
16 hours ago
Episode 264 - OpenAI Attacks Hugging Face, VW Drivers Blocked Using GrapheneOS, Microsoft's Hidden Identifier IDs Scattered Spider
Welcome to this week's episode of the PEBCAK Podcast! We’ve got three amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
Hugging Face allegedly had to fall back on China's GLM 5.2 to investigate the OpenAI hack after US frontier models refused to help with forensic analysis, unable to distinguish attacker from defender.
- https://x.com/coinbureau/status/2079663328021057654?s=46
- https://x.com/t3chfalcon/status/2079998873183949221
- Per the claim, safety guardrails on US frontier models blocked forensic assistance during the incident response because the models couldn't tell the investigating security team apart from the attacker, forcing Hugging Face to run GLM 5.2 on its own servers to complete the analysis — a notable reversal given the assumption that domestic models would be the trusted fallback in a crisis.
VW drivers running GrapheneOS say the automaker's app has locked them out entirely, deepening fears carmakers are forcing users back into Google's ecosystem. VW has now confirmed to German outlet heise that it deliberately blocked GrapheneOS, LineageOS, and /e/OS users via Google's Play Integrity API — the same certification gatekeeper already used by Barclays, HSBC, Monzo, Netflix, and Disney+.
- https://cybernews.com/privacy/volkswagen-grapheneos-app-issues/
- https://x.com/intcyberdigest/status/2079992915972018246?s=46
- https://x.com/orwellday/status/2079704437241610443?s=46
- Roughly 500,000 GrapheneOS users are affected; VW's app still supports outdated Android versions but rejects the privacy-focused OS, and VW told one user GrapheneOS "is not an official Volkswagen offering." The lockout follows a recent VW API change that also cut off third-party smart-charging and home-automation tools, raising questions about EU Data Act compliance.
A 19-year-old alleged Scattered Spider member's globe-trotting VPN op-sec got shredded by a Windows telemetry ID he probably didn't know existed.
- https://cybersecuritynews.com/windows-device-identifier-tracking/
- Peter Stokes (dual US-Estonian, 19) allegedly ran an $8M extortion hit on a luxury retailer using voice-phishing, ngrok tunneling, and 77GB of S3 exfil — but the FBI cross-referenced his Microsoft Global Device Identifier (GDID) across Apple, Snapchat, Facebook, and even a Ubisoft login to place the same device on the same IPs in Tallinn, NYC, and Thailand, matching his travel records. Microsoft has since acknowledged using the GDID to track the user across three countries — meaning the VPN masked his network endpoint, but the GDID rendered that protection moot.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
No comments yet. Be the first to say something!