🤖 Exposed AI Models - Public Access Vulnerability
This article highlights the discovery of AI models left exposed on the internet, allowing public access to potentially large and sensitive models.
Key Points:
• AI models, including large ones like Kimi 1T and Deepseek 765B, are publicly accessible.
• These models are inadvertently exposed on the internet.
• The exposure allows external users to interact with other organizations' AI systems.
🔗 Resources:
• StolenCompute ↗ - Information on exposed AI compute resources
Image
Image
🚀 Threat Hunting - 13Cubed Mini Course
This article announces 13Cubed's new "Architecting the Hunt" mini course, designed to provide a repeatable framework for threat hunting through hands-on lab exercises.
Key Points:
• 13Cubed is releasing its initial mini course: "Architecting the Hunt."
• The course provides a repeatable framework for threat hunting.
• It includes a lab environment with 100 hosts and over 9 million events for practical experience.
🤖 AI - AGI Perspective from 2015
This article humorously reflects on the concept of Artificial General Intelligence (AGI), implying a satirical perspective on its historical presence.
Key Points:
• A tweet suggests AGI was present in 2015.
• This statement is accompanied by an image related to basic machine learning.
🤖 AI Industry - Unexpected Collaborations
This article notes an unexpected collaboration within the artificial intelligence sector, as indicated by an accompanying visual.
Key Points:
• An unexpected alliance has formed in the AI industry.
• An image accompanies the post, providing context for the collaboration.
🤖 OpenAI Support - Correcting Account Warnings
This article reports on OpenAI Support issuing an apology for an incorrectly applied warning to an organization's account.
Key Points:
• OpenAI Support acknowledged issuing an incorrect warning to an organization's account.
• They apologized for the error and any resulting inconvenience.
🤖 Cybersecurity - LLMs in Cyberattacks
This article discusses a report detailing how suspected China-based operators are integrating Large Language Models (LLMs) into their cyberattack workflows.
Key Points:
• Suspected China-based operators are incorporating LLMs into their intrusion campaigns.
• Specific LLMs like Claude Code and DeepSeek-v4-pro are being used.
• These models are part of the operators' operational workflow in cyberattacks.
🔗 Resources:
• Hunt.io Blog ↗ - Blog on LLMs in cyberattacks
🤖 Cybersecurity - Modern Intrusion Traits
This article outlines three common characteristics observed in modern cyber intrusions and the malware employed in these attacks.
Key Points:
• Intrusions often target edge devices lacking security software, such as VPN appliances.
• Security telemetry and alerts are disabled on systems with endpoint protection.
• Malware is designed to avoid leaving traces on the local file system.
🔗 Resources:
• Volexity Blog ↗ - Blog discussing modern intrusion traits
🤖 Cybersecurity Threat - TA488 (Void Blizzard) XSS Exploits
This article summarizes a joint report from NSA, FBI, and allied agencies concerning threat actor TA488, known as Void Blizzard or Laundry Bear, and their use of half-click XSS exploits.
Key Points:
• A joint report was released by NSA, FBI, and allied partners.
• The report focuses on threat actor TA488, also known as Void Blizzard.
• TA488 utilizes half-click XSS exploits in their operations.
Image
Image
Image
🤖 AI Ethics - Hacking Liability
This article explores the legal implications and questions of responsibility regarding an OpenAI model reportedly hacking Hugging Face.
Key Points:
• An OpenAI model allegedly compromised Hugging Face.
• Questions arise concerning legal responsibility for AI-driven security incidents.
• It is unclear who would be accountable if charges were pursued.
🚀 Cybersecurity Event - SpecterOps Black Hat USA Gathering
This article announces a SpecterOps community event during Black Hat USA, providing a social opportunity for security professionals.
Key Points:
• SpecterOps is hosting a community event during Black Hat USA.
• The event will take place at B.B. Bowl Vegas.
• It offers networking for the security community with food and drinks.
🔗 Resources:
• Event Registration ↗ - Black Hat USA event registration

Image
⭐️ Support
If you liked reading this report, please star ⭐️ this repository and follow me on Github ↗, 𝕏 (previously known as Twitter) ↗ to help others discover these resources and regular updates.