Subscribe Share Full episode and show notes Vulnerability Management , AI/ML , AI benefits/risks Security Researchers Are Threat Actors – PSW #929 This week in the security news: Security Researchers Are Threat Actors according to Microsoft Hands-free malicious firmware If you’ve ever typed “ls” in Windows, this is for you Cisco makes more patches, wants you to pay Ambiguous Secure Boot bypass Threat actors love network edge devices, and I have the chat logs and leaks to prove it The downside of chip sanctions Your VoIP phone is hacked Vulnerability disclosure and incentives Claude reccovers Bitcoin wallet an Instagram “Exploit” Turn the plane around The worms will continue PAN-OS global protect vulnerability The 1-Click Github token stealer Data-nuking prompt injection Turning Buses into spies SymJack NIST NVD mistakes, and how CNAs... June 4, 2026 Full Segment Notes This week in the security news: Security Researchers Are Threat Actors according to Microsoft Hands-free malicious firmware If you've ever typed "ls" in Windows, this is for you Cisco makes more patches, wants you to pay Ambiguous Secure Boot bypass Threat actors love network edge devices, and I have the chat logs and leaks to prove it The downside of chip sanctions Your VoIP phone is hacked Vulnerability disclosure and incentives Claude reccovers Bitcoin wallet an Instagram "Exploit" Turn the plane around The worms will continue PAN-OS global protect vulnerability The 1-Click Github token stealer Data-nuking prompt injection Turning Buses into spies SymJack NIST NVD mistakes, and how CNAs need to up their game Hosts Paul Asadoorian @0offset https://securitypodcaster.com Jeff Man https://www.obsglobal.com/ Larry Pesce @haxorthematrix https://www.finitestate.io/ https://breakstuffforfun.com/ Lee Neely Sam Bowne https://samsclass.info/ Announcements If you’re in the SOC, you already know the pain. Too many alerts, not enough context, and attackers slipping through the cracks. Now add AI-driven attacks and increasingly complex environments. At the AI for Next-Gen SOC Virtual Cybersecurity Summit on June 24th, learn how to actually apply AI for detection engineering, threat hunting, and reducing false positives without breaking your workflows. Security Weekly listeners can register for free at https://securityweekly.com/nextgensoc using the promo code: CSS26-SW List of Articles Paul Asadoorian Microsoft’s Coreutils project brings Linux commands to Windows So many times I type "ls" instead of "dir", MS solved that problem Pwnd Blaster: Hacking your PC using your speaker without ever touching it This is awesome: "Creative’s Katana V2X can be fully reflashed over BLE using the undocumented CTP protocol, without pairing or physical access, letting any attacker within ~15 meters push arbitrary firmware. With a small patch (tens of bytes of ARM/Thumb), the soundbar’s existing HID “media keys” interface is extended into a full keyboard, so the device becomes a remotely triggered Rubber Ducky that types commands on the host PC while still behaving like a normal speaker." This is not so awesome: "Creative’s official position to SingCERT was that this “does not present a cybersecurity risk,” so the latest upstream firmware remains vulnerable and there is no vendor patch pipeline. The researcher’s community patch (v2x-patcher) simply neuters CTP-over-BLE, but in the wild a motivated actor could just as easily ship a persistent firmware that disables future updates, turns the mic into a covert listening device, and uses HID keystroke injection for code execution on every connected PC." Hands Free: What LLM Driven Vulnerability Research Looks Like A great, concrete, example of how LLMs are helping vulnerability research. This is great, however, can it help with the patch? Yes. But we still have problems: The vendors themselves need to use AI tools to find AND FIX vulnerabilities The bigger problem is getting people to apply the patches We still have job security even if we can find and fix all the vulnerabilities... A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure Security researchers that don't fall in line are now considered threat actors by Microsoft: "We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world. " - This is the wrong approach. Cisco sings Mythos’ praises – but doesn’t say how many bugs the model uncovered "The 1.8 billion lines of code, written in more than 25 different languages, spanned Cisco’s portfolio, we’re told. Netzilla paired the models with a “human-guided harness,” and achieved a false positive rate of under 3 percent, Grieco wrote." - That's nice, but maybe we could use AI to help Cisco customers apply the patches? Also, customers have to pay to apply patches, so when Cisco releases a gagillion patches, they will want you to pay... Security Advisory: Upcoming Firmware Update for Acer Wave 7 Router This is one of the best, or worst, vulnerabilities ever: "The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access." - It should really be two: one for incorrect access permissions and one for exposing/storing sensitive data, right? Announcing Bitskrieg Speaking of Nightmare Eclipse: "[We] found a way to violate secure boot trust, it's not a full secure boot bypass but it breaks the guarantees secure boot is supposed provide. We believe this be used to compromise confidential virtual machines but we're not really sure if that's possible since we don't have access to such technologies. One thing we're sure of, is it fully bypasses bitlocker." Gentlemen Ransomware Exploits Fortinet Flaws, AI, and Custom C2 Tools Threat actors love network edge devices, and I have the chat logs and leaks to prove it: "The Gentlemen kept going on the same plane. Their primary initial access vector across the corpus was Fortinet, with 81 mentions of FortiGate in the Rocket. Chat logs and CVE-2024-55591 (the FortiOS auth bypass) named explicitly. Branded VPN passwords used across multiple victims: gentlemen25, Gentlemen25, gentle26. Halcyon's separate analysis records the group brute-forcing roughly 1,000 Fortinet VPNs." Pointing a Cursor at evading detection "I need to create a testing framework" instead of "I need to create a malicious software that discovers and exploits, then implants malware": "As in legitimate developer environments, the attacker used Cursor and Claude Opus agents to assist with software creation, testing, performance evaluation, and revisioning. While these tools were ostensibly used to create a red team framework, it is likely that the threat actor used this terminology to circumvent Claude’s guardrails around malware development. In reality, the framework was built for stealthy post-exploitation activity in target environments. Sophos Counter Threat Unit™ (CTU) researchers have linked this development activity to known ransomware deployment and data theft operations." An AI audit of FreeBSD This is the correct approach: "We are not trying to chase CVE numbers or post bug counts. We just want to be useful to the people running the project." - Also, it's one of the things that goes wrong with disclosure: incentives. Finding bugs to gain popularity is the wrong reason. Huawei chairman thanks the US for export restrictions on chips The downside of sanctions: Sanctions as Unintended Accelerant - Huawei Rotating Chairman Xu Zhijun openly stated: "If the U.S. hadn't pushed our country, our company, and our industry, we wouldn't have tried to do this." Export controls — starting with the 2019 Entity List addition and escalating through Biden/Trump-era chip restrictions — created a protected domestic market with forced demand for Chinese silicon. Nvidia CEO Jensen Huang has repeatedly made the same argument from the other side: blocking access doesn't kill demand, it redirects investment. For a security audience, this is a textbook case of how supply chain weaponization has second-order effects. Novel Architectures Emerging from Constraint - Unable to access leading-edge EUV lithography or advanced NVIDIA/AMD silicon, Huawei developed its LogicFolding architecture — a vertical circuit-stacking approach that reduces signal travel distance as a workaround to process-node limitations. This matters from a threat intel perspective: sanctions-driven innovation means Chinese chip capabilities are now advancing along non-standard architectural trajectories that Western benchmarks and export control frameworks weren't designed to assess or contain. The Strategic Dilemma Washington Created - Analysts note the export controls likely delayed China's AI semiconductor progress by several years — but simultaneously funded and politically justified Beijing's entire domestic chip self-sufficiency program. Chinese cloud/AI firms shifted spend to Huawei Ascend processors en masse, giving Huawei the revenue and scale it needed. The podcast discussion angle: at what point does the delay cost become less than the capability cost of creating a fully indigenous, sanctions-immune competitor stack? Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557 CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED) A critical unauthent
A critical vulnerability in FortiProxy and FortiOS (CVE-2024-55591, CVSS 9.8) allows unauthenticated remote code execution. Affected versions are FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and FortiOS 7.0.0 through 7.0.16. Patches are available in FortiProxy versions 7.0.20 and 7.2.13, and FortiOS version 7.0.17.