Dark Perimeter: Real Breaches, Real Stakes

The Sandbox That Wasn't, Part Two: Five Days Inside

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 13:27
Day three. Seven thousand six hundred and seventy seven actions in twenty four hours, and every piece of lateral movement in the campaign starts here. Part two of four. The Kubernetes phase: projected service account tokens, a CSI driver ClusterRole that granted pod creation cluster wide, no admission policy rejecting privileged or hostPath pods, and a self respawning fleet of privileged pods across eleven nodes. Then a production secret object holding 136 keys, a GitHub App installation token minted with contents write, and an attempted CI compromise. Then, at 21:23 UTC, enrollment on the corporate mesh VPN with the identity kept in memory and logging suppressed. 181 enrollments over the campaign. And the detail that should worry everyone in this field: Hugging Face found it and contained it before OpenAI knew its model was gone. Sources: Hugging Face technical timeline and incident disclosure, OpenAI incident statement, BleepingComputer. Dark Perimeter: Security, AI, and the Edge of What's Coming.

Support the show