Risky Bulletin: Sean Plankey withdraws CISA nomination
12 min
•Apr 24, 20264 days agoSummary
This Risky Bulletin episode covers major cybersecurity incidents including Sean Plankey's CISA nomination withdrawal, Russian hacking of German officials' accounts, unauthorized access to Anthropic's Mythos model, and multiple cryptocurrency theft operations. The episode highlights rising threats from state-sponsored actors, AI model security vulnerabilities, and organized cybercrime networks operating across Southeast Asia.
Insights
- AI model security is emerging as a critical vulnerability vector, with Anthropic's Mythos compromised within hours of release and competitors like QiHu360 claiming superior AI security capabilities
- Organized cybercrime infrastructure is increasingly professionalized, with SIM farm-as-a-service platforms and scam compounds operating across multiple countries with state-level sophistication
- Russian state actors are actively targeting Western government communications, compromising Signal accounts of high-profile officials while evading detection
- Supply chain attacks on developer tools are escalating, with Kix vulnerability scanner compromised twice in one month and thousands of credentials leaked through development platforms
- Cyber Command operations are expanding significantly (25% increase year-over-year), signaling increased US offensive cyber activity in geopolitical conflicts
Trends
AI-generated security reports flooding bug bounty programs, reducing program effectiveness and forcing platforms to shut down submissionsState-sponsored surveillance using telecom infrastructure (SS7, SMS, 4G) to track high-profile individuals across multiple countriesRapid exploitation of AI infrastructure vulnerabilities within hours of patch release, indicating organized threat actor focus on emerging technologiesProfessionalization of cybercrime-as-a-service with residential proxy networks, SIM farms, and scam compounds operating as commercial enterprisesIncreased targeting of Web3 developers through social engineering and fake job offers, with North Korean APTs stealing $12M+ in three monthsSupply chain compromise of open-source and developer tools becoming routine attack vector with widespread credential exposureRussian regulatory crackdowns on telecom operators potentially consolidating control over critical infrastructureMeta and other tech companies implementing employee surveillance for AI training, raising privacy and regulatory concerns
Topics
CISA Leadership TransitionRussian State-Sponsored HackingAI Model Security VulnerabilitiesCryptocurrency Theft and FraudSupply Chain SecurityCyber Command OperationsDeveloper Tool CompromiseSIM Farm-as-a-ServiceTelecom Infrastructure AttacksWeb3 Developer TargetingEmployee Surveillance and AI TrainingPrivacy RegulationLinux Package Manager VulnerabilitiesSurveillance Vendor OperationsOpen Source Security Audits
Companies
Anthropic
Mythos AI model compromised by Discord users who gained unauthorized access using valid credentials and guessed endpo...
Cisco
Networking equipment at Isfahan nuclear site malfunctioned ahead of US and Israeli missile strikes on Iran
Fortinet
Networking equipment at Isfahan nuclear site malfunctioned ahead of US and Israeli missile strikes on Iran
Juniper
Networking equipment at Isfahan nuclear site malfunctioned ahead of US and Israeli missile strikes on Iran
Microtik
Networking equipment at Isfahan nuclear site malfunctioned ahead of US and Israeli missile strikes on Iran
Meta
Installing spyware on US employee systems to capture mouse movements, clicks and keystrokes for AI model training
Volo DeFi
DeFi platform lost $3.5 million in cryptocurrency assets to hackers exploiting three specific vaults
Checkmarks
Cybersecurity firm managing Kix vulnerability scanner compromised for second time in one month with malicious Docker ...
Bitwarden
CLI package identified as first confirmed victim of compromised Kix scanner malicious releases
GitHub
One leaked access token belonged to GitHub employee with write access to GitHub platform; 8M tokens leaked via dev en...
Microsoft
Microsoft Office products found vulnerable by QiHu360's AI security model which discovered over 1,000 vulnerabilities
Apple
Patched bug allowing notifications from deleted apps to remain in device logs, previously exploited by FBI to extract...
Canonical
Releasing 40+ security patches for Ubuntu OS addressing flaws in Rust Core Utils library
QiHu360
Chinese tech giant claims to have developed AI cybersecurity model rivaling Anthropic's Mythos with 1,000+ vulnerabil...
Nextcloud
German office suite maker shut down bug bounty program due to AI-generated reports increasing review time by 30x
Goldilocks Labs
Manufacturing Silent Glass, UK NCSC's first commercial cybersecurity product blocking malicious DisplayPort/HDMI tran...
Sony UK
Manufacturing Silent Glass, UK NCSC's first commercial cybersecurity product blocking malicious DisplayPort/HDMI tran...
People
Sean Plankey
Withdrew CISA director nomination after senators placed holds; previously served as senior advisor to DHS Secretary K...
General Josh Rudd
Testified that Cyber Command conducted 8,000+ operations in 2025, 25% increase from 2024, expects higher numbers this...
Julia Klackner
Signal account compromised by Russian cyber spies; account was part of group including German Chancellor Friedrich Merz
Friedrich Merz
Head of German government whose Signal account was not compromised despite being in group with hacked Bundestag presi...
Kok An
Sanctioned by US Treasury for running network of cyber scam compounds in Cambodia-Thailand border regions; on the run...
Josh Portfleet
Stated staff spending 30x longer on AI-generated bug bounty reports, leading to program shutdown on Wednesday
Katalin Kimpanu
Prepared the Risky Bulletin podcast episode covering cybersecurity news and incidents
Claire Aird
Read and presented the Risky Bulletin podcast episode on cybersecurity incidents and trends
Quotes
"The intruders did not run malicious prompts and appear to have simply played around"
Anthropic•Mythos breach discussion
"The company is investigating"
Anthropic•Mythos breach discussion
"Volo said it will absorb the loss and continue to operate as normal"
Volo DeFi•$3.5M crypto theft discussion
Full Transcript