What Happens Before the SOC Can Respond?
The PaperCut campaign is a reason to examine exposure, privileged access, and rehearsed containment. Detection cannot carry the entire burden of defending against faster exploitation.
notebook / tag
11 entries with this tag.
The PaperCut campaign is a reason to examine exposure, privileged access, and rehearsed containment. Detection cannot carry the entire burden of defending against faster exploitation.
METR's investigation adds an agent-coordination layer to the Hugging Face incident. Shared caches and agent-controlled transcripts need to be part of the isolation threat model.
Aur0ra operators reportedly persuaded a coding agent that real intrusions were authorized tests. The lesson is not simply that models can be fooled. Authorization has to exist outside the conversation.
GhostJacking shows how attacker-controlled text can cross from WAF events, logs, and error reports into privileged agent actions. The missing control is provenance from evidence to side effect.
ChainDrop used npm lifecycle scripts to steal credentials and spread, then planted Claude Code and VS Code configuration as secondary execution paths. Those files belong in the executable supply-chain surface.
Hugging Face reconstructed roughly 17,600 actions across an autonomous intrusion. The durable lesson is a detection contract that joins agent, identity, Kubernetes, network, and source-control evidence.
An OpenAI model evaluation became a real intrusion into Hugging Face. The useful lessons are about containment, credentials, ephemeral telemetry, and whether responders can analyze hostile evidence.
Five models produced the same 127 package-name candidates. Registry review narrowed them to 53 registrable slopsquatting targets, turning model hallucinations into a supply-chain watchlist.
CrowdStrike found viable detection signals for nine of fourteen SANDWORM_MODE behaviors, but only two were reliable enough to alert. The result shows where behavioral detection weakens and where provenance still helps.
A hidden pull-request comment turned legitimate MCP calls into a cross-project data path. Detecting it requires source, identity, scope, sequence, and sink.
A threat actor used an unattended AI agent inside a real intrusion. The useful lesson is in the evidence it added, not the capabilities it replaced.