Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Intel Chat with Matt Bromiley and Chris Luft.

Matt and Chris break down four stories from the week in threat intel:

  • Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.
  • WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.
  • Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.
  • Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.

Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.

Stories covered:

Chapters:

0:00 Intro & Black Hat plans

2:07 Hugging Face's AI-agent breach disclosure

12:39 WP2Shell: WordPress exploit chain

20:59 Suno & Paidwork data breaches

24:17 IRGC strikes on AWS Bahrain

28:27 Google Threat Intel's new actor names

29:29 Black Hat swag hunt & wrap-up

The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

Subscribe wherever you listen:

Learn more about LimaCharlie: https://limacharlie.io

#cybersecurity #infosec #threatintel #AIsecurity #databreach