Skip to content
TrackPodcasts
technologySep 11, 202634:36

9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615

About this episode

Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on.

Then we get to work.

Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it.

Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises.

Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass.

A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did.

The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked.

Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie.

Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent.

All that, plus Josh Marpet's take, on Security Weekly News #615.

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://securityweekly.com/swn-615

Get every episode summarized

Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Transcript ready

284 searchable segments. Every word is indexed and playable.

9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615

Security Weekly Podcast Network (Audio)

0:00
34:36

Full transcript

Security Weekly Podcast Network (Audio)9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hello and welcome to Security Weekly News episode 615 on Friday the 11th of September 2026. Okay, before anything else. Today is 25 years since 911 and we're going to mark that, well I'm going to mark that properly in a moment. This week, the left hand edge is shift left and our controls didn't. 10,000 malware loaders hiding behind gaming videos, a CVSS 10 and Gemini CLI that never needed a prompt. The first ever Take It Down Act sentencing, 263 million dollars walked out of Bitcoin sidechain and then some of it walked back and an un-tropic safety lead who regains her to better and one in 10 chance. This all ends badly. All this with Josh Marpett and more on Security Weekly News. It's the show that keeps you up to date on the latest security news twice

a week. You're trusted source for accurate security information and expert analysis. It's time for the Security Weekly News. Welcome back. Okay, if you're getting something out of this show and especially when Doug and Josh are on, you definitely are. Do as a favor, subscribe, review, send it to someone on your team that's dominant needs to be smart. Everything we do, it's securitywink.com, podcast newsletters, webcasts, all of it. And you know what? I even read the comments on YouTube and we're still more pretty bad, to be honest, about me. But anyway, right? Okay, 25 years. Today is September 11th, 2026, 25 years. 2,977 people did not come home that day. And I'm going to be very careful in my words as with some of these stories today. We remember the people who were killed in the tar, as the pentigan, the four aircraft on the grind,

the firefighters, the police, the paramedics, the poor authority staff who ran towards it. But there's also the people that are still here. And 25 years later, there are survivors and responders living with us every single day. Thousands of the morale from what they breathed in at grind zero, cancers, lung disease, and conditions that only turned up years later. And thousands more, and we'll get a bit more mental health later, carrying it in their heads. The ones who got out, the ones who watched, the ones who spent months in that pile looking for their friends, physical and mental scars, both real, both kind. So, every one affected the families, the survivors, the responders, the people still fighting for treatment and a recognition, a quarter of a century big love to you all today. We have critical infrastructure protection, information sharing, coordinated national cyber response, a huge amount of what we do in the

industry, traces right back to that day. None of us can pretend it didn't shape the job. Okay, deep breath, because I've had shivers all day and just needed to get that out. Okay, this is the cyber rundown for Friday, the 11th, December, 2026. Facts first, my view, and then a short list of things to do is mostly the way this is hopefully going to go. Story one, the left and shift left moved. 15 years we've told developers to shift left, catch the floor earlier, catch the secret before it hits the repo. That assumed a human wrote the code, committed it, opened a pull request, and then had a security control. Chris Hughes at Resilient Cyber makes the point that AI code in agents have quietly broken that assumption. An agent now reads the issue, inspects the repo, writes the code, picks the

dependencies, runs the tests, edits the workflow file, and opens a pull request. So how are we meant to know where left is now? It's not the first commit. It's the moment the agent receives context and authority. Agent development adds a whole layer before any of that exists. Reportisatory instruction files, persistent agent memories, MCP servers, shell permissions, inherit it, environment variables, credential, sitting on the runner, and the auto approved mode, which is the one that I might sometimes use on a vibe coding project, which is growing legs, taking up all my free time, and might have burned more tokens in your Grammy in Vegas. Okay. I'd say SST scan will find common injection in generator code, hopefully. It will not tell you

the agent read attacker-controlled instructions out of the repo before it wrote the code. Right. Okay. I think shift left hasn't failed. It's a good theory. I don't buy that for a dollar. I had my head just load some music and like, silly 80s comments in my head and they won't go away. So the starting line moved and whatever I was saying, we didn't move with it. What you should do, define an approved agent catalog, which agents, which models, which MPC, MCP servers, get every agent at its own identity with bind privileges, stop sharing a human's token. How many times I said all this? A treat repository instruction fires as active content. Okay. Next. 10,000 loaders hiding in plain sight. Pallow-alta unit 42 have published on a long-running paper install operation that tracks his CL-CRI 1171, which has an interesting part that isn't a clever

payload. It's the distribution layer underneath. At least 11 gaming YouTube channels, hundreds of thousands, hundreds of thousands of subscribers, millions of views, genuine looking content, frame rates, crash fixes, optimization tips, the link to the performance pack. That isn't right. There's a link. It's just it's badness in it. Plus SEO poisoning on searches for legitimate tools and they get at the traffic. The tracker URL carried and included click ID with your OS browser, referral, shirts, terms, and public IP. The thing looks great and then you get a payload. It's like scanner or analyst. That's funny. That's a check. Just come up my computer. Scanner or analyst does not matter. You get the decoy. The shared loader is called offer loader

and unit 42. You find more than 10,000 distinct samples. That's 10,000 samples, not 10,000 victims. So the size of the infrastructure is just massive. One of the families is Dockrow, hijacker, a chrome back door that edits chrome secure preferences, then computes valid integrity values for the settings that just changed. Nothing looks fricked about with. The paper install model is one operator infecting machines, then selling that access to multiple buyers with different malware, different C2, different objectives, seeing beautiful idea. When your analyst closes an alert as hardware, would they? Would they? Hope not. They majored to closed, according to the article. One of the articles three separate compromises. Okay, I think this is operational camouflage.

It's not technically brilliant. Every layer was built to look too boring to ask you. The tree as question isn't just how bad is this detection? It's what business model sits behind this. So do this. Treat on authorized browser extensions and secure preference changes as a real possible compromise, right? And if you come for a maloder like this, rebuild the host. Don't remove one binary and think job done, T and metals time. Zero trust is clearly the future as threats get faster, quieter and harder to detect, but implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead.

CYC'sos are adopting it at securityweekly.com slash threat locker. Google's AI threat tracker from prompting to autonomy. I have everybody loves that pilot at the minute. Don't know. Okay. Google threat intelligent groups. Actually, I went to Google HQ in London this week and it was nonsense. I sat in something that was meant to be an AI masterclass and it was a sales pitch. Do no bad, Google. That was bad. That was really bad. Anyway, the September update is out and the headline is moved from isolated prompts to agentic workflows. The case study you'll see people spouting off a bite all over the place is a financially motivated actor compromise cloud infrastructure and then built and ran a mass credential harvesting campaign in six hours. I tell you, you want to see me when I'm on a ADHD hyperfocus. I could have built it into. But anyway, thousands of third party credentials

and AI coding chatbot, a prompt and a pre-written markdown file used as playbooks. Agents did the scamming, the troubleshooting and the IP rotation from the victim's own cloud addresses and the cool bit. Some malicious loaders carried deliberately extreme prompt injection text designed to make an LLM based security scanner reviews to analyze the file. And I totally see where this is coming from because only today when I was doing research for this show a really important story five. And NLLM, which I'll not name, refuse to research that subject, which is okay because it'll make let me like get running the guardrails and make a firework, but I can't research a sensitive topic to enhance awareness. Okay, back to the point,

if your scanner treats a refusal as a completed scan, the malicious code underneath could pass through it. And then the vision happens, right? Google explicitly say they have not observed fully autonomous and the end attack pipelines in the wild. Humans still pick the targets and set the goals. Agentic, according to people, does not mean autonomous. Well, it does when I press a button. Anyway, I think the most important word in this story is an AI, which is kind of two letters and not a word, but anyways, it's latency. We have quietly dependent on attacker friction for 20 years. Sleep fatigue, toll breakage, being shit, decisions by hand. It's like agent removed big chunks of that and it breaks our response economics. There's your terminal today response economics.

A socket to text in minutes, but wait for ours for change approval. Still getting smashed up and that's do this inventory your new AI DevTools local agents, MCP servers and model readers. You might have more than you can think make LLMP scanners feel visibly because a refusal must never equal clean. And a six hour compromise scenario. That's what's needed in your next tabletop, right? Which is a hint of what's keeping me from sleeping at the minute and having type a fun at the vibe coding palace in London. Okay, next story for no prompt injection required pre-task RCE in Gemini CLI presented at Defcon where me and Doug didn't go. Josh went probably. Josh goes everywhere. It's because he's beautiful. Presented at Defcon by Novi researcher Elad Megid.

Like, and this is this is a beautiful story. It's good. It's well written. CVE 2026 12537 with CVSS 10. That's solid 10 Gemini CLI and this is the numbers 0.39.1. And the run Gemini CLI get her back. She before 0.1.22. So Google patched it back in April. There was a walk through at Defcon. And I'm going to tell you why it was beautiful in a kind of let the world burn type way. No prompt injection, no model manipulation, no malicious tool call. The model was never involved. Gemini CLI launches a sandbox proxy from an environment variable and the variable vulnerable version ran that command through a shell. Inheadless CLI, C I sorry,

their workspace was automatically trusted. So an attacker opening a pull request could drop a crafted dot Gemini dot EMV file into the repo and their values got loaded. The proxy launched before the sandbox inherited the parent environment before the secret sanitization and shell medic characters were were all the fun was that. So you could you find it. So he got the name it just like stars. No V called it pre task authority. Attacker input got execution before the model, the sandbox and the guardrails got to do their cool jobs. Now look at what the defenses were doing at that moment. Docker sandbox. The malicious code ran before it. Environment sanitizer, the process had already inherited the original environment. To the lie list, the model never

requested a tool prompt injection controls prompt injection as everywhere. There was no prompt, right? Workspace trust prompt. Nobody's there. Inheadless CI. So trust was automatic. Every control was real. Every single one protected the wrong phase. And just a little bit on the scope. You need a workflow that auto-proo to test untrusted pull request content with secrets attached. So that to me myself and I still describe the shit tongue of public repos, right? I'm from what I have read from why I've read. Nobody's find any evidence of broad exploitation. Look, demonstrated it is not the same as used. This made me laugh. I wrote we spent three years. And I like for all

these were up just when years comments, I kind of just put my finger in the air and like, oh, I think that's what it is. So you're probably smarter than me. Three years telling everyone to worry about prompt injection. And the attacker danced around the prompt, around the model, around the sandbox by arriving before all three. So if you want to be the first at a bond, you'll be concert so you can fist bump them. Oh my god, that concert was so good. I wasn't. I'm never first. Never first. Anyway, calling your product an AI agent doesn't make compact command injection go away. The test for every agent platform is now what execute before trust is established and what secrets exist. At that moment, right? Do this. Upgrade Gemini CLI to the one after that and the action after that other one. Pin reviewed versions don't use mutable tags and check your CI logs for cell

execution before the agent's normal startup telemetry. So that's going to be fun for the weekend. Next story five, right? This is the one that the LLM wouldn't play on. Cause people are evil. Not the LLM. The first ticket dynast sent the thing on a shout out, a big shout out on this one, because it matters, right? Okay. The subject matter is horrific and there's real victims behind it. On Tuesday in Southern District of Ohio, James Strathler, became the first person in the United States sentenced under the ticket dynast 15 years, which never seems like enough does it? The US Attorney's Office describes cyber crimes involving real and AI generated sexually explicit images and threats of violence against numerous victims.

More than 3000 images across his devices. So obviously we're not going to go into the detail here and Samantha calls reporting at 404 media. But the link in the show notes is there if you want some more. What I will give you is the timeline because the timeline is the story under this cyber lens. Charge were misdemeanors in January and released. He carried on stalking and harassing his victims more charges in April. Like there's just not enough women prisons for these people. Is there like prison prison? Straight away. In June more women came forward. Police handed it to the FBI and the federal charges came after that. The ticket dynast came in the force in May in between his first arrest and those federal charges. So it's the first UL federal law making a crime to knowingly

publish or threaten to publish non-consensual intimate imagery, including AI generated material. So we're not law enforcement. A lot of you will have worked with them. We're parents or you working security. So what matters? A one day someone might tell you something. So what do you do? And research is more like don't just go off me. This is just some tips. Do not investigate it yourself. Don't download anything. Don't see if anything is evidence and don't go and confront anyone even though you might want to. You could wreck the case and put yourself in legal trouble and you don't want to end up taking up one of them jail spots that's for them people. If a child's in immediate danger from 999 in the UK 911 in the US straight away in the UK reported to the National Crime Agency's CEOP Safety Center and report the image itself to the Internet Watch Foundation.

If a young person under 18 of those like if it's someone under 18's image report remove child line and IWF work together. It gets content taken down without the child haven't speak to the police for a brilliant service right? In the US it's NC Max just google it, take ticket.ncmc.org for over 18's there's different go to the link through the research report it. Okay shout out if you're a parent or have teachers online go and follow Dale the Cyber Safety Guy he's at Cyber Safety Guy across socials and the site is cybercestiguy.com. Dale 22 year old 22 22 year old you wish Dale. RAF please veteran with eight years in cyber security and digital forensics. I'm 22 years I did 23 and a half so get some time in Dale but during his service he

analyzed evidence and criminal investigations involving child sexual sat I can't even say the word I'm so mad child sexual exploitation and that's a job that takes it out of a person and it took it out of him and that's why advocates mental health and why advocates what he does now and a bit of symmetry he now works at unit 42 at Palo Alto like like so many people I know work there unbelievable right okay he publishes good stuff free guides no paywall no sign up no data collection an app safety checker type in any app to get the real world risk stranger message in location sharing not just the age risk the age written and his core message isn't install more blockers it's conversation this is important it's conversation talk to your kids build the relationship so they come to you when something goes wrong and every penny from a paid subscription from his newsletter

goes to child line and and I'm sure this week I seen that super nanny follows him so it must be good okay Dale made chiptius friends great work genuinely keep going I know you were at the start thinking it's not getting the traction it deserves and I agree with you and I hope it is not I and I'm sure it is and it definitely will okay next story they take 263 million dollars they give it back well sort of sixth is timbers someone withdrew roughly four thawed and bitcoin from the wallet backing the liquid network side chain around three hundred and twenty seven million dollars at the time liquid halted the network exchanges paused l b t c deposits and withdrawals and then the actor described itself as a white hat operation which signs of a grade on that by the seventh about three thousand four hundred bitcoin have been returned like look

from reading these around five around five hundred ninety and around six hundred bitcoin around forty seven millions paid with them which is not a bad day in the white hat world when the rest of us are happy unhappy to receive like three hundred and seventy four dollars from Microsoft for all the good work but all of use all of use that do that good work it's like keep it up because it's what's keeping us safe right okay next story on the white hat label crazy no pre authorized by day and they're going on about no key stolen they capital to money it's like it's just this is like the federation faithfully authorized a withdrawal right the cryptography like it's just like the problem is the system has already

been convinced when this went through that counterfeit l b t c was real the approvals were authentic and the payment was still wrong look into the story and if you're in the financial services especially in the crypto game which i'm very glad i might off you need to look at this because perfect signing controls broken ledger validation da da da it's like what you need to look at is validate your economic invariance independently build circuit breakers rate limits withdrawal caps anomaly detection look and get if this is your if this is yours look and get the thread landscape just shifted under your feet attacks movement machines speed now and you can't defend what you can't see tainium atlases change that one prompt and it queries every endpoint in your fleet surfacing machines exposed to a live axiote supply chain compromise in seconds this is live state not a stale cmdb

it pinpoint twitch endpoints are truly compromised and traces the attackers command and control atlases secures the business by isolating patching and remediating all at once tainium atlases see everything act instantly find out more at securityweekly.com slash tainium right okay over to my good friend Josh who's going to pull this all together and give you some very exciting stuff well i don't know how exciting it is but i love the fact that we can now get some of our reach news from eight k's from the sec the securities exchange commission because they're required company publicly traded companies are required to notify the sec if they have a notification event and there's a whole long list of what's a notification event but i need to move quickly vera dime i think i'm pronouncing that right vr a di gm has had a eight k published where they had a third party who took some vendor credentials the third party credentials to a patient facing

api and downloaded patient personal data social security numbers but no clinical data because that's so much better that they only got their social security numbers the the ransomware group called the gentleman claim three and a half million records so it's unconfirmed but because vera dime hasn't corroborated but you know it's it's still it's ugly bad okay i read the eight k it's kind of bland and kind of boring so i went looking for some other things this is the second time so vera dime had it happen in 2024 and that was when somebody used a legitimate customer credential not a vendor credential to get into a storage account they lost 2.6 million people's records and they had a ten and a half million dollar settlement that started paying out in June so from 2024 to this past June just a few months ago basically two year lag for them to pay 10 and a half million what is 10 and a half million for two and a half million records it sounds like about four bucks a record that's not exactly the most exciting settlement i've ever heard of

so now they've lost apparently approximately three and a half million records is what is claimed is it going to be now fifteen million dollars they're going to have to pay out when are we going to make companies actually pay out enough that they regard it as a deterrent and they regarded as cheaper to do the security that's kind of my point so i'm i'm i'm very uncomfortable with the fact that we're talking about a third party credential we should have third party risk management vendor risk management we should have credentials that have limited scope limited space limited privileges limited everything and if we don't we're doing it wrong if you're not doing your iam if you're not doing your mfa if you're not doing your inventory of information and access control of that information let's be clear at this point in time you're doing it wrong this is simply a fundamental a table stakes thing that if you're not doing you're doing it wrong i want to be very clear on something by the way that's going back to what you started this show

i used to work in the twin towers i was not there that day and i had stopped working there a few months prior i got laid off but i saw the towers come down i was still living in northern New Jersey at the time and it was pretty traumatic and i'm hoping to raise my children in a world where that kind of thing doesn't happen and where we realize that people are people and we can all live in peace as long as we try to back to you all right thank you Josh great words and we are article just always making me look bad but okay good stuff is always one more for me and i'll let you go and this is a bad segue the world is ending but the world's always ending right so grab a cup of cocoa and strap in right story it a better than 10% chance we all die

have a lovely weekend kind of end like that can we so Evan Humbinger and let's like the titles reported different like alignment scientifically lead at unthrobic i've seen some of it say ahead ahead of ai safety but i think the former rather than the latter is correct okay he wrote publicly this week that he personally believes there's a greater than 10% chance ai could kill all humans within a decade what we have to wait that long he's also said unthrobic as trying its best has no plan yet to solve alignment for superintelligence and isn't clearly on track to get one this came after researcher Jacob Coxon resigned accusing both open ai and unthrobic of racing straight to self-improving superintelligence that post tens of millions of views

Humbinger said he thinks the risk from present models is low his concern is the future superintelligence arriving through recursive self-improvement do you know i wish i had recursive self-improvement every day try to be better i'm gonna try and be better today today's a good day to start so nobody has sent a clawed instance used this morning has a one in 10 chance of ending humanity by Christmas unless i'm using it right and if it does like clawed i wasn't pushing you that hard for my vi-coding product project it's not a product yet maybe one day it will be right look a personal this was from him a personal subjective estimate not a corporate forecast not a consensus number not an actual model you cannot back test the apocalypse but you like can't put confidence

interval on it but it's not a reason to bend this like we hear wild numbers in ai it's like nobody cares they just throw out numbers and percentages at the end of the day do i think the world's gonna end with ai probably not and i'd like a decent run at it first because i just want a party want a party with my friends look you can pick your own percentage it's gonna be really low you just need we need controls systems acting with non-human identities like we just like just have some review have some guardrails that someone will get a rind look right it sounds like the guy who's trying to make himself famous but capabilities are coming on faster and faster and we should be aware we should be aware and you should be aware and you should be careful and you shouldn't be scared and it's not 10% and shift left's moved and the jobs getting

harder and but don't fear the models anyway right that's your lot same time next Tuesday i'm back to the professional comedy and dog will be back with a fun isn't that man funny thank you Josh thank you team one last shout out to Dale cyber safety guy dot com send it to a parent cost you nothing look after each other spare a thought today on September the 11th be better peace out cyber people thanks for watching if you want more content like this head over to securityweekly.com slash subscribe you'll find all our shows the latest episodes and everything happening across the security weekly network see you next time

More episodes

More from Security Weekly Podcast Network (Audio)

View all episodes →