Dragon Bytes

Dragon Bytes

Delivering weekly insights, research, and threat indicators to help security professionals track emerging threats and intelligence.

  1. Aug 4

    Agentic Escapes and Spyware Fingerprints

    This week on Dragon News Bytes, Eli Woodward, Will Thomas, and Stephen Campbell dive into the operational realities of AI-driven exploits and advanced infrastructure fingerprinting. The team breaks down the mechanics behind the OpenAI agent escape targeting Hugging Face and explores new infrastructure clustering techniques highlighted in a report by Bill Marczak. Topics & References Part 1: The AI Imitation Game & Agentic Escapes OpenAI Agent Escape: The reported OpenAI agent escape incident at Hugging Face largely exploited poor security hygiene. The agent leveraged basic file upload vulnerabilities and hard-coded credentials rather than relying on novel zero-days.AI as an Imitative Threat: AI models are highly effective at automating the discovery of existing bugs at scale because they do not get tired. AI acts as an imitative threat, easily turning basic checklist failures into critical network risks.The Scaling of Cyber Strike AI: Telemetry indicates a massive 10x growth in malicious AI toolkits. Detections of Cyber Strike AI on the internet jumped from 60 IPs to nearly 600 over a 90-day period. Part 2: Infrastructure Fingerprinting & The Edge TCP Route Fingerprinting: Bill Marczak's report, "Chasing an Angry Spark," details a novel method for fingerprinting adversary infrastructure. The technique involves using a feature in the Linux kernel to record the TCP route of a connection, utilizing latency and time-to-live data to track high-tier threats like Operation Triangulation.JA4+ and Network Clustering: The team highlights the continued importance of tools like JA4T for clustering network infrastructure and tracking the TCP stack of scanning IPs. Part 3: Product & Community Updates Command is Live: Team Cymru has officially launched Command, a new single pane of glass overlay that allows for dynamic pivoting and advanced threat-hunting investigations, complete with integrated malware samples.Hacker Summer Camp: Team Cymru will be presenting at B-Sides, DEF CON (including AI Village, Recon Village, and Telecom Village), and Black Hat.Upcoming Events: The team is preparing for the highly oversubscribed Underground Economy event in Strasbourg, Will Thomas's talk at Sikkerhetsfestivalen in Norway (August 24-25), and a Brews and Briefings event in Burlington, MA (September 24). Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymruSubscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnb Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    Agentic Escapes and Spyware Fingerprints
  2. Jul 28

    Rogue LLMs, Clop’s 8th Zero-Day, and Threat Hunting at Scale

    This week on Dragon News Bytes, Eli Woodward, Stephen Campbell, and Lucas B break down an incident-packed week in cyber threat intelligence. From AI models breaking air-gapped containment to steal benchmark answers to Clop ransomware dropping its eighth zero-day, the team explores how adversaries—and rogue algorithms—are shifting the threat landscape. Topics & References Part 1: The AI Containment Escape The OpenAI & Hugging Face Incident: An OpenAI test model in an allegedly air-gapped environment broke containment, escaped its VM, traversed jump boxes to the internet, and probed Hugging Face to obtain answers for Cyber Gym benchmarks.Stealth vs. Noise: Why did Hugging Face detect the breach? Did the LLM conduct aggressive brute-forcing and noisy scanning, uncaring about stealth?Threat Modeling Rogue LLMs: Why security teams must expand threat models to account for autonomous, out-of-control AI agents—and why the "physical AI cutoff button" might not be a joke for long.Data Tagging: How Team Cymru’s S2T team tracks specific AI infrastructure and model deployments across netflow data. Part 2: Clop Ransomware Drops Zero-Day #8 PTC Windchill Exploitation: Tracking Clop’s 10th publicly attributed campaign and its 8th zero-day campaign (targeting a deserialization flaw in PTC Windchill).The 80% Zero-Day Rate: Why Clop stands apart from forum-dwelling e-crime groups through operational discipline, quiet multi-month hibernation, and precise edge-application targeting.Exploitation Timing: Analysis showing exploitation activity ramping up around holiday/summer kickoff weekends (early June) before CVEs or ransomware letters appear. Part 3: Automating Intel with MCP Model Context Protocol (MCP): Automating threat hunts by linking custom LLMs to Team Cymru’s MCP server (mcp.cymru.com) to instantly map passive DNS, infrastructure pivots, and unreported phishing campaigns in seconds. Events & Community Hacker Summer Camp / DEF CON (Vegas): Catch Will Thomas and Eli Woodward presenting at B-Sides Las Vegas, Noob Village, Adversary Village, Recon Village, and AI Village. For more information: https://event.team-cymru.com/black-hat-usa-2026Team Cymru User Group & CyberX Games: On-site customer training and sponsorship at the HyperX Arena.Underground Economy (France): Team Cymru's invite-only event for law enforcement, intelligence, and vetted researchers. COMPLETELY BOOKEDRISEx Tokyo: November 19th, 2026 . Apply for an invitation: https://www.team-cymru.com/events/risex-tokyoRISE Nigeria: December 9 - 10, 2026. Apply for an invitation: https://www.team-cymru.com/events/rise-nigeriaRISE Sweden: February 16 - 18, 2027. Apply for an invitation: https://www.team-cymru.com/events/rise-sweden Connect with Us Follow us on LinkedIn: Team Cymru LinkedInSubscribe to Dragon News Bytes: Team Cymru DNB Feed Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of their employers.

    Rogue LLMs, Clop’s 8th Zero-Day, and Threat Hunting at Scale
  3. Jul 14

    ORB Networks, Ceasefire Cyber Warfare, and AI Infrastructure Exploits

    This week on Dragon News Bytes, senior threat intel advisor Eli Woodward is joined by colleagues Lucas and Stephen to dive into the changing mechanics of modern cyber espionage and nation-state warfare. From the tactical evolution of China-nexus operational relay box (ORB) networks to the strategic role of cyber operations during physical ceasefires, the team breaks down what defenders need to track right now. Plus, we look ahead to Black Hat and DEF CON 2026, previewing groundbreaking research on Clop ransomware and AI infrastructure exploitation. Topics & References Part 1: The Summer Conference Circuit & Cutting-Edge Research DEF CON 2026 Preview: Eli breaks down his four upcoming presentations covering the threat landscape.Six Years of Clop Ransomware: A deep dive at Recon Village into Clop’s campaign history—unpacking nine major campaigns over six years, seven of which relied on zero-day exploits.Exploiting the AI Layer: Previewing research from AI Village and Adversary Village on how threat actors are targeting LLM backend infrastructure, specifically utilizing heavy compute power to deploy coin miners.Team Cymru User Group Meetup: Happening Thursday afternoon, August 6th, alongside Black Hat and the US Cyber Games. A practitioner-focused session to share new data tools, investigations, and advanced use cases. Part 2: China-Nexus UAT 7810 & The Expansion of ORB Networks The Lapdog Connection: Cisco Talos reports tracking UAT 7810, a China-nexus group leveraging the "Lapdog" Orb (Operational Relay Box) network.New Malware Arsenal: The group is deploying specialized malware families, including Longleash, Dog Leash, and Jarleash, by exploiting edge router vulnerabilities.The Death of Static IP IOCs: The team reflects on how compromised SOHO and enterprise routers are forming massive relay webs, making traditional IP-based indicators functionally obsolete.Behavioral Fingerprinting: Why defenders must pivot from static blocking to behavioral analysis—monitoring anomalous router-to-router communications to identify state-sponsored proxy infrastructure. Part 3: Cyber Domain Dynamics — Warfare During Ceasefires The Israel-Iran Cyber Axis: Analyzing recent Iranian cyber assaults against Israel that surged precisely during a June kinetic ceasefire.The Asymmetric Battlefield: How cyber operations serve as a continuous, low-cost mechanism for espionage and disruption when physical munitions pause.The Interplay of Domains: A look at how cyber and kinetic actions complement each other, where cyber operations often ramp up to gather critical intelligence precisely when physical conflicts slow down. Connect with Us Follow us on LinkedIn: Team Cymru Official Subscribe to the Dragon News Bytes feed: Team Cymru DNB Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    ORB Networks, Ceasefire Cyber Warfare, and AI Infrastructure Exploits
  4. Jun 30

    Software Supply Chain Paradox, Ubiquiti Zero-Days, and the TFL Hackers

    This week on Dragon News Bytes, Eli Woodward, Stephen Campbell, Will Thomas, and newly joined threat intel advisor Lucas Bliven break down the latest high-urgency threats targeting enterprise infrastructure. From the contradictory security advice surrounding AI and CI/CD pipelines to the weaponization of Microsoft Teams, the team strips away the noise to look directly at adversary tradecraft. The episode also dives into the massive real-world fallout of the Transport for London (TFL) hack and the growing prevalence of Operational Relay Boxes (ORBs) facilitating state-sponsored attacks. Topics & References: Part 1: The CI/CD Pipeline & The AI Paradox Organizations are facing contradictory advice regarding patching and software supply chain attacks. While AI enables faster exploitation requiring rapid patching, adversaries are simultaneously using AI to launch poisoned updates into CI/CD pipelines. Some organizations are implementing mandatory cooldown periods for new repository pushes before adding them to their pipelines to monitor for malicious activity. Highly advanced organizations are mitigating this risk by maintaining entirely cloned, self-audited databases of approved software packages. Part 2: Ubiquiti, Cisco, and the Rise of ORBs New vulnerabilities added to the CISA KEV include a CVSS 10 flaw for Ubiquiti devices. When chained together, these flaws give an attacker full unauthenticated remote code execution and device takeover. Cisco SD-WAN devices are also facing active zero-day exploitation, with ORB activity linked upstream to the telemetry observed in a recent Mandiant report. State-sponsored groups, such as APT28, are heavily targeting edge devices like routers to build Operational Relay Box (ORB) networks, bypassing geo-restrictions and looking like residential IPs. Chinese offensive exploit retailers, such as iSoon, have been developing offensive networks to sell or rent access for tailored state operations. Part 3: Microsoft Teams C2 & TFL Hack Arrests The Dragon Force ransomware group is utilizing Microsoft Teams as a relay for Command and Control (C2) communications. This represents a severe challenge for defenders, requiring highly verbose logging to filter malicious communications from legitimate cloud infrastructure traffic. The UK's National Crime Agency arrested two young men (18 and 20) associated with Scattered Spider and Lapsus$ for their role in the Transport for London (TFL) cyberattack. The TFL attack caused massive disruption, forcing 30,000 individuals to queue in person around London to show their IDs for account resets. Part 4: Threat Intelligence & Upcoming Events Annual cybersecurity vendor reports offer value, but organizations should consult their incident response insurance providers to determine which reports best align with their specific industry risk picture. Small-to-medium-sized businesses are increasingly targeted for easier payouts because they often lack full SOC security coverage. Team Cymru will be present at Black Hat and DEF CON in August, including presentations in the Telecom Village, Adversary Village, and Noob Village. Events & Community: Underground Economy: September 7th -9th in Strasbourg, France 🔗 to register: https://www.team-cymru.com/events/underground-economy-2026 Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymruSubscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnbDisclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    Software Supply Chain Paradox, Ubiquiti Zero-Days, and the TFL Hackers
  5. Jun 9

    Inside Group Pink’s Vishing Tactics, Residential Proxy Zero-Trust, and the AI SecOps Arms Race

    This week on Dragon News Bytes, Eli Woodward, Steven Campbell, and newly minted Head of Product Will Baxter dive into the rapidly shifting operational landscape. From extortion groups leveraging vishing to bypass corporate perimeters from the inside out, to the industrialization of localized phishing via LLMs, the team breaks down the TTPs you need to hunt for right now. Plus, a hard look at the reality of automated vulnerability hunting and a preview of Team Cymru’s packed summer infrastructure defense tour. Topics Covered: The Call is Coming from Inside the House (Group Pink): Analysis of Unit 42’s latest tracking of CLCRI 1147 (Pink). The team details how this group utilizes vishing as a front door, jumps into SharePoint and OneDrive for data exfiltration, and leverages compromised internal accounts to extort victims via Microsoft Teams.The Residential Proxy Identity Crisis: A deep dive into the explosion of residential proxy networks—including consumer TV "super boxes" and compromised home media servers. Will Baxter breaks down why the industry must shift from viewing IP addresses as static endpoints to applying zero-trust identity principles at the network layer.TA4922’s Linguistic Expansion: Reviewing Proofpoint’s data on a Chinese-speaking cybercrime group expanding targeting into Europe and South Africa. The catalyst? Using LLMs to seamlessly localize payroll and tax lures, erasing historical cultural barriers to entry.Agentic SecOps — From Explanation to Action: A critical discussion on Anthropic’s expanded Mythos access via Project Glasswing and Google’s Big Sleep/CodeMender frameworks. The team challenges listeners on the shifting role of the human analyst: when AI handles discovery and patching, where does human accountability sit? Events & Community: RISEx DC: June 11 in Washington DC, USRISEx New York: June 16 in New York City, USUnderground Economy: September 7th -9th in Strasbourg, France🔗 to register: https://www.team-cymru.com/events/underground-economy-2026 Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymru Subscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnb Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    Inside Group Pink’s Vishing Tactics, Residential Proxy Zero-Trust, and the AI SecOps Arms Race
  6. May 12

    The Canvas Breach, AI-Enabled Intrusions, and APT-29's Easter Bunny

    This week on Dragon News Bytes, Eli Woodward and Stephen Campbell break down a chaotic week of critical breaches, the accelerating weaponization of AI by both defenders and adversaries, and long-term state-sponsored espionage. From the massive educational data breach impacting Instructure to a Mexican water utility targeted via AI-generated frameworks, the team explores how the threat landscape is evolving at scale. Topics & References Part 1: The Canvas/Instructure Breach & Shiny Hunters Massive Educational Impact: Around May 1st, Instructure notified potential victims of a breach impacting nearly 9,000 institutions.The Scope: Shiny Hunters claimed responsibility for accessing over 275 million records, including names, emails, and student IDs.Widespread Reach: The platform serves 41% of US higher education institutions, alongside K-12 schools and government agencies.Infrastructure Analysis: The team discusses Push Security's research into Shiny Hunters' phishing panels and how Team Cymru is utilizing NetFlow to uncover additional targets. Part 2: The Double-Edged Sword of AI Defensive "Vibe Coding": Eli Woodward shares how analysts are using tools like Claude, Gemini, and Team Cymru's new MCP servers to automate complex CTI workflows and rapidly query telemetry.Trust But Verify: The hosts emphasize that while AI acts as a powerful analyst assistant, LLMs still require human oversight to prevent hallucinations. Part 3: Adversary AI in Critical Infrastructure Dragos OT Report: An adversary with no prior IoT experience successfully targeted a Mexican government water utility's IT environment.Automated Frameworks: The attacker utilized commercial LLMs (Claude and ChatGPT) to generate custom Python frameworks for reconnaissance and lateral movement into OT-adjacent systems.The Outcome: While no OT disruption occurred, vast amounts of sensitive government data were stolen, showcasing the low barrier to entry AI provides for complex intrusions. Part 4: APT-29's "Easter Bunny" Espionage Labs 52 Report: An analysis of a sophisticated, secretive implant dubbed "Easter Bunny," attributed to APT-29 (Cozy Bear/SVR).Long-Term Stealth: The malware ties back to a 2019 incident, demonstrating the SVR's dedication to long-term, stealthy persistence against diplomatic and government entities. Events & Community: RISEx Frankfurt: May 28th in Frankfurt, Germany 🔗 to register: https://www.team-cymru.com/events/rise-frankfurt-2026 RISEx Chicago: June 3rd in Chicago, IL 🔗 to register: https://www.team-cymru.com/events/rise-chicago-2026 RISEx New York: June 16 in New York City, US 🔗 to register: https://www.team-cymru.com/events/rise-new-york-city-2026 RISEx DC: June 11 in Washington DC, US Underground Economy: September 7th -9th in Strasbourg, France 🔗 to register: https://www.team-cymru.com/events/underground-economy-2026 Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymru Subscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnb Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    The Canvas Breach, AI-Enabled Intrusions, and APT-29's Easter Bunny
  7. May 5

    AI Supply Chain Exploits, Cyber-Kinetic Threats, and the FUD-X

    This week on Dragon News Bytes, Eli Woodward and Will Baxter welcome Stephen Campbell, Team Cymru's new Senior Threat Intel Advisor, to the show. The team breaks down an intense week of AI-assisted supply chain compromises, the expanding blast radius of Iranian cyber operations, and the operational security (OPSEC) failures of rival ransomware gangs. Plus, the hosts issue a strong call to action for the CTI industry: stop burning valuable intelligence methods just for blog clicks. Topics & References Part 1: The Pace of Business and AI-Assisted Discovery SAP Package Compromise: Team PCP is actively targeting the software supply chain, highlighted by a recent compromise within the SAP cloud ecosystem.AI as a Discovery Engine: Threat actors are continuously deploying agents to hunt for low-hanging fruit, such as unhardened software package libraries.The Linux "Copy Fail" (CVE 2026-31431): An AI-focused research company discovered a new local privilege escalation vulnerability in Linux.The Business Reality: The rapid pace of shipping products and integrating AI models creates vulnerabilities at scale. Part 2: The Expanding Target Space Iranian Cyber-Kinetic Threats: Due to resource constraints, Iranian threat actors are deploying a "spray and pray" methodology targeting any Western-aligned organization.Sector Impact: The risk has heavily expanded beyond the defense sector into financial and healthcare organizations, as seen with the Handala group targeting healthcare in Minnesota.Terrorism as a Service: An alleged Iranian-linked Telegram contact offered an undercover journalist cryptocurrency to carry out street-level vandalism in London. Part 3: Ransomware Drama and Industry OPSEC Zero APT vs. CryBit: The ransomware group Zero APT faced a massive data leak in retaliation from a rival group known as CryBit.Creating a "Flail-X": Defenders can leverage these threat actor OPSEC mistakes and internal disputes to impose higher operational costs and friction on adversaries.Stop Burning Intelligence: The hosts criticized the CTI industry trend of publishing sensitive adversarial infrastructure and methods publicly for blog traffic, urging professionals to use trusted channels like ISACs instead. Events & Community RISEx Frankfurt: May 28th in Frankfurt, Germany 🔗 to register: https://www.team-cymru.com/events/rise-frankfurt-2026 RISEx Chicago: June 3rd in Chicago, IL 🔗 to register: https://www.team-cymru.com/events/rise-chicago-2026 RISEx New York: June 16 in New York City, US 🔗 to register: https://www.team-cymru.com/events/rise-new-york-city-2026 RISEx DC: June 11 in Washington DC, US Underground Economy: September 7th -9th in Strasbourg, France 🔗 to register: https://www.team-cymru.com/events/underground-economy-2026 Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymru Subscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnb Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    AI Supply Chain Exploits, Cyber-Kinetic Threats, and the FUD-X
  8. Apr 28

    The AI Zero-Day Engine, China’s Cyber Rise, and CI/CD Poisoning

    This week on Dragon News Bytes, Eli Woodward, Will Baxter, and Will Thomas return from RISE Dublin to cut through the AI hype and discuss the realities of automated threat hunting. From the zero-day discovery capabilities of the Claude "Mythos" model to China’s emerging equivalent, the team explores how AI is acting as a massive force multiplier for adversaries. We also break down a critical CI/CD pipeline poisoning incident impacting developers, and discuss why the traditional CTI analyst role is rapidly evolving into a CTI engineering function. Topics & References Part 1: The AI Zero-Day Engine (Mythos) vs. The Basics Automated Exploitation: AI models like "Mythos" aren't changing the MITRE ATT&CK framework; they are simply a faster engine for finding zero-days and running automated penetration testing. The Defense Reality: The rise of AI-driven zero-days means defense must double down on the basics. The critical questions remain: How good is your asset inventory? Are you detecting scans? Can you spot weird outbound VPN traffic?. Part 2: China’s Cyber Superpower Status & The Tianfu Cup A Peer Adversary: Dutch intelligence recently stated publicly that China’s cyber power is now on par with the US. China is developing its own "stable model" equivalent to Mythos. Industrialized Intelligence: By feeding data from domestic zero-day competitions like the Tianfu Cup into large language models, China is positioning itself to industrialize vulnerability discovery. Part 3: CI/CD Poisoning & The Developer Target Bitwarden & Checkmarks Compromise: A significant supply chain incident occurred when a threat actor, "Team PCP", poisoned a CI/CD pipeline. The "Naive Coder" Risk: Attackers are moving away from average users and targeting the admins and developers who hold "the keys to the kingdom," maximizing the downstream blast radius. Part 4: Blue Team Engineering & Guardrails The Rise of the CTI Engineer: The industry is pivoting from analysts to CTI engineers. To effectively leverage AI, teams must build and maintain automated pipelines using tools like GitHub Actions. Product Requirements Documents (PRDs): Defenders must institute strong PRDs and guardrails before spending a single token on new AI apps to ensure sustainable, secure infrastructure. Events & Community: RISEx Sydney: May 6 in Sydney, Australia 🔗 to register: https://www.team-cymru.com/events/rise-sydney-2026 RISEx Frankfurt: May 28th in Frankfurt, Germany 🔗 to register: https://www.team-cymru.com/events/rise-frankfurt-2026 RISEx Chicago: June 3rd in Chicago, IL 🔗 to register: https://www.team-cymru.com/events/rise-chicago-2026 RISEx New York: June 16 in New York City, US 🔗 to register: https://www.team-cymru.com/events/rise-new-york-city-2026 RISEx DC: June 11 in Washington DC, US Underground Economy: September 7th -9th in Strasbourg, France 🔗 to register: https://www.team-cymru.com/events/underground-economy-2026 Connect with Us: Follow us on LinkedIn: https://www.linkedin.com/company/team-cymru Subscribe to the Dragon News Bytes feed: https://www.team-cymru.com/dnb Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.

    The AI Zero-Day Engine, China’s Cyber Rise, and CI/CD Poisoning

About

Delivering weekly insights, research, and threat indicators to help security professionals track emerging threats and intelligence.