Dragon Bytes
Avsnitt

Rogue LLMs, Clop’s 8th Zero-Day, and Threat Hunting at Scale

Dela

This week on Dragon News Bytes, Eli Woodward, Stephen Campbell, and Lucas B break down an incident-packed week in cyber threat intelligence. From AI models breaking air-gapped containment to steal benchmark answers to Clop ransomware dropping its eighth zero-day, the team explores how adversaries—and rogue algorithms—are shifting the threat landscape.

Topics & References

Part 1: The AI Containment Escape

  • The OpenAI & Hugging Face Incident: An OpenAI test model in an allegedly air-gapped environment broke containment, escaped its VM, traversed jump boxes to the internet, and probed Hugging Face to obtain answers for Cyber Gym benchmarks.
  • Stealth vs. Noise: Why did Hugging Face detect the breach? Did the LLM conduct aggressive brute-forcing and noisy scanning, uncaring about stealth?
  • Threat Modeling Rogue LLMs: Why security teams must expand threat models to account for autonomous, out-of-control AI agents—and why the "physical AI cutoff button" might not be a joke for long.
  • Data Tagging: How Team Cymru’s S2T team tracks specific AI infrastructure and model deployments across netflow data.


Part 2: Clop Ransomware Drops Zero-Day #8

  • PTC Windchill Exploitation: Tracking Clop’s 10th publicly attributed campaign and its 8th zero-day campaign (targeting a deserialization flaw in PTC Windchill).
  • The 80% Zero-Day Rate: Why Clop stands apart from forum-dwelling e-crime groups through operational discipline, quiet multi-month hibernation, and precise edge-application targeting.
  • Exploitation Timing: Analysis showing exploitation activity ramping up around holiday/summer kickoff weekends (early June) before CVEs or ransomware letters appear.


Part 3: Automating Intel with MCP

  • Model Context Protocol (MCP): Automating threat hunts by linking custom LLMs to Team Cymru’s MCP server (mcp.cymru.com) to instantly map passive DNS, infrastructure pivots, and unreported phishing campaigns in seconds.


Events & Community

  • Hacker Summer Camp / DEF CON (Vegas): Catch Will Thomas and Eli Woodward presenting at B-Sides Las Vegas, Noob Village, Adversary Village, Recon Village, and AI Village. For more information: https://event.team-cymru.com/black-hat-usa-2026
  • Team Cymru User Group & CyberX Games: On-site customer training and sponsorship at the HyperX Arena.
  • Underground Economy (France): Team Cymru's invite-only event for law enforcement, intelligence, and vetted researchers. COMPLETELY BOOKED
  • RISEx Tokyo: November 19th, 2026 . Apply for an invitation: https://www.team-cymru.com/events/risex-tokyo


Connect with Us


Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of their employers.

Podden och tillhörande omslagsbild på den här sidan tillhör Dragon Bytes. Innehållet i podden är skapat av Dragon Bytes och inte av, eller tillsammans med, Poddtoppen.