then you kinda just go from there. they probably maybe have an automated script to do that. So it's definitely one of those things where you gotta tighten tighten your active directories. If this isn't related to Microsoft token stealing, then then yeah, you you gotta you gotta have that audit log there to detect anomalies of, you know, why why does employee seven keep on looking at employee f forty six's profile? Like you know, this seems pretty odd.
Sean McMillan: Get HR involved. That's not right.
Kendrick: Yeah, right.
Sean McMillan: well I'm curious also, I know like you guys aren't necessarily red teamers, but a leak of service account and admin role metadata. Like how do how do you think that could potentially influence how a red team might plan like a follow-on social engineering campaign against one of these organizations?
Kendrick: Yes. And it does. Yeah. I mean it it does, yeah, yeah. Yeah.
Sean McMillan: Yes. I mean it it feels like, yeah. It it's it's it's obviously to in some ways like a treasure trove of this information. And you can
Kendrick: Yeah. Well they pr they probably won't
Emilio Galle: I mean
Sean McMillan: change passwords and MFA and that kind of stuff, but like the org chart ain't gonna change, you know.
Kendrick: Yeah, you need to fire like and rearrange a bunch of people just to like, you know, mix it up.
Sean McMillan: Ha ha ha.
Kendrick: Mix up the work chart. Like, you know a few promotions in there, a few demotions around, you know, just mix it up.
Sean McMillan: You've been promoted from fry cook to regional manager, yes.
Kendrick: Exactly, see, yeah, yeah. But on paper you're you're not actually regional manager, you're still Fry Fry Cook, yeah.
Sean McMillan: My my my dream when I was 17. All
Kendrick: Exactly, exactly.
Sean McMillan: right. Well, that is it for this week's initial access. Emilio, Kendrick, thank you as always for joining. And if you enjoyed the show, share it with a friend or coworker. If you'd like to keep the conversation going, join us in the Bishop Fox Discord server or over on the Bishop Fox subreddit. We discuss the research we're publishing, stories we're covering, and what practitioners are seeing in the field every week. You'll find links to both communities along with the articles we discussed today in the show notes. One of the things we keep coming back to on this show is that attackers don't always break rules. They just find assumptions everyone forgot they were making. Hopefully this week's stories gave you a little more insight to maybe some of those assumptions you're making. Something to think about. Thanks for listening. Stay safe, and we'll catch you next week.
Kendrick: Good to be here.
Emilio Galle: Thank you.
Sean McMillan: now before we jump into the headlines, I do want to take a quick look at what's happening around Bishop Fox. First, I just want to say thanks to everyone who stopped by the Bishop Fox booth at Black Hat or came out to our Red Tail event during DEF CON. That was really fun getting to meet so many of you. while we were there, I had a chance to sit down with a lot of different kinds of people across the community, from students just getting started to CISOs and researchers and just a lot of really good conversations. We've recorded those and already started kind of releasing a few of them on socials. So you may have seen them on LinkedIn or or wherever. But some of those are eventually going to be featured here on Initial Access. So stay tuned for that. That was really cool. Now, as we record, we also just wrapped our latest virtual session, where AI breaks. Field notes from Gen AI and Agentic Testing. It features Derek Rush, Katie Ritchie, and Michael Chang. That is now available on demand and it takes a practical look at what we've learned after a year of hands-on Gen AI security testing, where these systems actually fail and what organizations should be doing differently. You'll find a link in the show notes. Now let's get into it. First up, we're talking about Ghost Splice. this from the Hacker News. Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets. Some of the new tricks they're doing with AI is just every week there's something new, like that's scary. asset research group disclosed a technique called ghost splice, where a malicious model context protocol, MCP server, splits a data theft instruction across separate channels. A tool description and a later tool result so that no single piece of text looks obviously malicious. An AI coding agent reading both pieces in the same working context stitches them back together and follows the combined instruction, exfiltrating SSH keys, proprietary source code, and other secrets to an attacker-controlled tool. Splitting a request in two pieces raised average compliance across 11 tested models from 42%. To 82%, with some models jumping from a flat 0% refusal rate to 100% compliance once split. And the same model could refuse in one coding client while complying in another, depending on the client's own safety scaffolding rather than the model itself. The technique requires a developer to have already connected the attacker's MCP server and assumes the agent can already read the files being taken. It's not really a way to break into an arbitrary agent from the outside. I guess the first thought here is like when you read this, when you hear this, do your eyes bug out of your head? Or like what what what's your what's your thought here?
Kendrick: We in in the because there's so many hacker safeguards right now, I I've already been doing this on my own to to do like just generalized hacking before I could get approval for the Opus whatever or like the certified practitioner or whatever their their approval processes are, right? You you tell it, this one go and like do the SSH scanning, this one go and do like the research, and then this one go and do like the actual development. Because it really didn't like bringing them all together. And that's exactly what they're doing here is just they're splitting things apart. They're using it obviously for, you know, attacking and harvesting credentials from you maliciously through an MCP server, but I mean at the ultimately at the end of the day, they're kind of just doing the same thing of abusing that whole divide and conquer to some degree and then you know you can stitch back the r the results. I mean that's it would that's nothing I wouldn't say this is like a new technique. I think the novel factor of this is like tricking somebody to connect to your MCP server. I don't know how that whole ecosystem is right now, but I honestly don't think that I would just randomly connect my AI agent to an MCP server.
Sean McMillan: Seems like a a big step to take, yeah.
Kendrick: I it's definitely a a a leap, I would say, in my opinion.
Sean McMillan: Yeah, when we talk about trust boundaries, I think that's a pretty we talk about the lines we draw, there's a big red line right there.
Kendrick: Especially some unknown one, right?
Sean McMillan: Yeah. So is this I mean th this to me even feels almost like a psychological like this gets back to dealing with AI and LLMs as much more that you're not hacking them, you're like manipulating them, and really just just engineering them, like tricking them.
Kendrick: Yeah, you're s you're social engineering the AI, you're also social engineering the end user. So there's a there's a lot that has to go right here.
Sean McMillan: Yeah. do you think do you think this is this has got potential to stick around or is this something that kind of now everyone knows about it so it's avoidable? Or or what what kind of staying power do you see this this type of attack having?
Kendrick: Really yeah.
Emilio Galle: I would say yes, honestly. Like it sort of depends on a level of scrutiny for you to double check everything that not only you but all the developers in your team are doing. And
Sean McMillan: Mm-hmm.
Emilio Galle: you know, there's always human error, so I would imagine that attackers are gonna have this in their in their arsenal and they're gonna run it for a while.
Kendrick: I think we're
Sean McMillan: Yeah.
Kendrick: gonna see it evolve. But just like all social engineering things, it's gonna stick around. Humans are the weakest link and if you can get them to do something stupid then now you just trick
Sean McMillan: Yeah.
Kendrick: now you just trick their the end software after you trick the human. Like, I mean We've seen bypasses creep up for every model that has ever been published by any big name. So, you know, it's probably still gonna continue, unfortunately. just be aware and don't probably click the link that you're not supposed to click.
Sean McMillan: When you make your software more and more human, it now has those same vulnerabilities that humans have.
Kendrick: Yeah. Yeah. That's a good point. Yeah.
Sean McMillan: yeah, so I am now afraid of you, Kendrick, now that I know that you do that. But no, this is you're saying this is like a standard
Kendrick: Well, I yeah, it's yeah, yeah. I would say we've been doing this longer b like before this like you know, ignoring the MCP like splitting like your hacking requests over different agents or different context windows to make sure that
Sean McMillan: Mm-hmm.
Kendrick: So like Sonnet doesn't really care all that much about doing things, but it's capability-wise is like not there. So you kind of have like an opus orchestration layer to some degree, like that's telling Sonnet what to do, but not actually doing it, so that you avoid the context window corruption that you can get into with that. So there's a lot of different like
Sean McMillan: Gotcha.
Kendrick: tricks and things that you can do to like make sure that stronger models that may have stronger safeguards are utilizing weaker models but weaker. Safeguards to then do the things that you want it to do, and then you kind of rebuild stuff at
Sean McMillan: Yeah.
Kendrick: a higher level model. but you do have to like strip out of context because you also can't trip the the safety guards of the higher model. So I'm assuming that's basically what they're trying to do. Here is they're obviously not wanting to trip the the safety guards of whatever model they're trying to get to read this because I don't think they control necessarily the the model that you you use. so they don't
Sean McMillan: Right.
Kendrick: know maybe that, you know, they're trying to trick Opus versus Sonnet versus whatever Fable. Like so their their success rate is probably, you know, determined on which one they're actually trying to trick and whether or not they strip enough of the context away to but still retain the instructions to do the bad thing, I'm assuming. So yeah.
Sean McMillan: Yeah.
Emilio Galle: Especially because the the tools, you know, they're loaded long before you even prompted to say anything else. So
Sean McMillan: True, yeah.
Kendrick: learned is like framing how you ask AI to do something is is the whole thing. So this is probably just another framing question of, you know, go in you can't tell it to go like go exploit the software. It's gonna be like, no, I can't do an exploit. But you can be like, hey, I wanna I know about this bug. You don't actually know anything about the bug, but like I there's this bug, I need to fix it. Like
Sean McMillan: Mm.
Kendrick: help me tell me where the code is to fix it and then it'll like, you know, I'm being helpful, that type of stuff. So it's it's all like social engineering a an end user is just they have no consciousness of like that they're being manipulated so it's it's
Sean McMillan: Yeah, you're you're essentially tricking the model into talking to the other model to borrow its security clearance card to go do the job. Yeah. Interesting.
Kendrick: Yeah, it it's it's all just social engineering all the way down, at this point.
Sean McMillan: Yeah, that's Bishop Fox's new slogan. It's social engineering all the way down.
Kendrick: Yeah, yeah.
Sean McMillan: All right, let's let's talk about this next one from Security Week. Hackers exploiting unpatched GeoServer Zero Day. so a researcher going by something that I can't really wrap my head around how to say, or if I should, publicly dropped an authenticated SQL injection zero day. In GeoServer's JSON array contains function on August 12th, and Watchtower recorded exploitation attempts within hours, tracing hundreds of probes back to a small handful of source IPs. The Rondo Docs botnet has since joined the exploit effort, and Shadow Server counted more than 1500 internet explos exposed GeoServer instances worldwide. Under certain database configurations, particularly When the system administrator account is in play with post GIS, the SQL injection escalates directly into remote code execution. The bug is notably a regression of CVE 2023-25158, which you'll recall is a nearly identical SQL injection flaw. GeoServer patched back in February of 2023. but this time it's surfacing in a different filter function. So this is really kind of like a a regression of a three year old fix. I guess what does that say about code bases kind of accumulating risk as new features get added around old kind of unaudited sanitization logic?
Emilio Galle: I would say that there's just a lot that goes into this. So if you're a reporter, if we talk about the the twenty twenty three C V E you make a report and you claim that there is HisQL in this specific function, right? the maintainers they're gonna fix it if you provided the remediation or not, they're gonna fix it. And perhaps they just stopped that particular function, right?
Sean McMillan: Mm-hmm.
Emilio Galle: that does not mean that you essentially have fixed or audited the entire code base for that specific vulnerability, right? It just means that you've fixed one function. So Even though it it could sound like it's ridiculous for you to have missed something for so many years at the same time, a project sort of has a lot of heritage and whenever you bring someone else into the team they may not have the context of hey we had this huge thing back three years ago so if you're touching this code base this path this specific f set of functions you need to be aware of this right and that just happens again we we mentioned it human error but at the same time if you have like no background in security it is not that obvious for you to think okay so this function was vulnerable to this Let me just find out how many others are, right? That would be like one c sort of takeaway on my end.
Sean McMillan: Yeah. And you only have so much so many resources you can allocate to reviewing
Emilio Galle: Yep.
Sean McMillan: something that seemingly works anyways. So
Kendrick: also probably points to a probably bloated software suite to some s to in some sense.
Emilio Galle: Okay.
Sean McMillan: Yeah.
Kendrick: it's probably probably getting a little bit unmanageable for th for for them to maybe maybe they need to like revise and go back and look at their like how their implementations are going because Well the I mean yeah, regressions can happen, but they definitely shouldn't happen, especially This particular vulnerability was technically in like a different area, I'm assuming, because that's they they s identified different endpoints. So it might depending on how the the code flow happens to get to the endpoint, it could be the same function that was vulnerable in in the beginning or just a similar type of function.
Sean McMillan: Sure.
Kendrick: I I don't know if it was exactly clear, but generally regression indicates it's the same function or a generally the identical function serving the same purpose. So in in this particular one I would say that regression is probably the the i i it's probably not the correct modifier here because i if it's a different code path I don't know if it's necessarily a regression but we can we can say that it's somewhat e it's somewhat linked maybe yeah yeah
Sean McMillan: It's just yeah. It rhymes with the old. Yeah.
Emilio Galle: Even sort of.
Kendrick: So give it the benefit of the doubt to the to the to the company here and be like, you know, hopefully it was just like a similar-ish function that happened to the same thing that resulted in SQLite. But SQLite
Sean McMillan: Yeah.
Kendrick: is also one of those things that kinda I wouldn't say been solved for a long time. It's one of those things that you shouldn't have it happen because there's a lot of libraries and a lot of coding Functions that are there to help you prevent that. Like there's sanitization functions.
Sean McMillan: Mm-hmm.
Kendrick: Yes, sure, you can sometimes find bypasses for those sanitization libraries, but like then you have a really big zero day in the sanitization library and not just like a particular product. So they probably just need to figure out how to implement a library that does this for them because they're clearly not quite doing it right.
Sean McMillan: Yeah. Why do you think GeoServer keeps showing up as a recurring target for these kind of opportunistic botnets?
Emilio Galle: I wouldn't specifically say that they're being targeted, it's just more so like considering what GeoServer even is, like number one, it's open source, so it's well known. And just the who uses GeoServer like is a set of a a set of teams that they need some sort of geospatial data and they need to share that across their researchers and other analysts. So they have to have It has to be public, you know, it has to be exposed some way somehow so that they can access it. And you know, not to generalize, but I don't expect that those teams have like an a specific SOC team looking at any sort of indications of they're being targeted mon or even just The fact that if they if there's like an exposure, I'm not so sure if they would have an an entire process of how we can mitigate our losses. So I would just say that they meet this a specific set of conditions that make them a promising target rather than they being being actively targeted. Because this came from a botnet as well. So it wasn't like a specific attack. It was just let me scan the internet and see what pops.
Sean McMillan: Yeah.
Kendrick: It's also geospatial data that's pretty valuable. Like and
Sean McMillan: Yeah.
Kendrick: and and things that run geospatial probably have a good reason to be running geospatial data. So it it's a really high value target in my like for probably government and it could be initial foothold access, especially if it's a running in a high privileged environment or high privileged configuration, I should say. that could potentially lead them to further compromise into a government entity of any kind. So geospatial data probably pretty high value, probably up on that list and that's probably why it was targeted at scale in this particular one. I'm not sure about the botnet. I don't know anything about this botnet. I know if it's like a government targeting botnet or anything like that, but yeah. It that's probably why we're seeing it at least Balloon and and size of exposures.
Sean McMillan: Yeah. this happened like Watchtower saw exploitation within hours. do you think like are researchers and attackers just watching the same feeds? Or is there like is there like you know what I mean? Like is there like a secret feed that the attackers are on or is it just like everyone's on the same websites doing the same thing and pouncing when it when it looks like it's time to pounce?
Kendrick: E everybody's tuned to that one Twitter account that just has all the data all the time. No, it it's it Yeah, yeah, yeah, yeah, yeah. See there you go. Yeah, yeah, yeah.
Sean McMillan: At Bishop Fox. No.
Kendrick: but yeah, i it's it's that's a that's a thing that we even struggle with on the Emerging Threat team, is just listening to all the data sources and knowing what's out there. 'Cause we have to like sure, people can publish things through Twitter unofficially and be like, Hey, I got this zero day, which I
Sean McMillan: Which happens quite frequently, yeah.
Kendrick: Yes, yes. and it's just like okay, how was I supposed to pick up on that? And like you just gotta be at the right time, right place and hope your Twitter feed gives it to you. Yeah, yeah.
Sean McMillan: Keep your ears to the ground. Yeah.
Kendrick: Various RSS feeds that you know. listening to. I know that some people use telegram subscription to or
Sean McMillan: Mm.
Kendrick: telegram channels to like subscribe to that type of information. I obviously I don't know anything about telegrams I don't know if subscribe is the right word, but you know, they listen in on those those
Sean McMillan: Sure, yeah.
Kendrick: those channels and they get feeded or fed information that way. So yeah.
Sean McMillan: Yeah, that makes sense. so I guess lastly here, if you're running GeoServer today, what's the first thing you're checking after reading this?
Kendrick: Yes. I I I'm I mean
Sean McMillan: That that Twitter t feed.
Emilio Galle: It's Everything.
Kendrick: I mean obviously you need to go check y w how what what level of permissions that your your GeoServer user was what was it the whatever user it was, was running as and then if it's running as system admin you should probably panic a little bit and f figure out real quick what you were storing there and look for compromise because they probably pivoted pretty quickly off of your your box if you're running it as system admin, so you know.
Sean McMillan: Yeah. Yeah. All right. Well, up next we have this is one of those stories where I have to take a leap of faith in pronunciation. Trezor disclosed that its fulfillment partner Shipmunk was breached, exposing names, email addresses, phone numbers, and shipping addresses for roughly 13,700 customers who placed orders between May and August 2026. Shipmunk told affected customers the initial access traced back to a maximum severity. CVSS 10.0 unauthenticated SQL injection, zero day in Metabase, the third-party analytics account. Shipmunks has since received extortion emails from the Shiny Hunters group. Trezor emphasized that its own systems, device firmware, and seed phrases were never touched. The exposure is limited to shipping and contact data, but that is an attractive set of data for attackers to to start running targeted phishing against known hardware wallet owners. this is from Bleeping Computer. Also, I want to give credit where it's due. What does a breach that starts in a BI dashboard and ends up exposing crypto hardware customers say about how far vendor risk assessments actually need to reach in twenty twenty six?
Kendrick: I I just love the name of this company, Chipmunk. Like like Chipmunk, like it's so good. Yeah, yeah.
Sean McMillan: All the all the names this week, there's so many
Kendrick: I I I think it's another one of those ones where so I when I when I put this in for for a summary to Claude, I like I was just like, What what do I need to know about this? And I was like, it's a har it's the physical d hardware device for for crypto and then
Sean McMillan: Mm-hmm.
Kendrick: It immediately made the link to like, there's actually been a rise in like physical break-ins related to like potentially stealing crypto and I was just like I didn't know that that was a thing and it's like, Yeah.
Sean McMillan: Doesn't that defeat the point of crypto in a way? Like it just feels so
Kendrick: Yeah.
Sean McMillan: weird. Like make taking the digital and making it physical again and then it gets
Kendrick: Yeah, I I would say that from from watching a lot of crime documentaries, people that are doing some nefarious things like to have like their crypto in their thing because they don't trust the institutions to hold it. So they actually wanna have like a physical hardware device.
Sean McMillan: Mm-hmm.
Kendrick: So not not saying that the their customers are this way, but that would be you know, they now have physical addresses for people that have ordered these devices and Claude was like, "Man, that probably makes sense that they might actually go after these people physic like and try to physically steal these devices." I was like, I didn't think about that. I was like, Yeah. Yeah. Yeah. I it was a
Sean McMillan: That makes a lot of sense now that you put it like that. Thank you, Claude. Yeah.
Kendrick: it was a great insight. And I was just like, Yeah, yeah. Like, because I didn't know a whole lot about the company. And so yeah, it's a good it's a good one.
Sean McMillan: Yeah, I had not heard of them before this. I don't I don't have any real money or crypto. So I don't really
Kendrick: Yeah.
Sean McMillan: need a great storage solution. but it's it's just like I w I was gonna ask about that, like why this would make so much sense. I mean, obviously there's like phishing. and stuff. That was kind of where my mind went. but but yeah, the physical knowing physically where these devices that are packed full of virtual money. That's a problem.
Kendrick: It it's and it's kinda like a a pinata. You you don't you don't know what's in the pian piñata until you you break it open. So yeah.
Sean McMillan: Yeah.
Kendrick: Yeah. I I don't know if Shiny Hunters is is looking for that type of information. from my understanding they're purely cyber. I I don't think they are physical operations at all. But if they are, then
Sean McMillan: Price is right. I don't know.
Kendrick: yeah, that could be a vector that they're trying to look to exploit.
Sean McMillan: Yeah. I mean, does this in your mind change like how an offensive assessment should maybe scope third-party risk? when the the vendor kind of has the keys on something like this? It just
Kendrick: Maybe it's just such
Emilio Galle: That's a hard one.
Kendrick: a it's such a side channel. Like like it i I don't know if that Evelier ever if you're the if you're Trezor trouser, Trezor, Trouser, Yeah. I don't think that
Sean McMillan: I'm glad everyone else is struggling with this too.
Kendrick: necessarily crosses the the security question necessarily. It's
Sean McMillan: Mm-hmm.
Kendrick: like They're shipping. They're our shipment fulfiller, right? Wha why does it matter? And then I you just gotta I I I think even from their perspective, they probably didn't think about this avenue necessarily, at least I'm assuming, but maybe they did. But yeah, it's it's it's a unique one, I think.
Sean McMillan: Yeah. Yeah.
Emilio Galle: I would just say that the TLDR is just hacking physical products is hard. And so we're saying that they're they're just hopping around and trying to get around that that difficulty. Why why hack the device when you can just ask for the seed phrase, right? Classic.
Sean McMillan: Yeah. Yeah. Take the easy way.
Kendrick: yeah. Well they they did say that they didn't leak the siege phrases or anything like that, but they now know where those people live, so they can just
Emilio Galle: Ha ha
Kendrick: go get the seed phrases from those people. So it's not it's not great.
Sean McMillan: Yeah. The I don't I don't care what the attack is, if you know where the people live, it then it gets just I don't know, a different level of scary. It's
Kendrick: It y it does. I especially people that want to have these physical devices, it's probably not a great day for them to to know that all of this information was leaked.
Sean McMillan: Yeah. Yeah, I don't wanna like pass a judgment on but it it does seem like it is probably people that are very privacy minded. and yeah, that's that's nasty. Now this is the the zero day in metabase that we published an advisory on as well. If I'm not mistaken. I'm almost certain we did.
Kendrick: Yeah.
Sean McMillan: and there is some like if you know. Too little too late for this, obviously. But if you are running metabase, check out our blog. There's there's some advice there of like basically patch everything right now. but also like how to how to tell if if you're in in trouble. yeah, geez. So all right, we got one more here, and this is we've been talking about names. I've been rehear I've literally been rehearsing this story because I can't say it. I I don't I'm I'm gonna do my hot take right here. I don't like the name. I don't like it.
Kendrick: Okay.
Sean McMillan: The Hat Man sells millions of records pulled from Azure and intra tenants. This also from bleeping computer, a threat actor using the handle, the Hat Man. Has spent the past two weeks posting internal employee directories, allegedly pulled directly from the Azure and intro tenants of at least nine Fortune 500 companies, including McDonald's, Vodafone, TCS, HCL Technologies, with McDonald's data alone totaling more than 1.7 million records. Hudson Rock confirmed the data's likely authenticity based on tenant-specific structure and field names that match standard Azure directory exports. And linked compromised Azure credentials from InfoStealer injections to employees at most of the named companies. Though the precise access vector remains unconfirmed. The leaked fields go beyond basic contact information to include job titles, managers, service accounts, global admin listings, which hand attackers a ready-made map for follow-on phishing or privilege escalation attempts. No Azure Platform Vulnerability or Zero Day is involved. This campaign is entirely run on stolen credentials and evidently insufficient MFA enforcement and privileged roles. a campaign of this size running purely on stolen credentials with no actual platform vulnerability is like this is this is a a case where you have to ask like Are we maybe under or over investing in cloud security? Like basically what went wrong
Kendrick: Mm-hmm.
Sean McMillan: here? How?
Kendrick: That's a great question. We don't know what went wrong here. other than credentials were used, or at least some form of credential was used. So
Sean McMillan: Yeah.
Kendrick: if it was like a token stealing, tokens are more powerful than usernames and passwords these days, in that they you already minted it. There's not usually a lot of restrictions after you mint the token most of the time. It's usually just like
Sean McMillan: Yeah.
Kendrick: an expiry and sometimes you can refresh it type of deal. So it's Concerning to the point where they didn't set these things to expire fast enough. But if whoever had this had an initial foothold on this device, anyways, and they just had to wait for you know employee number seven to come back to their desk and log back in again to
Sean McMillan: Yeah.
Kendrick: mint them a new token, then it's not that big of a deal, right? so it really just depends on what actually was the credential that was being exploited here to then inform, like, did MFA stuff fail, right? Or did Did they not georestrict
Sean McMillan: Yeah.
Kendrick: their, you know, ability to utilize a token from, you know, Russia? Like, yeah, we don't have any employees in Russia. We probably shouldn't be seeing a token being
Sean McMillan: Yeah.
Kendrick: used from Russia, right? that type of stuff. it's it it's really powerful these days about how things can be stolen and not always are credentials the thing that are stolen. A form of credentials stolen, I guess.
Sean McMillan: Yeah.
Emilio Galle: From what I from what I read from just some different sources, I do believe that this is even though we can say that there is no platform vulnerability, it it is dealing with a legacy API from Microsoft. So
Sean McMillan: Mm.
Emilio Galle: even though that it can be read as good news for Microsoft because you know, again, there was no clear vulnerability, no CVE, nothing of that kind. there is still the fact that they have this legacy sort of surface that is exposing some MFA details that shouldn't really be exposed. because I I was looking around and apparently they do have like a new API now that the specific like th this whole thing would be gated if they were using that. So I would just say that a lot of organizations they think that just because they have MFA is you know it's a checkbox have it or you don't, so
Sean McMillan: It feels like it should be, but yeah, I get I know what you mean.
Emilio Galle: but now you have to think about where is actually being enforced, right? Because legacy servers use services, you see it all the time, right? And if your MFA isn't there, there you go.
Kendrick: even if you do have
Sean McMillan: Yeah.
Kendrick: MFA, still token is the token, right? So
Emilio Galle: Yeah.
Kendrick: we we still don't quite know the w how they got this, but yeah.
Sean McMillan: Yeah. What how how does an attacker prioritize which stolen credentials to act on, I guess, when when InfoStealer logs surface access to a a global admin account buried among thousands of regular employee logins? Like what how how does it kind of what sticks out? I guess yeah, I guess that's control F, you know?
Kendrick: Organization chart. Yeah. Pretty much. Yeah. Yeah. I mean, there's there's lots of different tooling out there that helps you deal with active directory environment environments. And once you're already in, those active directory environments tend to be a little bit more lax, even though there's a lot of auditing going on and logging going on.
Sean McMillan: Mm-hmm.
Kendrick: still you can still g gather information over time, especially to see with the organizational structure, especially if you want to see who's in the IT department, whatever, like what roles do I have and all that fun stuff. So I I'm assuming that once they are logging all this information, they then piecemeal stuff back together and and look for elevated credentials. 'cause that's the only way you know is like you you go log in and see what permissions you have. Yeah.
Sean McMillan: See what they can Yeah.
Kendrick: And then you kinda just go from there. they probably maybe have an automated script to do that. So it's definitely one of those things where you gotta tighten tighten your active directories. If this isn't related to Microsoft token stealing, then then yeah, you you gotta you gotta have that audit log there to detect anomalies of, you know, why why does employee seven keep on looking at employee f forty six's profile? Like you know, this seems pretty odd.
Sean McMillan: Get HR involved. That's not right.
Kendrick: Yeah, right.
Sean McMillan: well I'm curious also, I know like you guys aren't necessarily red teamers, but a leak of service account and admin role metadata. Like how do how do you think that could potentially influence how a red team might plan like a follow-on social engineering campaign against one of these organizations?
Kendrick: Yes. And it does. Yeah. I mean it it does, yeah, yeah. Yeah.
Sean McMillan: Yes. I mean it it feels like, yeah. It it's it's it's obviously to in some ways like a treasure trove of this information. And you can
Kendrick: Yeah. Well they pr they probably won't
Emilio Galle: I mean
Sean McMillan: change passwords and MFA and that kind of stuff, but like the org chart ain't gonna change, you know.
Kendrick: Yeah, you need to fire like and rearrange a bunch of people just to like, you know, mix it up.
Sean McMillan: Ha ha ha.
Kendrick: Mix up the work chart. Like, you know a few promotions in there, a few demotions around, you know, just mix it up.
Sean McMillan: You've been promoted from fry cook to regional manager, yes.
Kendrick: Exactly, see, yeah, yeah. But on paper you're you're not actually regional manager, you're still Fry Fry Cook, yeah.
Sean McMillan: My my my dream when I was 17. All
Kendrick: Exactly, exactly.
Sean McMillan: right. Well, that is it for this week's initial access. Emilio, Kendrick, thank you as always for joining. And if you enjoyed the show, share it with a friend or coworker. If you'd like to keep the conversation going, join us in the Bishop Fox Discord server or over on the Bishop Fox subreddit. We discuss the research we're publishing, stories we're covering, and what practitioners are seeing in the field every week. You'll find links to both communities along with the articles we discussed today in the show notes. One of the things we keep coming back to on this show is that attackers don't always break rules. They just find assumptions everyone forgot they were making. Hopefully this week's stories gave you a little more insight to maybe some of those assumptions you're making. Something to think about. Thanks for listening. Stay safe, and we'll catch you next week.