Skip to content
TrackPodcasts
newsSep 23, 20268:58

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

Risky Bulletin

Get every episode summarized

Each time Risky Bulletin publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“A network of 10,000 AI service is masking malicious Chinese AI activity. Ukrainian hackers leak Russia's naval secrets. Shiny Hunters hacks the FBI and the evil token's fishing service is disrupted by tech companies.”From the transcript

A network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.

Show notes

Hosts & guests

Transcript ready

90 searchable segments. Every word is indexed and playable.

Risky Bulletin: Team Cymru unmasks shady Chinese proxy network

Risky Bulletin

0:00
8:58

Full transcript

Risky Bulletin — Risky Bulletin: Team Cymru unmasks shady Chinese proxy network. Machine-transcribed; use the interactive transcript above to jump the player to any line.

A network of 10,000 AI service is masking malicious Chinese AI activity. Ukrainian hackers leak Russia's naval secrets. Shiny Hunters hacks the FBI and the evil token's fishing service is disrupted by tech companies. This is the Risky Bulletin, prepared by Catalan Kimpanu and read by me, Claire Eard. Today is the 23rd of September and this podcast episode is brought to you by SpectorOps. Security researchers have discovered a network of more than 10,000 proxy service that are enabling Chinese distillation of American AI models and other illicit activities. Security firm Tim Cunry, analyzed 100 of the service and found they were being used to bypass region bands and carry out distillation attacks. Most of the service ran open source AI Gateway Service Software. Some of these open source projects are being sponsored by illicit service providers,

including API relay resellers, residential proxy vendors, and people who were selling compromised AI accounts. In other news, a Ukrainian hacking group has leaked technical documents about more than 70 Russian naval projects. The files were allegedly stolen from Russian scientific research centers and manufacturers. They include in-depth details on submarines, warships, navigation systems, sonar technology, and autonomous underwater vehicles. A group calling itself Ukrainian militant has taken credit for the leak. E-commerce platform Big Commerce has notified merchants of a security incident involving a third party app named Ribbon. Hackers stole a Ribbon access key and used it to inject malicious scripts on stores hosted on the Big Commerce platform. The scripts were liven for five days in September. Big commerce revoked the key on September 17 and uninstalled Ribbon from all stores.

Attackers are believed to have collected customer details from all affected stores. The Shiny Hunters group claims to have stolen data about most FBI agents, as well as individuals who applied for jobs with the Bureau. The group also defaced the FBI job portal, which the agency took offline on Tuesday. Shiny Hunters claims the Bureau's recent security alert on the group's tactics contained incorrect information. The group said it would release the stolen data if the agency didn't correct or take down the alert within a week. The US National Institute of Standards and Technology will award eight states more than $1.7 million in total to help address the shortage of qualified cybersecurity professionals. The money will go to educational and community organisations to establish cybersecurity training programs. It will also cover internships, apprenticeships and hands-on projects. Island's Data Protection Agency has fined Google 403 million euros for breaking GDPR data processing

rules. The agency says Google manipulated users into sharing their location data through complicated account settings. It began investigating the company six years ago, following multiple complaints from data privacy organisations. A California Court has ordered two software companies to stop mass scraping LinkedIn Profiles. LinkedIn sued pro-API's NetSwift and their CEOs last October. LinkedIn alleges the company used millions of accounts to harvest profile data and user activity. A coalition of tech companies has disrupted the evil tokens phishing platform. The service launched in February this year and quickly became popular due to its ability to carry out device code phishing as well as regular phishing campaigns. Microsoft says the service was used to hack at least 12,000 email accounts. Microsoft's legal team seized domains and servers while other companies tracked evil tokens profits and identified its operators and customers.

UK police also arrested two of the services suspected operators earlier this month. A Chinese-speaking threat actor is hacking a large assortment of web apps, servers and devices and deploying backdoors on them. The Red Heron Group has been linked to attacks on GT repositories, ubiquity devices, zyxel switches, WordPress sites and AI servers. Security firm Gray Noise believes the attacker is focused on data theft and uses LLMs to assemble its attack tools. A Chinese sponsored hacking group has breached shipping and maritime organisations in four EU member states and government agencies in three others. The hacks took place last year and involved compromised USB devices. The EU's cybersecurity agency described the Chinese activity in a report. The same report found Iranian hackers had also targeted the EU's transportation sector but had focused mainly on airlines. A Russian threat actor has been using an arsenal of

exploits to spy on Ukraine's defence and aerospace sector. The campaign began in June last year and is ongoing. Security firm Sock Raider discovered the operation after the threat actor misconfigured its command and control server and leaked more than 8,400 files. Most of the attackers' exploits target older vulnerabilities in enterprise and edge network software. Checkpoint has patched an actively exploited zero-day in its security management server product. The server is used in large networks to manage checkpoint products from a central location. The patch fixes a directory traversal vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts. The company also marked a separate vulnerability as exploited in the wild. That one impacts the checkpoint site to site VPN and was patched last week. Meanwhile, F5 has patched an actively exploited zero-day in the big IP access policy manager

component. The zero-day allows an unauthenticated attacker to run malicious code on the big IP server. Exploitation requires a specific big IP access policy and OAuth profile to be configured on the server. No details about the attacker have been released. A RISTA network has patched a zero day in its bellow cloud orchestrator on-prem server. The vulnerability allows remote attackers to access internal functions without authentication. Security researcher Nightmare Clips has released a new Windows Defender zero-day. The so-called big-disc Buster vulnerability is a denial of service bug that prevents defender from performing platform and signature updates. The researcher published the exploit days after he also revealed his real name is Abdelhamid naturi. Security researchers have found malware in two Terraform providers and two Go modules. This is the first known case of malware on the Terraform registry. The malware is a go port of

the Grafago NPM malware that was found in February. It uses a Slack channel as a command and control server and deploys a rat on selected workstations. Microsoft has added a new feature to its Windows recovery process. The new feature is named Cloud Rebuild. It can perform full OS reinstall and can even be used when the OS isn't booting or the user can't use USB media. Apple has shipped a new security feature designed to detect active social engineering scams. In-personation risk detection shipped in iOS 27. It allows users to share sensitive data with third-party apps so the apps can detect scams. Share data can include download history, pass purchases, and email and phone call data. And finally, Cisco Talus has released a tool that detects malware that was built with or uses AI components. The cognitive artifact intelligence research network or can framework works

exclusively with virus total metadata. It searches virus total file uploads for specific artifacts left behind by AI toolkits. Can is open source and available on GitHub. And that is all for this podcast edition. Today's show is brought to you by our sponsor, Spectorops. Find them at spectorops.io. Thanks for your company.

More episodes

More from Risky Bulletin

View all episodes →