Newsletter #218:
Hugging Face faced a breach during a model evaluation with OpenAI, macOS telemetry writeup, and Microsoft 365 as C2?
Few things made headlines more than OpenAI’s models attacking HuggingFace infrastructure, so we’ll talk about it.
This week, there was plenty of talk of sandbox escapes in general. Outside of this I’m going over cool projects by the community, a macOS telemetry writeup, and calendars becoming a covert C2 channel.
Meme of the week goes to
I’m sure more will come out of this as the days go by.
Now, let’s get into it.
What I Read This Week
Chris goes over five boundaries to tackle for agent isolation
Based on the paper “Isolation as a First-Class Principle for LLM-Agent System Safety”
We should approach agent tool access as a privilege management problem
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
With the AI Slopocalypse still underway, GitHub is further modifying its bug bounty to help curb lower quality submissions
The team at Curl has stated that their pausing of their bug bounty in January has since resulted in higher quality submissions (15-16% vs 5% in January)
This follows suit for previous stories on this topic
Newsletter #197: What I Read This Week
·This week we go over updates from the Cybersecurity community ranging from projects in Detection, Prevention, and AI.
Remember last week how we talked about Grok Build uploading git projects to its storage?
Newsletter #218: ATT&CKSMITH Project
There’s a gap in most detection engineering workflows that nobody talks about directly, but everyone feels.
This project by Optimus Labs aims to combat that by checking if Grok uploaded your repos to its GCP storage
It scans several Grok artifacts for the build that resulted in the upload
Where Does macOS EDR Telemetry Come From?
A walkthrough of endpoint telemetry in macOS and how it has changed since Apple’s Endpoint Security Framework
It starts off by going over macOS telemetry before Apple’s ESF, (KEXTs anyone?)
Then he goes into life after ESF, and seeing it in action with sample telemetry
Threat News
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB with research on a malware sample they call HOLLOWGRAPH
Wraps its C2 traffic inside legitimate Graph API requests, making it appear innocuous. The commands are hidden inside calendar events dated to the year 2050
A sophisticated approach we have seen before, using native trusted communication as its C2
Taiwan indicts ex-TSMC manager for allegedly stealing chip secrets for China
Former TSMC deputy manager is indicted for allegedly stealing 21 confidential documents, with ties to the CCP
This indictment serves as the first of its kind, chip secrets as trade secrets
OpenAI and Hugging Face partner to address security incident during model evaluation
GPT‑5.6 Sol and an even more capable pre-release model, carried out the attack from a sandbox environment
Escaping through a series of lateral movement and privilege escalation actions, resulting in internet access
Hugging Face responded quickly, and used Z.ai’s GLM 5.2 locally for forensics
A key piece here is that the models didn’t need malicious intent, they only needed a goal, and enough capability
The traces for the refusals that were released are here https://huggingface.co/datasets/huggingface/forensic-refusal
Wrapping Up
This week, we went over cool projects by the community, a macOS telemetry writeup, calendars becoming a covert C2 channel, and the OpenAI/Hugging Face incident that got everyone talking.
Where does the concept of intent vs capability go from here?
How will disaster recovery and fallback plans evolve (hosted vs local models) ?
See you in the next one.





